Velvet Chollima

Threat Actor updated 23 days ago (2024-11-29T14:34:12.417Z)
Download STIX
Preview STIX
Velvet Chollima, also known as Kimsuky, APT43, Thallium, Black Banshee, and Emerald Sleet among other names, is a threat actor believed to be based in North Korea. The group has been active since 2012 and is linked to North Korea’s General Reconnaissance Bureau, the country's main military intelligence organization. Known for its focus on social engineering, Velvet Chollima uses various tactics including malicious Chrome browser extensions and app store services to target individuals conducting research on the inter-Korean conflict. The group is tracked by both the U.S. and South Korean governments along with private-sector cybersecurity companies due to their large-scale social engineering campaigns. In 2023, Velvet Chollima notably increased its activities, shifting towards a greater focus on cryptocurrency in addition to its traditional focus on cyber espionage. This shift was marked by the use of evasion and disruption techniques to bypass security tools. The group has also been observed exploiting critical vulnerabilities in widely used remote access tools like ConnectWise ScreenConnect to deploy malware strains similar to the Babyshark malware family, which is associated with the group. Recently, hackers from this group have been exploiting disclosed ScreenConnect vulnerabilities to deploy a new variant of malware, dubbed ToddlerShark by researchers. This new malware overlaps with ReconShark and BabyShark, reconnaissance tools previously used by Velvet Chollima. As a state-sponsored hacking group, Velvet Chollima continues to pose a significant threat to organizations and governments worldwide, particularly those involved in research or activities related to the inter-Korean conflict.
Description last updated: 2024-03-21T22:14:15.605Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Kimsuky is a possible alias for Velvet Chollima. Kimsuky is a threat actor group linked to North Korea, known for its malicious cyber activities with a particular focus on espionage. The group has been observed employing a variety of sophisticated tactics and techniques, including the use of malware such as TOGREASE, GREASE, and RandomQuery, which
6
Thallium is a possible alias for Velvet Chollima. Thallium, also known as Kimsuky, APT43, Velvet Chollima, and Black Banshee, is a significant threat actor that has been active since at least 2012. This group, believed to be operating on behalf of the North Korean regime, conducts intelligence collection and uses cybercrime to fund espionage activi
4
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Chrome
Espionage
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Velvet Chollima Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
9 months ago
CERT-EU
9 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
BankInfoSecurity
10 months ago
CERT-EU
a year ago
CERT-EU
2 years ago
Securityaffairs
2 years ago
CERT-EU
2 years ago
Flashpoint
2 years ago
CERT-EU
2 years ago
MITRE
2 years ago
MITRE
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
DARKReading
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago