Threat reportAPTTL-2026-0063
LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries (TL-2026-0063) is a critical-severity advanced persistent threat campaign, first published 2026-02-12. It is attributed to Lazarus Group (North Korea) with high confidence, references 3 CVEs (CVE-2024-7971, CVE-2023-29059, CVE-2024-21338), maps to 50 MITRE ATT&CK techniques (T1001, T1005, T1027), and is covered by 12 detection rules and 36 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 50MITRE ATT&CK
- Actors
- 1Lazarus Group
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 36Indicators of compromise
Key facts for TL-2026-0063
- Threat ID
- TL-2026-0063
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Lazarus Group
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- MIXED
- Target sectors
- Financial Services, Cryptocurrency, Technology, Defense, Aerospace, Government, Nuclear Energy, Remote-First Companies, Startups
- Target regions
- Global, United States, South Korea, Japan, Europe, Southeast Asia
- Detection rules
- 12
- Indicators of compromise
- 36
Malware and tooling in LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
Malware and tooling: BLINDINGCAN RAT — sophisticated remote access trojan attributed to DPRK, BOOTWRECK MBR wiper — STARDUST CHOLLIMA deploys custom MBR wiper to destroy evidence after financial theft operations, rendering systems unrecoverable, BeaverTail JavaScript malware — FAMOUS CHOLLIMA deploys via trojanized npm packages to steal browser credentials and cryptocurrency wallets from compromised employer systems, BeaverTail infostealer — JavaScript/Node.js malware stealing browser credentials and cryptocurrency wallets, deployed via fake job coding challenges (Contagious Interview), BeaverTail infostealer — browser credential theft + cryptocurrency wallet exfiltration deployed via fake job coding challenges, DTrack — SILENT CHOLLIMA reconnaissance and data theft RAT deployed in espionage and pre-ransomware operations across multiple sectors, DYEPACK — STARDUST CHOLLIMA custom SWIFT transaction manipulation malware that creates, deletes, and alters SWIFT records and intercepts PDF printouts, Destover/Jokra destructive wiper — data and MBR destruction capability used in Sony Pictures (2014) and Dark Seoul (2013), Destructive wiper (Destover/Jokra family) — data destruction capability used in retaliatory and coercive operations, FudModule rootkit — SILENT CHOLLIMA kernel-level rootkit using BYOVD (admin-to-kernel zero-day CVE-2024-21338 in appid.sys) for deep system compromise, H0lyGh0st ransomware — secondary DPRK ransomware family targeting small/medium businesses, InvisibleFerret Python backdoor — FAMOUS CHOLLIMA secondary payload for persistent access to employer networks after initial BeaverTail deployment
How LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries works
CrowdStrike has reclassified LABYRINTH CHOLLIMA — formerly the umbrella designation for the DPRK's most prolific cyber operations cluster (widely known as Lazarus Group) — into three distinct adversary groups with separate missions, tooling, and organizational affiliations: FAMOUS CHOLLIMA (IT worker fraud and insider threat operations), STARDUST CHOLLIMA (financial theft and cryptocurrency heists, also tracked as APT38/BlueNoroff/Sapphire Sleet), and SILENT CHOLLIMA (military espionage and destructive operations, also tracked as Andariel/Diamond Sleet). This taxonomy split reflects the intelligence community's evolving understanding that what was treated as a single 'Lazarus Group' is actually three operationally distinct units within North Korea's Reconnaissance General Bureau (RGB), each with different Bureau 121 sub-unit assignments, different target sectors, different tooling families, and fundamentally different strategic objectives. The reclassification has major implications for threat detection: defenders tracking 'Lazarus Group' as a monolith are missing that FAMOUS CHOLLIMA's IT worker scheme requires HR/hiring process controls (not network detection), STARDUST CHOLLIMA's SWIFT/crypto operations require financial transaction monitoring, and SILENT CHOLLIMA's espionage requires traditional APT hunting. One detection strategy cannot cover three distinct operational mandates.
