Labyrinth Chollima

2018-02-26 • Crowd Strikehttps://adversary.crowdstrike.com/en-US/adversary/labyrinth-chollima/

Labyrinth Chollima is a DPRK-nexus adversary that CrowdStrike has tracked since at least 2009, assessed as likely affiliated with Bureau 121 of North Korea's Reconnaissance General Bureau and motivated by financial gain, intelligence collection, destruction, and intellectual-property theft. Its lineage traces to the KorDLL malware framework, active 2009-2015, which evolved into the Hawup framework and, between 2018 and 2020, spawned two specialized offshoots that CrowdStrike now tracks as separate adversaries: one pursuing steady, lower-value cryptocurrency and fintech theft rooted in a 2018 fake cryptocurrency-trading-application operation, and another responsible for some of the largest cryptocurrency heists attributed to North Korea. Core Labyrinth Chollima itself narrowed toward espionage using a distinct malware lineage, and by 2022 adopted a kernel-level toolset alongside zero-day exploits in browsers, drivers, and Windows. The group maintains cross-platform Windows, Linux, macOS, and Android implants; has targeted cryptocurrency exchanges, fintech, and technology firms through trojanized applications, fake recruiter personas, and backdoored coding challenges; and has more recently prioritized European and North American manufacturing, defense, and logistics organizations using employment-themed lures and messaging-app-delivered trojanized files.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster