Cómo domar un Chollima
2025-03-24 • Birmingham Cyber • How to tame a Chollima •
https://news.mefiltraron.com/p/edicion-especial-como-domar-un-chollima
BCA LTD describes a North Korean corporate-espionage campaign and a newly named malware family, Chaotic Capybara. The Spanish-language report places the activity within the broader Lazarus Group ecosystem and discusses Chollima-labeled DPRK clusters such as Labyrinth Chollima, Stardust Chollima, Silent Chollima, Famous Chollima, and Velvet Chollima, including links to cryptocurrency theft, fake job interviews, cryptojacking, remote IT worker schemes, and espionage. The source says the researchers analyzed attacker infrastructure while investigating professional North Korean hackers. Defenders should prioritize the report for infrastructure pivots, macOS or campaign-specific indicators, and social-engineering patterns associated with Contagious Interview and related DPRK activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hostwindsdns.com | 2024-11-07 | 2026-06-20 |
| IPv4 | 5.230.44.79 | 2025-03-24 | 2025-06-20 |
| IPv4 | 38.110.228.112 | 2025-03-24 | 2025-06-20 |
| IPv4 | 5.230.252.157 | 2025-03-24 | 2025-06-20 |
| HASH | 021efdb311c9ce6101d7f389c08b511… | 2025-03-24 | 2025-03-24 |
| HASH | 09f7acb4dc385a965c7a70ca64faf00… | 2025-03-24 | 2025-03-24 |