Pressure Chollima

2026-01-29 • Crowd StrikeLABYRINTH CHOLLIMA Evolves into Three Adversaries

CrowdStrike Intelligence, in a January 2026 report, reassessed its long-standing LABYRINTH CHOLLIMA attribution and determined that three specialized North Korean adversaries emerged from a shared malware-framework lineage between 2018 and 2020: the core, espionage-focused LABYRINTH CHOLLIMA, GOLDEN CHOLLIMA, and PRESSURE CHOLLIMA. PRESSURE CHOLLIMA likely diverged around February 2019 with an early experimental downloader later replaced by a more advanced downloader publicly tracked elsewhere under a different name. Unlike GOLDEN CHOLLIMA's steadier, lower-value thefts, PRESSURE CHOLLIMA pursues high-payout cryptocurrency targets worldwide regardless of geography and is responsible for the DPRK's highest-profile cryptocurrency heists, including the two largest thefts on record and several other multi-million-dollar incidents linked through reused wallets. It deploys sophisticated, low-prevalence custom implants delivered via malicious Node.js and Python projects. Later 2026 CrowdStrike global and financial-sector threat reporting attributed to PRESSURE CHOLLIMA the largest single cryptocurrency theft ever reported, $1.46 billion stolen in 2025 through trojanized software distributed via a supply-chain compromise. Despite operating as a distinct unit, PRESSURE CHOLLIMA shares tooling and infrastructure with its sibling groups, reflecting centralized coordination within the DPRK cyber apparatus.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster