Silent Chollima Extortion Activity Targets US Entities
2024-10-11 • Poly Swarm •
https://blog.polyswarm.io/silent-chollima-extortion-activity-targets-us-entities
Silent Chollima, a North Korea-nexus actor also tracked as Stonefly, Andariel, Onyx Sleet, TDrop2, and DarkSeoul, was observed moving from its traditional espionage focus into apparent extortion and other financially motivated activity. Symantec-linked reporting cited August 2024 attacks against at least three US-based organizations with no obvious intelligence value, suggesting possible preparation for follow-on ransomware operations. The activity used the Preft backdoor, also known as Dtrack and Valefor, which the excerpt says is exclusive to Silent Chollima and supported attribution. Additional tooling included Nukebot, Mimikatz, keyloggers, Sliver, PuTTY, Plink, Megatools, Chisel, FastReverseProxy, a fake Tableau certificate, and certificates previously linked to the group, showing a broad toolset for intrusion, credential access, tunneling, and post-exploitation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 96118268f9ab475860c3ae3edf00d9e… | 2024-10-02 | 2024-12-13 |
| HASH | e5d56cb7085ed8caf6c8269f4110265… | 2024-10-02 | 2024-12-13 |
| HASH | 75448c81d54acb16dd8f5c14e3d4713… | 2024-10-02 | 2024-12-13 |
| HASH | fce7db964bef4b37f2f430c6ea99f43… | 2024-10-02 | 2024-12-13 |
| HASH | 5633691b680b46b8bd791a656b0bb9f… | 2024-10-02 | 2024-12-13 |
| HASH | 12bf9fe2a68acb56eb01ca97388a126… | 2024-10-02 | 2024-12-13 |
| HASH | f64dab23c50e3d131abcc1bdbb35ce9… | 2024-10-02 | 2024-12-13 |
| HASH | d71f478b1d5b8e489f5daafda99ad20… | 2024-10-02 | 2024-12-13 |
| HASH | ee7926b30c734b49f373b88b3f0d73a… | 2024-10-02 | 2024-12-13 |