Stardust Chollima

2018-02-26 • Crowd StrikeSTARDUST CHOLLIMA | Threat Actor Profile

STARDUST CHOLLIMA is a designation used by CrowdStrike for a targeted-intrusion adversary assessed to have a likely nexus to North Korea, with community and industry reporting also linking the activity to the Lazarus Group and Bluenoroff. The adversary primarily targets financial institutions to generate liquid assets for the regime, including campaigns abusing SWIFT banking systems and strategic web compromises against global banking networks, and has also been suspected of targeting organizations in Latin America. It uses implants built on a shared code framework and employs code-protection tools, password-protected executables, and secure-deletion functions to evade detection and persist on compromised systems for extended periods; CrowdStrike has also noted technical overlaps between this actor's tooling and the WannaCry ransomware. In 2026, CrowdStrike attributed a supply-chain compromise of a widely used open-source software package to STARDUST CHOLLIMA with moderate confidence, based on updated cross-platform malware variants and infrastructure overlaps with the group's prior operations, reflecting a continued focus on currency generation through cryptocurrency theft and compromise of financial-technology software supply chains.

Related Actors

Related Reports in This Cluster

Top Authors

View Stardust Chollima reports only

View Stardust Chollima reports only