Long-running North Korea threat group splits into 3 distinct operations
ID: 1562912d-4f26-520a-95d3-f9a1d300ddf3
STIX ID: report--1562912d-4f26-520a-95d3-f9a1d300ddf3
Feed Name: CyberScoop
CrowdStrike reports that a long-running North Korea-backed threat cluster, Labyrinth Chollima, has split into two specialized spin-offs — Golden Chollima and Pressure Chollima — with the spin-offs focusing on cryptocurrency theft (including a record $1.46B theft) while Labyrinth Chollima concentrates on espionage against manufacturing, defense, aerospace, logistics and critical infrastructure; the groups share some tools and infrastructure but have developed distinct capabilities to support their differing missions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
