Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-03

Stardust Chollima

As of 2026-09-30, Stardust Chollima is a threat actor tracked by Threadlinqs Intelligence across 35 threats spanning supply chain, apt, zero day. ATT&CK coverage spans 227 techniques across 16 tactics in 35 of 35 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1041 (Exfiltration Over C2 Channel).

Tracked threats
3519 critical · 14 high · 2 medium
First seen
2026-03-09
Last seen
2026-09-26
ATT&CK techniques
227across 35 of 35 threats
Related CVEs
60Referenced by its activity
35 tracked threat(s) · Categories: SUPPLY_CHAIN, APT, ZERO_DAY, VULNERABILITY, MALWARE, THREAT_INTEL, CAMPAIGN, PHISHING

Activity timeline

Stardust Chollima appears in 35 tracked threats between and ; the busiest month was 2026-07 with 13 reports.

ATT&CK techniques observed

227 techniques observed across 35 of 35 tracked threats · Stealth (formerly Defense Evasion) (46), Resource Development (23), Command and Control (22), Persistence (22), Discovery (19), Execution (18)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 27 of 35 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 27 of 35 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 22 of 35 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 20 of 35 tracked threats
  • T1005 Data from Local System — Collectionobserved in 19 of 35 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 18 of 35 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 17 of 35 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 17 of 35 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 16 of 35 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 15 of 35 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 15 of 35 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 15 of 35 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 14 of 35 tracked threats
  • T1059.001 PowerShell — Executionobserved in 14 of 35 tracked threats
  • T1204 User Execution — Executionobserved in 13 of 35 tracked threats

Tracked threats

Related CVEs

40 of 60 CVEs referenced by tracked Stardust Chollima activity