216.73.217.22

LABYRINTH CHOLLIMA Evolves into Three Adversaries

· Published 30/01/2026 08:48 · Modified 30/01/2026 08:57

Export JSON

Essential information

Published
30/01/2026 08:48
Modified
30/01/2026 08:57
Tags
2026-01-30 alertconf anycon applejeus backdoor.apt.fakewinhttphelper brambul bubblewrap citriloader cloud cryptocurrency devobrat dozer dprk espionage fintech fudmodule ghostship hawup hawup rat hiberrat hoplight httphoplight joanap kordll kordll bot koredos magikcookie manuscrypt matanet neddnloader nodalbaker north korea openssl downloader pipedown scuzzyfuss snakebaker sparkdownloader stackeyflate statussymbol swdownloader twopence electric undergroundrat winwebdown zero-day
Related entities
33 observables, 1 intrusion sets (apt), 18 techniques (mitre), 34 malware, 8 others

Description

The LABYRINTH CHOLLIMA threat group has split into three distinct adversaries: GOLDEN CHOLLIMA, PRESSURE CHOLLIMA, and core LABYRINTH CHOLLIMA. Each subgroup has specialized malware, objectives, and tradecraft. GOLDEN CHOLLIMA and PRESSURE CHOLLIMA focus on entities, while core LABYRINTH CHOLLIMA continues operations targeting industrial, logistics, and defense companies. Despite operating independently, these groups share tools and infrastructure, indicating coordinated resource allocation within 's cyber ecosystem. The evolution stems from the malware framework, which spawned several malware families. Recent operations demonstrate -focused tradecraft and the use of vulnerabilities to deliver malware.

External references