Labyrinth Chollima Evolves into Three North Korean Hacking Groups
ID: c2eeeecf-66a2-5f5f-a691-0ef47a64eebc
STIX ID: report--c2eeeecf-66a2-5f5f-a691-0ef47a64eebc
Feed Name: Infosecurity Magazine (News)
CrowdStrike reports that the North Korean-linked Labyrinth Chollima ecosystem has split into three distinct groups—Labyrinth Chollima, Golden Chollima, and Pressure Chollima—each using evolved variants of a common malware lineage (KorDLL → Hawup → Hoplight/Jeus/MataNet/TwoPence) and focusing respectively on state espionage (defense, manufacturing, critical infrastructure) and organized cryptocurrency thefts; despite separation they continue to share tools and infrastructure, indicating centralized coordination.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