LABYRINTH CHOLLIMA Reclassification: Three Distinct DPRK Adversaries
Background — The Lazarus Monolith Problem:
Since 2009, the cybersecurity industry treated North Korean cyber operations as a single entity: 'Lazarus Group' (CrowdStrike: LABYRINTH CHOLLIMA, Microsoft: ZINC/Diamond Sleet, MITRE: G0032). This created a taxonomy problem — the same designation covered IT worker fraud, billion-dollar bank heists, WannaCry ransomware, Sony Pictures destruction, cryptocurrency theft, defense sector espionage, and nuclear program intelligence gathering. These are fundamentally different operations requiring different skills, infrastructure, and organizational mandates.
CrowdStrike's reclassification acknowledges that LABYRINTH CHOLLIMA was never one group — it was three operationally distinct units sharing some infrastructure and code lineage but operating with separate missions under the RGB umbrella.
The Three New Adversary Designations:
1. FAMOUS CHOLLIMA (formerly BadClone activity cluster) - Active since: 2018 - Mission: IT worker fraud — obtaining freelance or full-time employment to generate revenue for DPRK - Microsoft equivalent: Emerging (no direct mapping yet) - Organizational affiliation: Bureau 121, RGB — revenue generation division - Primary TTPs: Social engineering, identity fraud, fake LinkedIn/job platform profiles, BeaverTail and InvisibleFerret malware for data theft from compromised employer networks - Target sectors: Technology companies, remote-first companies, startups — any organization hiring remote IT workers - Strategic purpose: Generate salary revenue funneled to DPRK regime. Estimated $600M+ annually from IT worker schemes. - Key operations: Thousands of DPRK IT workers placed in Western companies using stolen/fabricated identities. Workers use laptop farms, VPNs, and AI-generated faces to pass hiring processes. Some deploy malware after gaining trusted insider access. - Detection challenge: This is an HR/hiring problem, not a network security problem. Traditional SOC tools don't detect fraudulent employees. Requires identity verification, in-person onboarding, and behavioral analysis of remote workers.
2. STARDUST CHOLLIMA (formerly part of Lazarus/BlueNoroff) - Active since: 2015 - Mission: Large-scale currency generation — financial institution heists and cryptocurrency theft - Microsoft equivalent: Sapphire Sleet, COPERNICIUM - MITRE designation: APT38 (G0082), BlueNoroff - Organizational affiliation: Bureau 121, RGB — likely a specific element dedicated to financial operations - Primary TTPs: SWIFT transaction manipulation (DYEPACK), cryptocurrency exchange exploitation, DeFi/smart contract exploitation, watering hole attacks on financial sector, spearphishing targeting bank employees, custom malware (QUICKRIDE, NESTEGG, KEYLIME, CLOSESHAVE, BOOTWRECK), Hermes ransomware for evidence destruction - Target sectors: Banks (SWIFT network), cryptocurrency exchanges, DeFi protocols, venture capital firms, fintech companies - Strategic purpose: Direct revenue generation for DPRK weapons programs. Estimated $3B+ stolen since 2015. Single largest cryptocurrency theft: $1.5B from Bybit (2025). - Key operations: Bangladesh Bank heist ($81M, 2016), Ronin Network ($620M, 2022), Harmony Horizon Bridge ($100M, 2022), Atomic Wallet ($35M, 2023), Bybit ($1.5B, 2025), Operation AppleJeus (crypto exchange targeting) - Detection challenge: Requires financial transaction monitoring, SWIFT message integrity verification, cryptocurrency wallet/smart contract monitoring. Standard endpoint detection misses the financial fraud component.
3. SILENT CHOLLIMA (Andariel) - Active since: 2007 - Mission: Military espionage, destructive operations, and intelligence gathering for DPRK defense programs - Microsoft equivalent: Diamond Sleet (formerly ZINC), Onyx Sleet (Andariel subset) - MITRE designation: Overlaps with G0032 (Lazarus Group) espionage operations - Organizational affiliation: RGB Office 970 (per UN assessment), Bureau 121 (with low confidence per CrowdStrike) - Primary TTPs: Zero-day exploitation, watering hole attacks, supply chain compromise (3CX, CyberLink), Operation Dream Job (fake LinkedIn job offers), custom RATs (Manuscrypt, DTrack, LightlessCan, BLINDINGCAN, FudModule rootkit), BYOVD (Bring Your Own Vulnerable Driver) for kernel exploitation - Target sectors: Defense/aerospace, nuclear energy, government, technology, security researchers - Strategic purpose: Intelligence collection for DPRK weapons programs (nuclear, missile, submarine). Also conducts destructive operations (Sony Pictures 2014, WannaCry 2017) when politically directed. - Key operations: Sony Pictures destruction (2014), WannaCry ransomware (2017), Operation Dream Job (2020-ongoing), 3CX supply chain (2023), CyberLink supply chain (2023), Operation SyncHole (2025, watering hole targeting South Korean entities), FudModule rootkit evolution (admin-to-kernel zero-day) - Detection challenge: Uses cutting-edge techniques — zero-days, supply chain compromise, BYOVD rootkits. Requires advanced threat hunting, supply chain security, and kernel-level monitoring.
