CrowdStrike Identifies Three Splinter Groups from LABYRINTH CHOLLIMA

CrowdStrike Identifies Three Splinter Groups from LABYRINTH CHOLLIMA

First seen 30 Jan 2026, 05:02 UTC CyberscoopSecuritybrief.AsiaSecuritybrief.AuNknewsInfosecurity-Magazine+1 88% similarity 25.0

Article Content

Browse articles
ThreatCluster

CrowdStrike has reclassified the North Korea-linked intrusion set LABYRINTH CHOLLIMA into three distinct units: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA, which focus on cryptocurrency theft, and the core LABYRINTH CHOLLIMA unit, which is dedicated to espionage against industrial and defense-related organizations. This assessment reflects a strategic shift in the group's operations, allowing for specialized malware and objectives.

ThreatCluster AI

Community

Browse all →