Labyrinth Chollima Expands Activity, Spawns Offshoots

2026-02-06 Poly Swarm

https://blog.polyswarm.io/labyrinth-chollima-expands-activity-spawns-offshoots

Thumbnail for Labyrinth Chollima Expands Activity, Spawns Offshoots

CrowdStrike’s tracking separates Labyrinth Chollima activity into core Labyrinth Chollima for espionage and the Golden Chollima and Pressure Chollima clusters for cryptocurrency theft, with shared origins in Kordll, Hawup, and related tooling. Golden Chollima is described as pursuing steady smaller-scale cryptocurrency theft through Jeus and Applejeus variants, malicious Python packages, recruitment fraud, cloud IAM manipulation, Chromium zero-days, Snakebaker, and Nodalbaker. Pressure Chollima is linked to larger cryptocurrency heists and sophisticated implants including Swdownloader, Sparkdownloader, Scuzzyfuss, and Twopence Electric delivered through malicious Node.js and Python projects. Core Labyrinth Chollima is framed as an espionage actor targeting manufacturing, defense, aerospace, logistics, shipping, and critical infrastructure, using Hoplight-lineage tooling, Fudmodule, vulnerable driver exploitation, Chrome and Windows zero-days, and messaging-platform social engineering.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f749c7e84809ffc3939eaed06ad90e1… 2026-01-29 2026-04-03
HASH 512877c98fd83cd51bb287da4462b44… 2026-01-29 2026-04-03
HASH 73edc54abb3d6b8df6bd1e4a77c3733… 2026-01-29 2026-04-03
HASH d0cf9c1f87eac9b8879684a041dd6a2… 2026-01-29 2026-04-03
HASH 453d8bd3e2069bc50703eb4c5d278aa… 2026-01-29 2026-04-03
HASH a795964bc2be442f142f5aea9886ddf… 2026-01-29 2026-04-03
HASH d2359630e84f59984ac7ddebdece931… 2026-01-29 2026-04-03
HASH 56e51244e258c39293463c8cf02f5dd… 2026-01-29 2026-04-03
HASH d2e743216d17e97c8d1913d376d4609… 2026-01-29 2026-04-03
HASH f9586fdf4e0a65b17ee32bc3c3f493a… 2026-01-29 2026-04-03
HASH 7dee2bd4e317d12c9a2923d05315268… 2026-01-29 2026-04-03
HASH ff32bc1c756d560d8a9815db458f438… 2025-09-01 2026-04-03
HASH 9ba02f8a985ec1a99ab7b78fa678f26… 2022-04-18 2026-04-03
HASH dced1acbbe11db2b9e7ae44a617f3c1… 2022-04-18 2026-04-03
HASH a61ecbe8a5372c85dcf5d077487f09d… 2020-07-27 2026-04-03
HASH 05feed9762bc46b47a7dc5c469add9f… 2020-02-25 2026-04-03
HASH 4fe3c853ab237005f7d62324535dd64… 2017-02-12 2026-04-03

Related Actors

Related Reports

« Back