STARDUST CHOLLIMA
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 04/05/2026 16:33
- Updated at
- 04/05/2026 16:33
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 97 attack patterns (mitre), 24 malware, 7 sectors, 20 countries, 100 indicators, 53 vulnerabilities (cve), 2 tool
Aliases
NICKEL GLADSTONE BeagleBoyz Stardust Chollima Sapphire Sleet COPERNICIUM Bluenoroff APT38
Description
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
- Kaspersky Lazarus Under The Hood Blog 2017
- Microsoft Threat Actor Naming July 2023
- FireEye APT38 Oct 2018
- SecureWorks NICKEL GLADSTONE profile Sept 2021
- DOJ North Korea Indictment Feb 2021
- CrowdStrike GTR 2021 June 2021
- CrowdStrike Stardust Chollima Profile April 2018
- FireEye APT38 Oct 2018
- CISA AA20-239A BeagleBoyz August 2020
- mitre-attack (G0082)
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
19 MITREs 6 Malwares 13 Observables 1 APT
Attack patterns (MITRE) (97)
Malware (24)
-
RealTimeTroy usesFamily
-
softwareupdate.app usesFamily
-
HOPLIGHT uses
-
DarkKomet usesFamily
-
com.apple.cli usesFamily
-
SneakMain usesFamily
-
LessonOne usesFamily
-
ZoomClutch usesFamily
-
DownTroy usesFamily
-
RooTroy usesFamily
-
SilentSiphon usesFamily
-
TeamsClutch usesFamily
Sectors (7)
-
Legal targets
-
Finance targets
-
Financial organizations targets
-
Fintech targets
-
Technology targets
-
Banking institutions targets
-
Government targets
Countries (20)
-
Italy targets
-
Australia targets
-
Russian Federation targets
-
United States of America targets
-
Poland targets
-
Hong Kong targets
-
Thailand targets
-
Ukraine targets
-
Viet Nam targets
-
Czechia targets
-
France targets
-
India targets
Indicators (100)
-
uw04webzoom.usrelated -
3315e5a4590e430550a4d85d0caf5f521d421a2966b23416fcfc275a5fd2629arelated -
b448381f244dc0072abd4f52e01ca93efaebb2c0a8ea8901c4725ecb1b2b0656related -
real-update.xyzrelated -
http://signsafe.xyz/updaterelated -
googleservice.icurelated -
support.video-meeting.onlinerelated -
fastercapital.ccrelated -
c56a97efd6d3470e14193ac9e194fa46d495e3dddc918219cca530b90f01d11erelated -
46db9f2fc879bf643a8f05e2b35879b235cbb04aa06fe548f0bc7c7c02483cf3related -
c59ac795c44edfeba5266c2cf39d7d4b5f6a30aba224f7977abc228e7f353ee1related -
8e234482db790fa0a3d2bf5f7084ec4cfb74bffd5f6cbdc5abdbc1350f58e3ferelated
Vulnerabilities (CVE) (53)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user …
- Attack vector
- NETWORK
- Published
- 05/04/2024
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- Attack vector
- Network
- Published
- 15/02/2024
- Modified
- 21/12/2025
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to …
- Attack vector
- Network
- Published
- 05/10/2023
- Modified
- 21/12/2025
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow …
- Attack vector
- Network
- Published
- 10/10/2023
- Modified
- 21/12/2025
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
- Attack vector
- Network
- Published
- 20/11/2024
- Modified
- 21/12/2025
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to …
- Attack vector
- NETWORK
- Published
- 17/01/2024
- Modified
- 21/12/2025
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.
- Attack vector
- Network
- Published
- 30/11/2023
- Modified
- 21/12/2025
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the …
- Attack vector
- Network
- Published
- 25/06/2025
- Modified
- 21/12/2025
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow …
- Attack vector
- ADJACENT_NETWORK
- Published
- 12/09/2024
- Modified
- 21/12/2025
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/04/2017
- Modified
- 22/04/2026
Tool (2)
-
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft…
-
Mimikatz usesThe MITRE Corporation Confidence 100
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of…