Pressure Chollima
2026-01-29 • Crowd Strike • LABYRINTH CHOLLIMA Evolves into Three Adversaries
CrowdStrike Intelligence, in a January 2026 report, reassessed its long-standing LABYRINTH CHOLLIMA attribution and determined that three specialized North Korean adversaries emerged from a shared malware-framework lineage between 2018 and 2020: the core, espionage-focused LABYRINTH CHOLLIMA, GOLDEN CHOLLIMA, and PRESSURE CHOLLIMA. PRESSURE CHOLLIMA likely diverged around February 2019 with an early experimental downloader later replaced by a more advanced downloader publicly tracked elsewhere under a different name. Unlike GOLDEN CHOLLIMA's steadier, lower-value thefts, PRESSURE CHOLLIMA pursues high-payout cryptocurrency targets worldwide regardless of geography and is responsible for the DPRK's highest-profile cryptocurrency heists, including the two largest thefts on record and several other multi-million-dollar incidents linked through reused wallets. It deploys sophisticated, low-prevalence custom implants delivered via malicious Node.js and Python projects. Later 2026 CrowdStrike global and financial-sector threat reporting attributed to PRESSURE CHOLLIMA the largest single cryptocurrency theft ever reported, $1.46 billion stolen in 2025 through trojanized software distributed via a supply-chain compromise. Despite operating as a distinct unit, PRESSURE CHOLLIMA shares tooling and infrastructure with its sibling groups, reflecting centralized coordination within the DPRK cyber apparatus.
-
34
Related Actors
-
232
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Pressure Chollima reports only