Silent Chollima
2014-04-21 • Crowd Strike • The Art of Attribution: Identifying and Pursuing …
Silent Chollima is the name CrowdStrike introduced, as part of its nation-state adversary naming convention, for a North Korean state-sponsored threat actor. CrowdStrike first presented the name publicly in 2014, describing an operational window beginning in May 2011 and objectives spanning propaganda, disinformation, and disruption, with targeting of government, military, and financial institutions and tools including spearphishing, web exploitation, and social-media spamming. In a 2021 report, CrowdStrike's Falcon OverWatch threat hunters detailed a Silent Chollima intrusion against a pharmaceuticals organization, describing use of the penetration-testing tool Smbexec for stealthy lateral movement, the custom malware dropper Export Control, an information-stealing tool called GifStealer, and a remote-access tool named Valefor, along with anti-forensic techniques such as deleting and overwriting collected data and command history. CrowdStrike noted the group's evasiveness, attributing this partly to North Korea's restricted domestic internet use, which limits the exposure typically available to researchers profiling other nation-state actors.
-
19
Related Actors
-
162
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Silent Chollima reports only