Organizational Structure — RGB and Bureau 121:
The Reconnaissance General Bureau (RGB) is North Korea's preeminent intelligence service. Bureau 121 is the cyber warfare division within the RGB, responsible for all three CHOLLIMA groups:
- Bureau 121 operates an estimated 6,800+ cyber warriors (per UN Panel of Experts) - Operatives deployed globally: China, Russia, Southeast Asia, Africa - Training: Pyongyang University of Automation (primary), Kim Il Sung University, Kim Chaek University of Technology - Funding flows: All three groups ultimately fund DPRK regime — FAMOUS and STARDUST generate revenue, SILENT provides strategic intelligence - Infrastructure sharing: Some C2 infrastructure and code libraries shared between groups, complicating attribution
Why This Reclassification Matters for Defenders:
1. Detection strategy must be tripartite: HR controls for FAMOUS, financial monitoring for STARDUST, APT hunting for SILENT 2. Attribution clarity: 'Lazarus Group' attribution is now meaningless without specifying which sub-group 3. Risk prioritization: A financial institution faces STARDUST, not SILENT. A defense contractor faces SILENT, not FAMOUS. Blanket 'Lazarus' alerting wastes resources. 4. Intelligence sharing: CTI reports must specify which CHOLLIMA group to be actionable 5. Cross-vendor mapping: Microsoft (Diamond/Sapphire/Citrine/Moonstone Sleet), Mandiant (APT38/UNC groups), MITRE (G0032/G0082) all need updated mappings
Implications for Existing Threadlinqs Threats:
Several existing threats in the database attributed to 'Lazarus Group' or 'DPRK' should be reviewed for reclassification to the appropriate CHOLLIMA sub-group based on their operational characteristics.
MITRE ATT&CK techniques used in TL-2026-0063
command-and-control
T1001 Data Obfuscation; T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1560 Archive Collected Data
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1480 Execution Guardrails; T1622 Debugger Evasion
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
discovery
T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
credential-access
T1110 Brute Force; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
initial-access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1561 Disk Wipe; T1565 Data Manipulation; T1657 Financial Theft
persistence
T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
resource-development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
defense-impairment
Remediation for LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
Patches
- Apply all Chrome/Chromium patches — SILENT CHOLLIMA (Citrine Sleet) exploited Chromium zero-day CVE-2024-7971
- Patch 3CX desktop application — SILENT CHOLLIMA compromised 3CX supply chain (CVE-2023-29059)
- Update CyberLink software — SILENT CHOLLIMA distributed trojanized CyberLink installer
- Patch Korean financial software (INISAFE, MagicLine4NX) — SILENT CHOLLIMA exploited for Operation SyncHole watering holes
Immediate actions
- Map existing 'Lazarus Group' alerts to the appropriate CHOLLIMA sub-group based on TTP patterns — financial TTPs = STARDUST, IT worker = FAMOUS, espionage = SILENT
- Audit remote IT worker hiring pipeline for identity verification gaps — FAMOUS CHOLLIMA targets organizations with weak remote onboarding
- Review SWIFT transaction monitoring for anomalous patterns — STARDUST CHOLLIMA manipulates SWIFT messages using DYEPACK malware
- Verify supply chain integrity for software dependencies — SILENT CHOLLIMA compromised 3CX and CyberLink supply chains
- Monitor cryptocurrency wallet transactions for unauthorized transfers — STARDUST CHOLLIMA responsible for $3B+ in crypto theft
Workarounds
- For FAMOUS CHOLLIMA: require video-on interviews with identity verification, cross-reference applicant photos against known DPRK IT worker databases maintained by OFAC
- For STARDUST CHOLLIMA: implement withdrawal delays and manual approval for large cryptocurrency transfers; use hardware wallets with multi-signature requirements
