logo

LABYRINTH CHOLLIMA Evolves into Three Adversaries

ID: 7bd29337-2d04-52f1-9369-7139b124e39f

STIX ID: report--7bd29337-2d04-52f1-9369-7139b124e39f

Feed Name: Crowdstrike Blog

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Rob Bruner

...
...

CrowdStrike Intelligence profiles three distinct DPRK cyber units—GOLDEN (steady crypto/fintech theft), PRESSURE (high‑value crypto heists), and LABYRINTH (espionage)—detailing their specialized malware families (e.g., Jeus/AppleJeus, FudModule, SnakeBaker), use of zero-day exploits, cloud pivots, supply‑chain compromises, and employment-themed social engineering targeting fintech, crypto, defense, manufacturing, and logistics; the report warns organizations in these sectors to heighten vigilance for trojanized software, malicious Node.js/Python packages, and messaging-based lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.