Silent Chollima Extortion Activity Targets US Entities

2024-10-11 Poly Swarm

https://blog.polyswarm.io/silent-chollima-extortion-activity-targets-us-entities

Thumbnail for Silent Chollima Extortion Activity Targets US Entities

Silent Chollima, a North Korea-nexus actor also tracked as Stonefly, Andariel, Onyx Sleet, TDrop2, and DarkSeoul, was observed moving from its traditional espionage focus into apparent extortion and other financially motivated activity. Symantec-linked reporting cited August 2024 attacks against at least three US-based organizations with no obvious intelligence value, suggesting possible preparation for follow-on ransomware operations. The activity used the Preft backdoor, also known as Dtrack and Valefor, which the excerpt says is exclusive to Silent Chollima and supported attribution. Additional tooling included Nukebot, Mimikatz, keyloggers, Sliver, PuTTY, Plink, Megatools, Chisel, FastReverseProxy, a fake Tableau certificate, and certificates previously linked to the group, showing a broad toolset for intrusion, credential access, tunneling, and post-exploitation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 96118268f9ab475860c3ae3edf00d9e… 2024-10-02 2024-12-13
HASH e5d56cb7085ed8caf6c8269f4110265… 2024-10-02 2024-12-13
HASH 75448c81d54acb16dd8f5c14e3d4713… 2024-10-02 2024-12-13
HASH fce7db964bef4b37f2f430c6ea99f43… 2024-10-02 2024-12-13
HASH 5633691b680b46b8bd791a656b0bb9f… 2024-10-02 2024-12-13
HASH 12bf9fe2a68acb56eb01ca97388a126… 2024-10-02 2024-12-13
HASH f64dab23c50e3d131abcc1bdbb35ce9… 2024-10-02 2024-12-13
HASH d71f478b1d5b8e489f5daafda99ad20… 2024-10-02 2024-12-13
HASH ee7926b30c734b49f373b88b3f0d73a… 2024-10-02 2024-12-13

Related Actors

Related Reports

« Back