- For SILENT CHOLLIMA: deploy canary tokens in defense/aerospace environments; monitor for Operation Dream Job lure documents (fake job offers from defense contractors)
- Cross-group: monitor for shared DPRK infrastructure indicators — IP ranges associated with DPRK operations in China, Russia, Southeast Asia
Longer-term hardening
- Implement tripartite detection strategy: HR controls (FAMOUS), financial monitoring (STARDUST), APT hunting (SILENT)
- Deploy behavioral analytics for remote worker sessions — detect laptop farms, VPN anomalies, unusual working patterns indicative of FAMOUS CHOLLIMA
- Implement SWIFT Customer Security Programme (CSP) with mandatory controls — dual authorization, transaction limits, anomaly detection
- Deploy kernel-level monitoring for BYOVD and rootkit detection — SILENT CHOLLIMA uses FudModule rootkit with zero-day kernel exploits
- Establish supply chain security program with SBOM validation, code signing, and dependency scanning for SILENT CHOLLIMA supply chain attacks
- Cross-reference CTI feeds for all three CHOLLIMA groups — infrastructure sharing means indicators may overlap between groups
CVEs associated with LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
Weaknesses (CWE) in LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
Timeline of LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
- SILENT CHOLLIMA (Andariel) begins operations. Earliest known DPRK cyber operations focused on South Korean government and military targets. Initially conducted DDoS attacks against South Korean websites. Operated under RGB Office 970 per UN assessment.
- LABYRINTH CHOLLIMA umbrella designation established by CrowdStrike. At this point, all DPRK cyber operations tracked as a single entity. Bureau 121 of RGB identified as organizational home. Industry broadly adopts 'Lazarus Group' as the catch-all designation.
- SILENT CHOLLIMA conducts destructive attack on Sony Pictures Entertainment in retaliation for 'The Interview' film. Wiped systems, leaked confidential data, threatened employees. First major DPRK destructive cyber operation attributed publicly. FBI formally attributes to North Korea. Source: FBI Flash Alert.
- STARDUST CHOLLIMA (BlueNoroff/APT38) begins distinct financial operations. Focuses on SWIFT network exploitation and bank heists. CrowdStrike assesses this likely represents a specific Bureau 121 element dedicated to currency generation for DPRK weapons programs.
- STARDUST CHOLLIMA executes the Bangladesh Bank heist via SWIFT network manipulation. Attempted to steal $951M, successfully transferred $81M before a spelling error flagged the remaining transfers. Used DYEPACK malware to manipulate SWIFT transaction records. Most audacious state-sponsored bank robbery in history. Source: Mandiant APT38 report.
- SILENT CHOLLIMA (attributed) deploys WannaCry ransomware globally. Exploits EternalBlue (CVE-2017-0144). Infects 200,000+ systems in 150 countries. Causes $4-8B in damages. NHS (UK) severely impacted. Despite financial appearance, assessed as destructive/disruptive operation, not revenue generation. Source: NSA/FBI attribution.
- FAMOUS CHOLLIMA (BadClone activity cluster) begins IT worker fraud operations. DPRK operatives use stolen/fabricated identities to obtain remote IT jobs at Western companies. Revenue generated from salaries funneled to DPRK regime. Represents a fundamentally different operational model from traditional cyber operations.
- SILENT CHOLLIMA launches Operation Dream Job — fake LinkedIn job offers targeting defense/aerospace sector employees. Lure documents impersonate defense contractors (Lockheed Martin, BAE Systems, Boeing). Delivers custom RATs (BLINDINGCAN, LightlessCan) for espionage. Campaign continues through 2025+. Source: ESET, ClearSky, McAfee.
- STARDUST CHOLLIMA steals $620M from Ronin Network (Axie Infinity sidechain). Compromised 5 of 9 validator nodes via social engineering of Sky Mavis employees through fake job offers. Largest cryptocurrency theft at the time. FBI attributes to 'Lazarus Group' — more precisely STARDUST CHOLLIMA financial operations.
