Velvet Chollima — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
November 7, 2025
Last Seen
August 10, 2026

Velvet Chollima is a North Korea–linked advanced persistent threat (APT) group identified in recent reporting as a state-sponsored actor conducting persistent intrusions and potentially ransomware-focused campaigns.

Overview

Velvet Chollima is a North Korea–linked advanced persistent threat (APT) group identified in recent reporting as a state-sponsored actor conducting persistent intrusions and potentially ransomware-focused campaigns. The group highlights DPRK's evolving cyber operations with a widening geographic footprint, including Europe, signaling significant cybersecurity risk from a nation-state actor.

Related Threat Clusters

Recent Intelligence Reports

  • North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files — Techtimes · August 10, 2026
  • North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms — Techtimes · July 24, 2026
  • North Korean hackers Kimsuky target South Korea with new malware variants — Scworld · May 29, 2026
  • Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels — Thehackernews · May 29, 2026
  • Shai-Hulud goes open-source — News.Risky.Biz · May 15, 2026
  • Kimsuky targets organizations with PebbleDash — Securelist · May 14, 2026
  • North Korea — Securityaffairs.Co · November 11, 2025
  • Crowdstrike: AI Accelerating Ransomware Attacks Across Europe — Techrepublic · November 7, 2025

CVSS v3.1 Breakdown