Securitybrief.Au CrowdStrike Identifies Three Splinter Groups from LABYRINTH CHOLLIMA
Article Content
Browse articles
CrowdStrike has reclassified the North Korea-linked intrusion set LABYRINTH CHOLLIMA into three distinct units: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA, which focus on cryptocurrency theft, and the core LABYRINTH CHOLLIMA unit, which is dedicated to espionage against industrial and defense-related organizations. This assessment reflects a strategic shift in the group's operations, allowing for specialized malware and objectives.
Ask AI about this cluster
Answers cite the sources they use
Updated 192d ago How this analysis works
More articles in this cluster (6)
Following this threat?
Track WannaCry, Diamond Sleet and AppleJeus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…