Velvet Chollima is a North Korea–linked advanced persistent threat (APT) group identified in recent reporting as a state-sponsored actor conducting persistent intrusions and potentially ransomware-focused campaigns.
Overview
Velvet Chollima is a North Korea–linked advanced persistent threat (APT) group identified in recent reporting as a state-sponsored actor conducting persistent intrusions and potentially ransomware-focused campaigns. The group highlights DPRK's evolving cyber operations with a widening geographic footprint, including Europe, signaling significant cybersecurity risk from a nation-state actor.
Related Threat Clusters
-
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Kimsuky Group Leverages AI for Malware Targeting South Korean Government
The North Korean hacking group Kimsuky is utilizing generative AI to create malware aimed at South Korean government systems, as reported by Kaspersky on May 14, 2026. The malware, named HelloDoor, is a Rust-based…
5 articles · Updated May 14, 2026 -
Kimsuky Targets South Korea with Advanced Malware and Social Engineering Tactics
North Korean hackers known as Kimsuky have launched a series of cyberattacks against South Korean military and corporate sectors during March and April 2026. The group utilized sophisticated social engineering tactics,…
2 articles · Updated May 29, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
743 articles · Updated April 29, 2026 -
US, UK, and Australia Sanction Russian Cyber Firm Media Land for Ransomware Links
On November 19, 2025, the United States, United Kingdom, and Australia announced coordinated sanctions against the Russian web company Media Land, accusing it of facilitating ransomware operations. The sanctions include…
88 articles · Updated November 19, 2025 -
North Korea's Konni APT Targets Android and Windows Users in September 2025
In September 2025, the North Korea-linked APT group Konni, also known as Kimsuky, targeted users by posing as counselors to steal data and wipe Android phones using Google Find Hub. The attacks also affected Windows…
3 articles · Updated December 3, 2025
Recent Intelligence Reports
- North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files — Techtimes · August 10, 2026
- North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms — Techtimes · July 24, 2026
- North Korean hackers Kimsuky target South Korea with new malware variants — Scworld · May 29, 2026
- Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels — Thehackernews · May 29, 2026
- Shai-Hulud goes open-source — News.Risky.Biz · May 15, 2026
- Kimsuky targets organizations with PebbleDash — Securelist · May 14, 2026
- North Korea — Securityaffairs.Co · November 11, 2025
- Crowdstrike: AI Accelerating Ransomware Attacks Across Europe — Techrepublic · November 7, 2025