惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

www.infosecurity-magazine.com

Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem China-Linked Webworm APT Evolves Tactics, Expands to European Targets GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension Researchers Warn CypherLoc Scareware Has Targeted Millions of Users Verizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access Vector Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Software Agentic AI Accelerates Software Builds and Mobile App Attacks Grafana Labs Confirms Hackers Stole Source Code Hackers Bypass Security Tools to Target Users Directly Interpol Launches Sweeping Cybercrime Crackdown in MENA Region The Infosecurity Europe Cyber Startup Competition: Meet the Finalists NCSC Publishes Guidance on Securing Agentic AI Use Security Researchers Find 47 Zero-Days at Pwn2Own Berlin Bank of England, FCA and Treasury Raise Alarm Over Frontier AI Gremlin Stealer Evolves into Modular Threat with Advanced Evasion Capabilities Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign Google Launches Android Spyware Forensics Tool for High-Risk Users New Fragnesia Flaw Hands Linux Local Users Root Access Most Organizations Now Use AI Agents for Sensitive Security Tasks ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks Canvas Owner Reaches Agreement With Cybercriminals After Ransomware Attack Avada Builder Flaws Expose One Million WordPress Sites Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain Risks UK Cybersecurity Market Expands to £14.7bn with Strong Growth in AI Security Firms Microsoft Fixes 17 Critical Flaws in May Patch Tuesday OpenAI Launches 'Daybreak' to Help Build Secure By Design Software Mini Shai-Hulud Hits TanStack npm Packages End‑to‑End Encrypted RCS Messaging Arrives Across iPhone and Android Attackers Combine ClickFix With PySoxy Proxying to Maintain Persistence Malicious Hugging Face Repository Typosquats OpenAI South Staffordshire Water Fined £1m After Data Breach TrickMo Variant Routes Android Trojan Traffic Through TON Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities Fake Claude Code Page Pushes PowerShell Stealer at Devs Hackers Observed Using AI to Develop Zero-Day for the First Time US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates ShinyHunters Escalates Canvas Extortion with School by School Ransom Campaign Zara Data Breach Impacts Nearly 200,000 Customers Police Shut Relaunched Crimenetwork Dark Web Marketplace Australian Cyber Security Centre Issues Alert Over ClickFix Attacks PCPJack Campaign Boots TeamPCP Off Compromised Machines Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds Cline Kanban Flaw Lets Websites Hijack AI Coding Agents OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos Fake Claude AI Site Drops Beagle Backdoor on Windows Users Daemon Tools Developer Confirms Software Was Trojanized Researchers Spot Uptick in Use of Vercel for Phishing Campaigns CloudZ Malware Abuses Phone Link to Steal SMS OTPs CISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-Attack Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign One in Eight Workers Has Sold Their Corporate Logins Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails North Korean APT Targets Yanbian Gamers via Trojanized Platform Fake SSA Emails Drive Venomous#Helper Phishing Campaign AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber Risk NCSC Warns of an AI-Fuelled “Vulnerability Patch Wave” Trellix Reveals Unauthorized Access to Source Code Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says OpenAI To Extend Cyber Program to Government Agencies Anthropic Rolls Out Claude Security for AI Vulnerability Scanning Two American Cybersecurity Workers Jailed for BlackCat Ransomware Attacks Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher Three Arrested for Hacking Over 610,000 Roblox Accounts Deep#Door Python Backdoor Evades Detection On Windows CISA and Partners Publish Zero Trust Guidance For OT Security UK: Education Sector Faces Surge in Cyber Breaches Despite Stable National Threat Levels Europol Busts Albanian Scam Call Centers in Major Online Fraud Case Cyber is the Number One Global “People Risk,” Says Marsh Cursor Extension Flaw Exposes Developer API Keys Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets Researchers Track 2.9 Billion Compromised Credentials Critical Flaw Turns Vect Ransomware into Data Destroying Wiper A Quarter of Healthcare Organizations Report Medical Device Cyber-Attacks Medtronic Confirms Data Breach After ShinyHunters Claims Ransomware Turf War as 0APT and KryBit Groups Trade Blows Chinese National Extradited Over Silk Typhoon Cyber Campaign No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures US Sanctions Target Cambodian Scam Network Leaders Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected Widely Used Browser Extensions Selling User Data Most Cybersecurity Professionals Feel Undervalued and Underpaid Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet BlackFile Group Targets Retail and Hospitality with Vishing Attacks UK Biobank Data Breach: Health Data of 500,000 Listed for Sale in China AI Rush is Reviving Old Cybersecurity Mistakes, Mandiant VP Warns Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation Google Favors General‑Purpose Gemini Models Over Cybersecurity‑Specific AI Apple Fixes iOS Notification Bug Exposing Deleted Messages Google Introduces Unique AI Agent Identities in New Gemini Enterprise Platform Cyber-Attacks Surge 63% Annually in Education Sector Researchers Uncover 10 In-the-Wild Prompt Injection Payloads Targeting AI Agents NCSC Backs Passkeys, Hailing a New Era of Sign-in MacOS Native Tools Enable Stealthy Enterprise Attacks NCSC Unveils SilentGlass, a Plug-In Device to Protect Monitors from Cyber-Attacks
Labyrinth Chollima Evolves into Three North Korean Hacking Groups
2026-01-30 · via www.infosecurity-magazine.com

One of the most prolific North Korean-linked cyber threat groups, Labyrinth Chollima, has recently evolved to make to three distinct hacking groups, according to CrowdStrike.

In a new blog published on January 29, the cybersecurity giant said the three groups will now be tracked as Labyrinth Chollima, Golden Chollima and Pressure Chollima.

The firm assessed “with high confidence” that while Labyrinth Chollima continues to focus on cyber espionage, targeting industrial, logistics and defense companies, the other groups have shifted towards targeting cryptocurrency entities.

Each group is using distinct toolsets in their malware campaigns, according to CrowdStrike. The toolsets are all evolutions of the same malware framework used by Labyrinth Chollima in the 2000s and 2010s.

However, the CrowdStrike threat intelligence analysts said that despite now operating independently, these three adversaries still share tools and infrastructure, indicating centralized coordination and resource allocation within the North Korean cyber ecosystem.

Labyrinth Chollima, One of Many Lazarus Aliases

Labyrinth Chollima (also known as UNC4034 and Temp.Hermit) is one of the most active cyber threat groups attributed to North Korea.

According to CrowdStrike, the group is responsible for some of North Korea’s most notable intrusions, including destructive attacks against South Korean and US entities and the global WannaCry ransomware incident

While some of the group’s past operations have been attributed to the Lazarus Group, it now seems that most cyber threat intelligence analysts have abandoned this latter name as it encompasses too many distinct teams within North Korean attributed hacking ecosystem.

For example, the entry for the Lazarus Group on Malpedia, a cyber threat intelligence repository maintained by Germany’s Fraunhofer research institute, lists 42 different aliases, highlighting how broadly the name has been applied to distinct North Korean hacking teams.

Labyrinth Chollima’s Beginnings and Stardust Chollima Emergence

CrowdStrike started tracking the Labyrinth Chollima group as a distinct cyber hacking group tied to the North Korean regime when it discovered the KorDLL malware framework used in the wild between 2009 and 2015.

KorDLL is a source code repository containing implant templates, command-and-control (C2) protocols, libraries for common tasks and code for various obfuscation techniques.

This framework “spawned several epoch-defining malware families, including Dozer, Brambul, Joanap, KorDLL Bot and Koredos,” said CrowdStrike.

It later evolved into the Hawup and TwoPence malware frameworks, which led CrowdStrike to split Labyrinth Chollima into two groups: Labyrinth Chollima, which used the Hawup framework and Stardust Chollima, which used the TwoPence framework and its evolved versions.

KorDLL malware framework evolution. Source: CrowdStrike
KorDLL malware framework evolution. Source: CrowdStrike

Labyrinth Chollima, Golden Chollima and Pressure Chollima

Today, CrowdStrike is sharing a new evolution of the Hawup framework into three distinct versions. These include the Hoplight framework used by Labyrinth Chollima, the Jeus framework used by Golden Chollima and the MataNet framework used by Pressure Chollima alongside the TwoPence framework.

Aside from using distinctive tooling, the three groups also differ in their targeting and techniques, tactics and procedures (TTPs):

  • Golden Chollima focuses on consistent, smaller-scale cryptocurrency thefts in fintech-heavy regions using cloud-focused tradecraft and recruitment fraud lures
  • Pressure Chollima pursues high-value, opportunistic crypto heists globally with advanced, low-prevalence implants
  • Labyrinth Chollima conducts espionage against defense, manufacturing and critical infrastructure sectors via zero-days, employment-themed lures, and kernel-level malware