LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries — Threadlinqs Intelligence
As of 2026-05-30, LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries is a critical-severity apt threat attributed to Lazarus Group (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-0063 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: Lazarus Group · North Korea (DPRK) · MIXED
CrowdStrike has reclassified LABYRINTH CHOLLIMA — formerly the umbrella designation for the DPRK's most prolific cyber operations cluster (widely known as Lazarus Group) — into three distinct
LABYRINTH CHOLLIMA Reclassification: Three Distinct DPRK Adversaries
Background — The Lazarus Monolith Problem:
Since 2009, the cybersecurity industry treated North Korean cyber operations as a single entity: 'Lazarus Group' (CrowdStrike: LABYRINTH CHOLLIMA, Microsoft: ZINC/Diamond Sleet, MITRE: G0032). This created a taxonomy problem — the same designation covered IT worker fraud, billion-dollar bank heists, WannaCry ransomware, Sony Pictures destruction, cryptocurrency theft, defense sector espionage, and nuclear program intelligence gathering. These are fundamentally different operations requiring different skills, infrastructure, and organizational mandates.
CrowdStrike's reclassification acknowledges that LABYRINTH CHOLLIMA was never one group — it was three operationally distinct units sharing some infrastructure and code lineage but operating with separate missions under the RGB umbrella.
The Three New Adversary Designations:
1. FAMOUS CHOLLIMA (formerly BadClone activity cluster)
- Active since: 2018
- Mission: IT worker fraud — obtaining freelance or full-time employment to generate revenue for DPRK
- Microsoft equivalent: Emerging (no direct mapping yet)
- Organizational affiliation: Bureau 121, RGB — revenue generation division
- Primary TTPs: Social engineering, identity fraud, fake LinkedIn/job platform profiles, BeaverTail and InvisibleFerret malware for data theft from compromised employer networks
- Target sectors: Technology companies, remote-first companies, startups — any organization hiring remote IT workers
- Strategic purpose: Generate salary revenue funneled to DPRK regime. Estimated $600M+ annually from IT worker schemes.
- Key operations: Thousands of DPRK IT workers placed in Western companies using stolen/fabricated identities. Workers use laptop farms, VPNs, and AI-generated faces to pass hiring processes. Some deploy malware after gaining trusted insider access.
- Detection challenge: This is an HR/hiring problem, not a network security problem. Traditional SOC tools don't detect fraudulent employees. Requires identity verification, in-person onboarding, and behavioral analysis of remote workers.
2. STARDUST CHOLLIMA (formerly part of Lazarus/BlueNoroff)
- Active since: 2015
- Mission: Large-scale currency generation — financial institution heists and cryptocurrency theft
- Microsoft equivalent: Sapphire Sleet, COPERNICIUM
- MITRE designation: APT38 (G0082), BlueNoroff
- Organizational affiliation: Bureau 121, RGB — likely a specific element dedicated to financial operations
- Primary TTPs: SWIFT transaction manipulation (DYEPACK), cryptocurrency exchange exploitation, DeFi/smart contract exploitation, watering hole attacks on financial sector, spearphishing targeting bank employees, custom malware (QUICKRIDE, NESTEGG, KEYLIME, CLOSESHAVE, BOOTWRECK), Hermes ransomware for evidence destruction
- Target sectors: Banks (SWIFT network), cryptocurrency exchanges, DeFi protocols, venture capital firms, fintech companies
- Strategic purpose: Direct revenue generation for DPRK weapons programs. Estimated $3B+ stolen since 2015. Single largest cryptocurrency theft: $1.5B from Bybit (2025).
- Key operations: Bangladesh Bank heist ($81M, 2016), Ronin Network ($620M, 2022), Harmony Horizon Bridge ($100M, 2022), Atomic Wallet ($35M, 2023), Bybit ($1.5B, 2025), Operation AppleJeus (crypto exchange targeting)
- Detection challenge: Requires financial transaction monitoring, SWIFT message integrity verification, cryptocurrency wallet/smart contract monitoring. Standard endpoint detection misses the financial fraud component.
3. SILENT CHOLLIMA (Andariel)
- Active since: 2007
- Mission: Military espionage, destructive operations, and intelligence gathering for DPRK defense programs
- Microsoft equivalent: Diamond Sleet (formerly ZINC), Onyx Sleet (Andariel subset)
- MITRE designation: Overlaps with G0032 (Lazarus Group) espionage operations
- Organizational affiliation: RGB Office 970 (per UN assessment), B
Weaknesses (CWE)
CWE-94, CWE-426, CWE-269, CWE-502
Target sectors: Financial Services, Cryptocurrency, Technology, Defense, Aerospace, Government, Nuclear Energy, Remote-First Companies, Startups
Target regions: Global, United States, South Korea, Japan, Europe, Southeast Asia
Detections & IOCs
As of 2026-07-28, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2024-7971, CVE-2023-29059, CVE-2024-21338, T1566, T1566, T1189, T1195, T1199, T1059, T1059, T1059, T1059, T1059