STARDUST CHOLLIMA
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 04/05/2026 16:33
- Updated at
- 04/05/2026 16:33
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 97 attack patterns (mitre), 24 malware, 7 sectors, 20 countries, 100 indicators, 53 vulnerabilities (cve), 2 tool
Aliases
NICKEL GLADSTONE BeagleBoyz Stardust Chollima Sapphire Sleet COPERNICIUM Bluenoroff APT38
Description
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
- Kaspersky Lazarus Under The Hood Blog 2017
- Microsoft Threat Actor Naming July 2023
- FireEye APT38 Oct 2018
- SecureWorks NICKEL GLADSTONE profile Sept 2021
- DOJ North Korea Indictment Feb 2021
- CrowdStrike GTR 2021 June 2021
- CrowdStrike Stardust Chollima Profile April 2018
- FireEye APT38 Oct 2018
- CISA AA20-239A BeagleBoyz August 2020
- mitre-attack (G0082)
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
19 MITREs 6 Malwares 13 Observables 1 APT
Attack patterns (MITRE) (97)
-
T1041 usesExfiltration Over C2 Channel MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
T1115 usesClipboard Data MITRE
-
T1027.002 usesSoftware Packing MITRE
-
-
T1049 usesSystem Network Connections Discovery MITRE
-
T1562.003 usesImpair Command History Logging MITRE
-
T1560 usesArchive Collected Data MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
T1555.001 usesKeychain MITRE
-
T1132 usesData Encoding MITRE
Malware (24)
-
RealTimeTroy usesFamily
-
softwareupdate.app usesFamily
-
HOPLIGHT uses
-
DarkKomet usesFamily
-
com.apple.cli usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SneakMain usesFamily
-
LessonOne usesFamily
-
ZoomClutch usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DownTroy usesFamily
-
RooTroy usesFamily
-
SilentSiphon usesFamily
-
TeamsClutch usesFamily
Sectors (7)
-
Legal targets
-
Finance targets
-
Financial organizations targets
-
Fintech targets
-
Technology targets
-
Banking institutions targets
-
Government targets
Countries (20)
-
Italy targets
-
Australia targets
-
Russian Federation targets
-
United States of America targets
-
Poland targets
-
Hong Kong targets
-
Thailand targets
-
Ukraine targets
-
Viet Nam targets
-
Czechia targets
-
France targets
-
India targets
Indicators (100)
-
4f49514ab1794177a61c50c63b93b903c46f9b914c32ebe9c96aa3cbc1f99b16related -
426650ccd372823b531bc417e33f39582714b368953e464647b3be281f010de7related -
productnews.onlinerelated -
stix 100/100 Revoked· Valid until 14/12/2025 · Source: AlienVault
-
887fbf39125451a667977c82b989a2cdba78a888d228f941b8bae6d7dbb26433related -
abiesvc.inforelated -
583bc1607ca8aafa0b6ee9a4c6870085ef3f5f1823456f930ef32b0bf2229867related -
stix 100/100 Revoked· Valid until 14/12/2025 · Source: AlienVault
-
documents.antcapital.usrelated
Vulnerabilities (CVE) (53)
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user …
- Attack vector
- NETWORK
- Published
- 05/04/2024
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- Attack vector
- Network
- Published
- 15/02/2024
- Modified
- 21/12/2025
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to …
- Attack vector
- Network
- Published
- 05/10/2023
- Modified
- 21/12/2025
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow …
- Attack vector
- Network
- Published
- 10/10/2023
- Modified
- 21/12/2025
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
- Attack vector
- Network
- Published
- 20/11/2024
- Modified
- 21/12/2025
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to …
- Attack vector
- NETWORK
- Published
- 17/01/2024
- Modified
- 21/12/2025
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.
- Attack vector
- Network
- Published
- 30/11/2023
- Modified
- 21/12/2025
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the …
- Attack vector
- Network
- Published
- 25/06/2025
- Modified
- 21/12/2025
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow …
- Attack vector
- ADJACENT_NETWORK
- Published
- 12/09/2024
- Modified
- 21/12/2025
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/04/2017
- Modified
- 22/04/2026
Tool (2)
-
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft…
-
Mimikatz usesThe MITRE Corporation Confidence 100
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of…