STARDUST CHOLLIMA
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 04/05/2026 16:33
- Updated at
- 04/05/2026 16:33
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 97 attack patterns (mitre), 24 malware, 7 sectors, 20 countries, 100 indicators, 53 vulnerabilities (cve), 2 tool
Aliases
NICKEL GLADSTONE BeagleBoyz Stardust Chollima Sapphire Sleet COPERNICIUM Bluenoroff APT38
Description
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
- Kaspersky Lazarus Under The Hood Blog 2017
- Microsoft Threat Actor Naming July 2023
- FireEye APT38 Oct 2018
- SecureWorks NICKEL GLADSTONE profile Sept 2021
- DOJ North Korea Indictment Feb 2021
- CrowdStrike GTR 2021 June 2021
- CrowdStrike Stardust Chollima Profile April 2018
- FireEye APT38 Oct 2018
- CISA AA20-239A BeagleBoyz August 2020
- mitre-attack (G0082)
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
19 MITREs 6 Malwares 13 Observables 1 APT
Attack patterns (MITRE) (97)
-
T1041 usesExfiltration Over C2 Channel MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
T1115 usesClipboard Data MITRE
-
T1027.002 usesSoftware Packing MITRE
-
-
T1049 usesSystem Network Connections Discovery MITRE
-
T1562.003 usesImpair Command History Logging MITRE
-
T1560 usesArchive Collected Data MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
T1555.001 usesKeychain MITRE
-
T1132 usesData Encoding MITRE
Malware (24)
-
RealTimeTroy usesFamily
-
softwareupdate.app usesFamily
-
HOPLIGHT uses
-
DarkKomet usesFamily
-
com.apple.cli usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SneakMain usesFamily
-
LessonOne usesFamily
-
ZoomClutch usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DownTroy usesFamily
-
RooTroy usesFamily
-
SilentSiphon usesFamily
-
TeamsClutch usesFamily
Sectors (7)
-
Legal targets
-
Finance targets
-
Financial organizations targets
-
Fintech targets
-
Technology targets
-
Banking institutions targets
-
Government targets
Countries (20)
-
Italy targets
-
Australia targets
-
Russian Federation targets
-
United States of America targets
-
Poland targets
-
Hong Kong targets
-
Thailand targets
-
Ukraine targets
-
Viet Nam targets
-
Czechia targets
-
France targets
-
India targets
Indicators (100)
-
1ddef717bf82e61bf79b24570ab68bf899f420a62ebd4715c2ae0c036da5ce05related -
d6d367453c513445313be7339666e4faeeebeae71620c187012ea5ae2901df34related -
123543c7a5523a15a933e32477b8cba4cd79a680bb69ef2dba178700bfb9ec07related -
docstream.onlinerelated -
d78cfc079feeee356110d8d88a52c818025dc1f78fda4d1acd5f987d46886305related -
5072b28399c874f92e71793fa13207d946a28a2f5903365ac11ddf666d15d086related -
cloud.globalbrains.corelated -
915a1924ff9299cbf28e48d7e1df5a09d7fe0d6a664564aea84e63f230eaa96erelated -
lemniscap.ccrelated
Vulnerabilities (CVE) (53)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user …
- Attack vector
- NETWORK
- Published
- 05/04/2024
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- Attack vector
- Network
- Published
- 15/02/2024
- Modified
- 21/12/2025
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to …
- Attack vector
- Network
- Published
- 05/10/2023
- Modified
- 21/12/2025
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow …
- Attack vector
- Network
- Published
- 10/10/2023
- Modified
- 21/12/2025
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
- Attack vector
- Network
- Published
- 20/11/2024
- Modified
- 21/12/2025
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to …
- Attack vector
- NETWORK
- Published
- 17/01/2024
- Modified
- 21/12/2025
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.
- Attack vector
- Network
- Published
- 30/11/2023
- Modified
- 21/12/2025
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the …
- Attack vector
- Network
- Published
- 25/06/2025
- Modified
- 21/12/2025
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow …
- Attack vector
- ADJACENT_NETWORK
- Published
- 12/09/2024
- Modified
- 21/12/2025
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/04/2017
- Modified
- 22/04/2026
Tool (2)
-
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft…
-
Mimikatz usesThe MITRE Corporation Confidence 100
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of…