Skip to main content
Mallory
MalwareUsed by 3 actors

Hawup

Hawup is a malware framework referenced as a common ancestral codebase within the DPRK-linked Labyrinth Chollima ecosystem. Reporting cited in the content states that Golden Chollima, Pressure Chollima, and the core espionage-focused Labyrinth Chollima group followed independent malware development trajectories while originating from the Hawup framework, alongside shared roots in the KorDLL framework. This positions Hawup as part of the shared tactical DNA underpinning later DPRK malware families and operations rather than as a standalone campaign-specific implant described in detail here. The associated threat actors are North Korea-linked clusters tracked by CrowdStrike: Golden Chollima and Pressure Chollima, which are focused on cryptocurrency theft, and core Labyrinth Chollima, which is focused on espionage. The broader ecosystem derived from Hawup has been used against cryptocurrency and fintech organizations, as well as defense, aerospace, manufacturing, logistics, shipping, maritime, military, nuclear, and critical infrastructure targets. Initial access and delivery tradecraft observed across these related clusters includes employment-themed social engineering, trojanized legitimate software, malicious ZIP archives delivered via WhatsApp, and malicious Node.js and Python projects or packages. The content does not provide specific Hawup-only indicators of compromise, payload behavior, persistence mechanisms, or platform details beyond its role as a shared framework lineage.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TraderTraitor

...each following independent malware development trajectories while originating from the Hawup framework.

via polyswarmblog.polyswarm.io
Pressure Chollima

...each following independent malware development trajectories while originating from the Hawup framework.

via polyswarmblog.polyswarm.io
Golden Chollima

...each following independent malware development trajectories while originating from the Hawup framework.

via polyswarmblog.polyswarm.io
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

Hawup | Mallory