# LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries

> CrowdStrike has reclassified LABYRINTH CHOLLIMA — formerly the umbrella designation for the DPRK's most prolific cyber operations cluster (widely known as Lazarus Group) — into three distinct adversary groups with separate missions, tooling, and organizational affiliations: FAMOUS CHOLLIMA (IT worker fraud and insider threat operations), STARDUST CHOLLIMA (financial theft and cryptocurrency heists, also tracked as APT38/BlueNoroff/Sapphire Sleet), and SILENT CHOLLIMA (military espionage and destructive operations, also tracked as Andariel/Diamond Sleet). This taxonomy split reflects the intelligence community's evolving understanding that what was treated as a single 'Lazarus Group' is actually three operationally distinct units within North Korea's Reconnaissance General Bureau (RGB), each with different Bureau 121 sub-unit assignments, different target sectors, different tooling families, and fundamentally different strategic objectives. The reclassification has major implications for threat detection: defenders tracking 'Lazarus Group' as a monolith are missing that FAMOUS CHOLLIMA's IT worker scheme requires HR/hiring process controls (not network detection), STARDUST CHOLLIMA's SWIFT/crypto operations require financial transaction monitoring, and SILENT CHOLLIMA's espionage requires traditional APT hunting. One detection strategy cannot cover three distinct operational mandates.

- **Published:** 2026-02-12T18:38:00Z
- **Last reviewed:** 2026-02-12T18:38:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0063
- **ID:** TL-2026-0063
- **Severity:** CRITICAL
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Lazarus Group (North Korea)
- **Detections:** 12 · **IOCs:** 36 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-7971, CVE-2023-29059, CVE-2024-21338

## Description

LABYRINTH CHOLLIMA Reclassification: Three Distinct DPRK Adversaries

Background — The Lazarus Monolith Problem:

Since 2009, the cybersecurity industry treated North Korean cyber operations as a single entity: 'Lazarus Group' (CrowdStrike: LABYRINTH CHOLLIMA, Microsoft: ZINC/Diamond Sleet, MITRE: G0032). This created a taxonomy problem — the same designation covered IT worker fraud, billion-dollar bank heists, WannaCry ransomware, Sony Pictures destruction, cryptocurrency theft, defense sector espionage, and nuclear program intelligence gathering. These are fundamentally different operations requiring different skills, infrastructure, and organizational mandates.

CrowdStrike's reclassification acknowledges that LABYRINTH CHOLLIMA was never one group — it was three operationally distinct units sharing some infrastructure and code lineage but operating with separate missions under the RGB umbrella.

The Three New Adversary Designations:

1. FAMOUS CHOLLIMA (formerly BadClone activity cluster)
- Active since: 2018
- Mission: IT worker fraud — obtaining freelance or full-time employment to generate revenue for DPRK
- Microsoft equivalent: Emerging (no direct mapping yet)
- Organizational affiliation: Bureau 121, RGB — revenue generation division
- Primary TTPs: Social engineering, identity fraud, fake LinkedIn/job platform profiles, BeaverTail and InvisibleFerret malware for data theft from compromised employer networks
- Target sectors: Technology companies, remote-first companies, startups — any organization hiring remote IT workers
- Strategic purpose: Generate salary revenue funneled to DPRK regime. Estimated $600M+ annually from IT worker schemes.
- Key operations: Thousands of DPRK IT workers placed in Western companies using stolen/fabricated identities. Workers use laptop farms, VPNs, and AI-generated faces to pass hiring processes. Some deploy malware after gaining trusted insider access.
- Detection challenge: This is an HR/hiring problem, not a network security problem. Traditional SOC tools don't detect fraudulent employees. Requires identity verification, in-person onboarding, and behavioral analysis of remote workers.

2. STARDUST CHOLLIMA (formerly part of Lazarus/BlueNoroff)
- Active since: 2015
- Mission: Large-scale currency generation — financial institution heists and cryptocurrency theft
- Microsoft equivalent: Sapphire Sleet, COPERNICIUM
- MITRE designation: APT38 (G0082), BlueNoroff
- Organizational affiliation: Bureau 121, RGB — likely a specific element dedicated to financial operations
- Primary TTPs: SWIFT transaction manipulation (DYEPACK), cryptocurrency exchange exploitation, DeFi/smart contract exploitation, watering hole attacks on financial sector, spearphishing targeting bank employees, custom malware (QUICKRIDE, NESTEGG, KEYLIME, CLOSESHAVE, BOOTWRECK), Hermes ransomware for evidence destruction
- Target sectors: Banks (SWIFT network), cryptocurrency exchanges, DeFi protocols, venture capital firms, fintech companies
- Strategic purpose: Direct revenue generation for DPRK weapons programs. Estimated $3B+ stolen since 2015. Single largest cryptocurrency theft: $1.5B from Bybit (2025).
- Key operations: Bangladesh Bank heist ($81M, 2016), Ronin Network ($620M, 2022), Harmony Horizon Bridge ($100M, 2022), Atomic Wallet ($35M, 2023), Bybit ($1.5B, 2025), Operation AppleJeus (crypto exchange targeting)
- Detection challenge: Requires financial transaction monitoring, SWIFT message integrity verification, cryptocurrency wallet/smart contract monitoring. Standard endpoint detection misses the financial fraud component.

3. SILENT CHOLLIMA (Andariel)
- Active since: 2007
- Mission: Military espionage, destructive operations, and intelligence gathering for DPRK defense programs
- Microsoft equivalent: Diamond Sleet (formerly ZINC), Onyx Sleet (Andariel subset)
- MITRE designation: Overlaps with G0032 (Lazarus Group) espionage operations
- Organizational affiliation: RGB Office 970 (per UN assessment), Bureau 121 (with low confidence per CrowdStrike)
- Primary TTPs: Zero-day exploitation, watering hole attacks, supply chain compromise (3CX, CyberLink), Operation Dream Job (fake LinkedIn job offers), custom RATs (Manuscrypt, DTrack, LightlessCan, BLINDINGCAN, FudModule rootkit), BYOVD (Bring Your Own Vulnerable Driver) for kernel exploitation
- Target sectors: Defense/aerospace, nuclear energy, government, technology, security researchers
- Strategic purpose: Intelligence collection for DPRK weapons programs (nuclear, missile, submarine). Also conducts destructive operations (Sony Pictures 2014, WannaCry 2017) when politically directed.
- Key operations: Sony Pictures destruction (2014), WannaCry ransomware (2017), Operation Dream Job (2020-ongoing), 3CX supply chain (2023), CyberLink supply chain (2023), Operation SyncHole (2025, watering hole targeting South Korean entities), FudModule rootkit evolution (admin-to-kernel zero-day)
- Detection challenge: Uses cutting-edge techniques — zero-days, supply chain compromise, BYOVD rootkits. Requires advanced threat hunting, supply chain security, and kernel-level monitoring.

Organizational Structure — RGB and Bureau 121:

The Reconnaissance General Bureau (RGB) is North Korea's preeminent intelligence service. Bureau 121 is the cyber warfare division within the RGB, responsible for all three CHOLLIMA groups:

- Bureau 121 operates an estimated 6,800+ cyber warriors (per UN Panel of Experts)
- Operatives deployed globally: China, Russia, Southeast Asia, Africa
- Training: Pyongyang University of Automation (primary), Kim Il Sung University, Kim Chaek University of Technology
- Funding flows: All three groups ultimately fund DPRK regime — FAMOUS and STARDUST generate revenue, SILENT provides strategic intelligence
- Infrastructure sharing: Some C2 infrastructure and code libraries shared between groups, complicating attribution

Why This Reclassification Matters for Defenders:

1. Detection strategy must be tripartite: HR controls for FAMOUS, financial monitoring for STARDUST, APT hunting for SILENT
2. Attribution clarity: 'Lazarus Group' attribution is now meaningless without specifying which sub-group
3. Risk prioritization: A financial institution faces STARDUST, not SILENT. A defense contractor faces SILENT, not FAMOUS. Blanket 'Lazarus' alerting wastes resources.
4. Intelligence sharing: CTI reports must specify which CHOLLIMA group to be actionable
5. Cross-vendor mapping: Microsoft (Diamond/Sapphire/Citrine/Moonstone Sleet), Mandiant (APT38/UNC groups), MITRE (G0032/G0082) all need updated mappings

Implications for Existing Threadlinqs Threats:

Several existing threats in the database attributed to 'Lazarus Group' or 'DPRK' should be reviewed for reclassification to the appropriate CHOLLIMA sub-group based on their operational characteristics.

## MITRE ATT&CK

- T1566 Phishing
- T1189 Drive-by Compromise
- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1543 Create or Modify System Process
- T1053 Scheduled Task/Job
- T1505 Server Software Component
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1622 Debugger Evasion
- T1480 Execution Guardrails
- T1110 Brute Force
- T1056 Input Capture
- T1539 Steal Web Session Cookie
- T1087 Account Discovery
- T1083 File and Directory Discovery
- T1135 Network Share Discovery
- T1518 Software Discovery
- T1217 Browser Information Discovery
- T1005 Data from Local System
- T1115 Clipboard Data
- T1560 Archive Collected Data
- T1567 Exfiltration Over Web Service
- T1071 Application Layer Protocol
- T1001 Data Obfuscation
- T1105 Ingress Tool Transfer
- T1485 Data Destruction
- T1486 Data Encrypted for Impact
- T1561 Disk Wipe
- T1565 Data Manipulation
- T1657 Financial Theft
- T1583 Acquire Infrastructure

## Sources

- [CrowdStrike — LABYRINTH CHOLLIMA Adversary Profile](https://www.crowdstrike.com/adversaries/labyrinth-chollima/)
- [CrowdStrike — FAMOUS CHOLLIMA Adversary Profile (IT Worker Fraud)](https://www.crowdstrike.com/adversaries/famous-chollima/)
- [CrowdStrike — STARDUST CHOLLIMA Adversary Profile (Financial Theft)](https://www.crowdstrike.com/adversaries/stardust-chollima/)
- [CrowdStrike — SILENT CHOLLIMA Adversary Profile (Espionage/Destruction)](https://www.crowdstrike.com/adversaries/silent-chollima/)
- [MITRE ATT&CK — Lazarus Group (G0032)](https://attack.mitre.org/groups/G0032/)
- [MITRE ATT&CK — APT38 (G0082) / Stardust Chollima](https://attack.mitre.org/groups/G0082/)
- [Malpedia — Lazarus Group Actor Profile](https://malpedia.caad.fkie.fraunhofer.de/actor/lazarus_group)
- [Mandiant — APT38: Un-usual Suspects](https://www.mandiant.com/sites/default/files/2021-09/rpt-apt38-2018-web_v5-1.pdf)
- [CISA — North Korean Malicious Cyber Activity (HIDDEN COBRA)](https://us-cert.cisa.gov/ncas/alerts/aa20-239a)
- [Kaspersky — Operation SyncHole: Lazarus Watering Hole in South Korea](https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/)
- [ESET — Gotta Fly: Lazarus Targets the UAV Sector](https://www.welivesecurity.com/en/eset-research/gotta-fly-lazarus-targets-uav-sector/)
- [Microsoft — Moonstone Sleet Emerges as New North Korean Threat Actor](https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0063
