logo

Hydra Tactics: North Korea’s LABYRINTH CHOLLIMA Splits to Hunt Crypto & Secrets

ID: 97470881-f590-5576-b7c0-277235299bf0

STIX ID: report--97470881-f590-5576-b7c0-277235299bf0

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-04-23

Author: Ddos

...
...

CrowdStrike reports that North Korea’s LABYRINTH CHOLLIMA has reorganized into three interrelated but specialized groups—GOLDEN CHOLLIMA (regular crypto/fintech theft), PRESSURE CHOLLIMA (high-value exchange heists), and a core LABYRINTH CHOLLIMA focused on espionage—sharing malware frameworks (KorDLL, Hawup) and tools like Jeus/AppleJeus and the FudModule rootkit; activities are driven by sanctions-induced financial needs and fund DPRK military projects, posing elevated risk to cryptocurrency, defense, and logistics sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.