Golden Chollima
2026-01-29 • Crowd Strike • LABYRINTH CHOLLIMA Evolves into Three Adversaries
CrowdStrike Intelligence introduced the designation Golden Chollima in a January 2026 reassessment describing how Labyrinth Chollima, a prolific North Korea-nexus adversary previously linked to destructive attacks against South Korean and United States entities and the WannaCry ransomware incident, segmented after 2018 into three specialized adversaries sharing a malware lineage traced through the KorDLL and Hawup code frameworks. Golden Chollima targets economically developed regions with significant cryptocurrency and financial-technology activity, conducting smaller but consistent thefts that CrowdStrike assesses provide steady baseline revenue for the North Korean government. Its toolset originates with malware first seen in 2018 posing as cryptocurrency trading software from a fabricated company, later expanding to additional tools sharing code with one another. Recent operations delivered malicious software packages through fake recruitment offers to reach fintech employees, then pivoted into victim cloud environments to manipulate identity and access controls and divert cryptocurrency to attacker-controlled wallets, while also exploiting browser zero-day vulnerabilities. CrowdStrike reports that Golden Chollima and related adversaries continue sharing tooling and infrastructure, reflecting coordinated North Korean resourcing, amid a broader 2025 surge in digital-asset theft.
-
60
Related Actors
-
690
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Golden Chollima reports only