Silent Chollima

2014-04-21 • Crowd StrikeThe Art of Attribution: Identifying and Pursuing …

Silent Chollima is the name CrowdStrike introduced, as part of its nation-state adversary naming convention, for a North Korean state-sponsored threat actor. CrowdStrike first presented the name publicly in 2014, describing an operational window beginning in May 2011 and objectives spanning propaganda, disinformation, and disruption, with targeting of government, military, and financial institutions and tools including spearphishing, web exploitation, and social-media spamming. In a 2021 report, CrowdStrike's Falcon OverWatch threat hunters detailed a Silent Chollima intrusion against a pharmaceuticals organization, describing use of the penetration-testing tool Smbexec for stealthy lateral movement, the custom malware dropper Export Control, an information-stealing tool called GifStealer, and a remote-access tool named Valefor, along with anti-forensic techniques such as deleting and overwriting collected data and command history. CrowdStrike noted the group's evasiveness, attributing this partly to North Korea's restricted domestic internet use, which limits the exposure typically available to researchers profiling other nation-state actors.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports in This Cluster

Top Authors

View Silent Chollima reports only

View Silent Chollima reports only