Hydra Tactics: North Korea’s LABYRINTH CHOLLIMA Splits to Hunt Crypto & Secrets
ID: 97470881-f590-5576-b7c0-277235299bf0
STIX ID: report--97470881-f590-5576-b7c0-277235299bf0
Feed Name: securityonline.info
CrowdStrike reports that North Korea’s LABYRINTH CHOLLIMA has reorganized into three interrelated but specialized groups—GOLDEN CHOLLIMA (regular crypto/fintech theft), PRESSURE CHOLLIMA (high-value exchange heists), and a core LABYRINTH CHOLLIMA focused on espionage—sharing malware frameworks (KorDLL, Hawup) and tools like Jeus/AppleJeus and the FudModule rootkit; activities are driven by sanctions-induced financial needs and fund DPRK military projects, posing elevated risk to cryptocurrency, defense, and logistics sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
