Activity timeline
Stardust Chollima appears in 35 tracked threats between and ; the busiest month was 2026-07 with 13 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 27 of 35 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 27 of 35 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 22 of 35 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 20 of 35 tracked threats
- T1005 Data from Local System — Collectionobserved in 19 of 35 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 18 of 35 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 17 of 35 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 17 of 35 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 16 of 35 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 15 of 35 tracked threats
- T1057 Process Discovery — Discoveryobserved in 15 of 35 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 15 of 35 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 14 of 35 tracked threats
- T1059.001 PowerShell — Executionobserved in 14 of 35 tracked threats
- T1204 User Execution — Executionobserved in 13 of 35 tracked threats
Tracked threats
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)HIGH
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow AbuseCRITICAL
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2HIGH
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)HIGH
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense IndustryCRITICAL
- Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform infostealer backdoor at compile timeCRITICAL
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked BackdoorCRITICAL
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)CRITICAL
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain AttackCRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)CRITICAL
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packagesHIGH
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel")HIGH
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE BackdoorsCRITICAL
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain CampaignCRITICAL
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams CallsHIGH
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social EngineeringHIGH
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain TheftHIGH
- NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoYMEDIUM
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret)HIGH
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector (CrashFix, FileFix, ConsentFix Variants)HIGH
- Lazarus-Linked npm Malware Masquerades as Rollup Polyfills (rollup-packages-polyfill-core, rollup-runtime-polyfill-core, swift-parse-stream, quirky-token, rollup-plugin-polyfill-connect, react-icon-svgs)HIGH
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion TechniquesHIGH
- Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked Maintainer AccountCRITICAL
- Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages CompromisedCRITICAL
- Mastra npm Supply-Chain Compromise (@mastra/* namespace) via Typosquatted 'easy-day-js' — Multi-Stage Cross-Platform InfostealerCRITICAL
- Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign Targeting Cryptocurrency, Web3, and Venture Capital SectorsHIGH
- Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple Certificate Rotation — DPRK UNC1069 / Sapphire Sleet WAVESHAPER.V2CRITICAL
- Axios npm Supply Chain Compromise — WAVESHAPER.V2 Cross-Platform RAT Deployment by UNC1069/Sapphire Sleet (DPRK)CRITICAL
- Axios npm Supply Chain Compromise by Sapphire Sleet (DPRK) — Cross-Platform RAT via Phantom DependencyCRITICAL
- UNC1069 Compromises Axios NPM Package in Supply Chain Attack Deploying WAVESHAPER.V2 Cross-Platform BackdoorCRITICAL
- North Korea (UNC1069) Supply Chain Compromise of Axios NPM Package via Backdoored plain-crypto-js DependencyCRITICAL
- UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure CompromiseCRITICAL
Related CVEs
- CVE-2026-72971
- CVE-2026-70332
- CVE-2026-70130
- CVE-2026-68823
- CVE-2026-68820
- CVE-2026-68816
- CVE-2026-68804
- CVE-2026-68794
- CVE-2026-65813
- CVE-2026-65789
- CVE-2026-65665
- CVE-2026-65657
- CVE-2026-64921
- CVE-2026-64911
- CVE-2026-64910
- CVE-2026-64909
- CVE-2026-64907
- CVE-2026-64903
- CVE-2026-64898
- CVE-2026-63532
- CVE-2026-63526
- CVE-2026-63525
- CVE-2026-63520
- CVE-2026-63518
- CVE-2026-63515
- CVE-2026-62915
- CVE-2026-62914
- CVE-2026-62913
- CVE-2026-62912
- CVE-2026-62911
- CVE-2026-62910
- CVE-2026-62893
- CVE-2026-62890
- CVE-2026-62889
- CVE-2026-62878
- CVE-2026-62869
- CVE-2026-62832
- CVE-2026-62827
- CVE-2026-62824
- CVE-2026-62823