Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Guardian of Peace, PLUTONIUM, GOP, WHOis Team, OperationTroy, Onyx Sleet, Subgroup: Andariel, Andariel
Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary organization of the Lazarus threat group. WHOIS utilizes spear phishing attacks, watering hole attacks, and supply chain attacks for initial access. They have been known to exploit vulnerabilities and use malware such as Infostealer and TigerRAT.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database