Ricochet Chollima

Threat Actor updated 4 months ago (2024-05-04T16:48:46.623Z)
Download STIX
Preview STIX
Ricochet Chollima, also known as Ruby Sleet or ScarCruft among other aliases, is a threat actor associated with the Democratic Peoples’ Republic of Korea (DPRK). Active in espionage operations since at least 2016, Ricochet Chollima has primarily targeted South Korean individuals and entities, focusing particularly on government officials, non-governmental organizations (NGOs), academics, journalists, and defectors from DPRK. The group utilizes spear-phishing attacks to deliver an array of custom tools, demonstrating their advanced capabilities in cyber warfare. In March 2023, Ricochet Chollima escalated its activities by compromising an aerospace research institute in Russia, marking a shift in its usual focus on South Korean targets. This incident was part of a broader pattern of North Korean threat actors targeting Russian governmental and defense industry entities. In addition to Ricochet Chollima, the Lazarus Group, another North Korean hacking team, also breached NPO Mashinostroyeniya, a Russian missile engineering firm, to facilitate intelligence gathering. These actions indicate a strategic expansion of North Korean cyber-espionage operations. Microsoft and SentinelOne have provided substantial evidence linking these cyberattacks to North Korean threat actors. The simultaneous support provided by North Korea to Russia in its war in Ukraine further complicates the geopolitical implications of these cyber-espionage activities. As such, it is crucial for nations and cybersecurity firms to remain vigilant and proactive in their defensive measures against these evolving and sophisticated threats.
Description last updated: 2023-12-20T16:43:37.705Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Ricochet Chollima Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
9 months ago
Ricochet Chollima - crowdstrike.com
CERT-EU
a year ago
Cyber Security Week in Review: September 8, 2023
CERT-EU
a year ago
North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity Researchers
CERT-EU
a year ago
North Korea's ScarCruft Deploys RokRAT Malware via LNK File Infection Chains
CERT-EU
a year ago
Elite North Korean Hackers Breach Russian Missile Developer