Velvet Chollima
2019-02-19 • Crowd Strike • 2019 Global Threat Report
Velvet Chollima, also tracked as Kimsuky, Thallium, APT43, Emerald Sleet, Springtail, and Black Banshee, is one of the North Korean threat actor groups given a Chollima family name under a naming convention used by CrowdStrike. A December 2024 recap describes it as a state-sponsored group thought to be an offshoot of Lazarus Group and associated with North Korea's Reconnaissance General Bureau, active since at least 2014 and focused on espionage against government employees, think tanks, academics, and human rights organizations, while also stealing cryptocurrency to fund its operations. Reported 2024 activity includes trojanized TrustPKI and NX_PRNMAN installers delivering Gomir and Troll Stealer malware, TRANSLATEXT malware used against South Korean academics, spear-phishing abusing weak DMARC policies, and use of the KLogEXE and FPSpy families. Separate reporting describes a campaign beginning January 2025 targeting South Korean officials, NGOs, and media organizations with spear-phishing PDFs redirecting victims to fake CAPTCHA pages that trigger malicious PowerShell commands, plus a distinct infostealer campaign using a trading-app lure to deliver a custom XenoRAT variant.
-
43
Related Actors
-
8
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster