Threat Intelligence, Critical Infrastructure Security, Government security

North Korean hacking group Labyrinth Chollima splits into 3 specialized units

A prominent North Korean state-sponsored hacking group, Labyrinth Chollima, has reportedly fragmented into three distinct entities, each with its own specialized objectives and tools, according to CrowdStrike. This strategic evolution aims to enhance the efficiency of cyberattacks orchestrated by the Democratic People's Republic of Korea (DPRK) regime, according to Tech Radar.

The three newly identified groups are Labyrinth Chollima, Golden Chollima, and Pressure Chollima. The original Labyrinth Chollima continues its focus on cyber-espionage, targeting military, government, and nuclear sectors in the US, Europe, and South Korea. Golden Chollima is now dedicated to cryptocurrency theft, specifically targeting small fintech firms across the US, Canada, India, South Korea, and Western Europe. Pressure Chollima also focuses on cryptocurrency heists but concentrates on centralized exchanges and technology companies in Western nations, having been linked to record-breaking crypto thefts. These groups often employ social engineering tactics, such as fake job postings on platforms like LinkedIn, to infiltrate organizations and deploy malware.

This division of Labyrinth Chollima into specialized units highlights North Korea's persistent need for revenue to fund its military ambitions, despite potential trade relations. The increased sophistication and specialization of these threat actors underscore the ongoing challenges for global cybersecurity.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds