KorDLL is a malware framework identified as a common ancestral codebase used by DPRK-linked activity that later evolved through the Hawup framework into multiple specialized malware lineages. Reporting cited in the content describes KorDLL as part of the shared tactical origin for the North Korea-linked clusters Golden Chollima, Pressure Chollima, and the espionage-focused Labyrinth Chollima. The framework is referenced as active in the 2009–2015 period and as foundational “tactical DNA” from which later tooling diverged. The content does not provide direct technical details on KorDLL’s standalone capabilities, infection vector, or specific indicators of compromise, but it does high-confidence link it to the broader DPRK malware ecosystem that later supported cryptocurrency theft and espionage operations. Those descendant operations targeted cryptocurrency and fintech organizations, as well as defense, manufacturing, aerospace, logistics, shipping, and critical infrastructure sectors, and used tradecraft including trojanized software, malicious Node.js and Python projects, employment-themed social engineering, and WhatsApp-delivered malicious ZIP archives. No KorDLL-specific hashes or other IOCs are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Labyrinth Chollima evolved from the Kordll framework (2009-2015) through Hawup into three specialized subgroups with divergent malware paths and objectives.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Shared malware framework/tooling lineage used across multiple DPRK-linked operational subgroups.
Referenced as a shared framework underpinning DPRK tradecraft and tooling origins across the described clusters.
A DPRK-linked malware framework lineage referenced as an early foundation (2009–2015) for later toolchains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.