- SILENT CHOLLIMA compromises 3CX desktop application supply chain (CVE-2023-29059). Trojanized installer distributed to 600,000+ organizations. Multi-stage attack: compromised 3CX build environment via compromised Trading Technologies application. First documented double supply chain attack. Targets: cryptocurrency companies for follow-on STARDUST CHOLLIMA operations.
- SILENT CHOLLIMA (tracked by Microsoft as Citrine Sleet) exploits Chromium zero-day CVE-2024-7971 (V8 type confusion). Targets cryptocurrency sector. Deploys FudModule rootkit with admin-to-kernel zero-day CVE-2024-21338 (Windows appid.sys driver). Demonstrates cutting-edge offensive capability. Source: Microsoft Threat Intelligence.
- CrowdStrike formally reclassifies LABYRINTH CHOLLIMA into three distinct adversary groups: FAMOUS CHOLLIMA (IT worker fraud), STARDUST CHOLLIMA (financial theft), SILENT CHOLLIMA (espionage/destruction). Represents the most significant taxonomy change for DPRK cyber operations since initial tracking. Adversary Universe pages updated with separate profiles, TTPs, and organizational affiliations.
- STARDUST CHOLLIMA executes the Bybit cryptocurrency exchange heist — $1.5B stolen in the largest single cryptocurrency theft in history. Demonstrates continued evolution of financial operations capability. The magnitude confirms DPRK cryptocurrency theft is a strategic national revenue program, not opportunistic criminal activity.
- SILENT CHOLLIMA conducts Operation SyncHole — sophisticated watering hole campaign targeting South Korean entities. Exploits vulnerabilities in Korean financial software (INISAFE CrossWeb EX, MagicLine4NX). Deploys Bankshot, DRATzarus, wAgentTea, and PostNapTea malware. Source: Kaspersky SecureList.
- SILENT CHOLLIMA targets the UAV (unmanned aerial vehicle) sector. ESET documents 'Gotta Fly' campaign using QuanPinLoader, ScoringMathTea, and BURNBOOK malware. Targets defense/aerospace companies developing drone technology. Demonstrates continued intelligence collection for DPRK military modernization programs. Source: ESET Research.
- Threadlinqs analysis: The LABYRINTH CHOLLIMA split is the most important DPRK taxonomy change since initial tracking. Three groups with three different missions require three different detection strategies. The industry's habit of attributing everything to 'Lazarus Group' created a false sense of understanding — defenders thought they knew their adversary but were actually conflating three distinct threats. FAMOUS CHOLLIMA is not a cyber threat — it's an HR/insider threat requiring hiring process controls. STARDUST CHOLLIMA requires financial transaction monitoring that most SOCs don't have. SILENT CHOLLIMA requires advanced APT hunting and supply chain security. One detection strategy covering 'Lazarus' = zero detection strategies covering three distinct threats.
- As of 2026-05-29, this CRITICAL DPRK-APT reclassification threat remains ACTIVE: CrowdStrike's Jan 29, 2026 split of LABYRINTH CHOLLIMA stands, and the underlying operations are escalating, not disrupted. The IT-worker scheme is the most active DPRK attack form (~2/day in 2026), 2025 thefts hit a record $2.02B, and financial services are now a top target despite ongoing arrests.
Sources cited for LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries
- CrowdStrike — LABYRINTH CHOLLIMA Adversary Profile
- CrowdStrike — FAMOUS CHOLLIMA Adversary Profile (IT Worker Fraud)
- CrowdStrike — STARDUST CHOLLIMA Adversary Profile (Financial Theft)
- CrowdStrike — SILENT CHOLLIMA Adversary Profile (Espionage/Destruction)
- MITRE ATT&CK — Lazarus Group (G0032)
- MITRE ATT&CK — APT38 (G0082) / Stardust Chollima
- Malpedia — Lazarus Group Actor Profile
- Mandiant — APT38: Un-usual Suspects
- CISA — North Korean Malicious Cyber Activity (HIDDEN COBRA)
- Kaspersky — Operation SyncHole: Lazarus Watering Hole in South Korea
- ESET — Gotta Fly: Lazarus Targets the UAV Sector
- Microsoft — Moonstone Sleet Emerges as New North Korean Threat Actor
Detection coverage for TL-2026-0063
As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0063 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.