Hawup
Hawup is a malware framework referenced as a common ancestral codebase within the DPRK-linked Labyrinth Chollima ecosystem. Reporting cited in the content states that Golden Chollima, Pressure Chollima, and the core espionage-focused Labyrinth Chollima group followed independent malware development trajectories while originating from the Hawup framework, alongside shared roots in the KorDLL framework. This positions Hawup as part of the shared tactical DNA underpinning later DPRK malware families and operations rather than as a standalone campaign-specific implant described in detail here. The associated threat actors are North Korea-linked clusters tracked by CrowdStrike: Golden Chollima and Pressure Chollima, which are focused on cryptocurrency theft, and core Labyrinth Chollima, which is focused on espionage. The broader ecosystem derived from Hawup has been used against cryptocurrency and fintech organizations, as well as defense, aerospace, manufacturing, logistics, shipping, maritime, military, nuclear, and critical infrastructure targets. Initial access and delivery tradecraft observed across these related clusters includes employment-themed social engineering, trojanized legitimate software, malicious ZIP archives delivered via WhatsApp, and malicious Node.js and Python projects or packages. The content does not provide specific Hawup-only indicators of compromise, payload behavior, persistence mechanisms, or platform details beyond its role as a shared framework lineage.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...each following independent malware development trajectories while originating from the Hawup framework.
...each following independent malware development trajectories while originating from the Hawup framework.
...each following independent malware development trajectories while originating from the Hawup framework.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Shared malware framework/tooling lineage used across multiple DPRK-linked operational subgroups.
Referenced as a shared framework underpinning DPRK tradecraft and tooling origins across the described clusters.
A shared malware framework lineage from which multiple DPRK subgroups’ toolchains diverged.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.