CrowdStrike reported that the long-running DPRK-linked activity it tracks as Labyrinth Chollima has diverged into three distinct operations, with two offshoots—Golden Chollima and Pressure Chollima—focused on cryptocurrency theft while the remaining Labyrinth Chollima activity concentrates on espionage. The split reflects increasing specialization: Labyrinth Chollima is described as targeting sectors including manufacturing, logistics, defense, and aerospace, while the crypto-focused units are assessed as generating revenue that supports the North Korean regime and, in part, its cyber operations.
CrowdStrike tied Golden Chollima to sustained, lower-value theft operations against cryptocurrency/fintech targets and described a tooling lineage that includes Jeus (and macOS AppleJeus) and overlaps with components such as PipeDown, DevobRAT, HTTPHelper, and Anycon, alongside more recent cloud-focused tradecraft (e.g., recruitment-fraud delivery of malicious Python packages leading to cloud IAM/resource access and crypto diversion). Pressure Chollima was characterized as pursuing high-payout opportunities globally and was linked in public reporting to record-setting cryptocurrency thefts (including a cited $1.46B heist), with CrowdStrike assessing it as among the DPRK’s more technically advanced crypto-theft operators; despite specialization, the groups reportedly retain shared lineage (including ties to the broader Lazarus Group construct) and exhibit some shared tools/infrastructure suggesting centralized coordination.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On January 29, 2026, CrowdStrike published research assessing that Labyrinth Chollima now operates as three distinct DPRK-linked adversaries with specialized malware and objectives. The report also provided indicators of compromise and malware samples to help defenders identify related activity.
CrowdStrike links Pressure Chollima to a record-breaking $1.46 billion cryptocurrency theft that occurred the year before the report. The incident is cited as evidence of the group's advanced capability and focus on high-value crypto heists.
After the split, Golden Chollima and Pressure Chollima focused primarily on cryptocurrency and fintech theft to generate revenue for North Korea. CrowdStrike says this specialization became a core part of the regime's cyber-enabled fundraising.
Since around 2020, CrowdStrike assesses the original Labyrinth Chollima cluster splintered into three distinct but coordinated groups: Labyrinth Chollima, Golden Chollima, and Pressure Chollima. The groups retained some shared tools and infrastructure while specializing in different missions.
CrowdStrike says the North Korea-linked activity cluster it tracks as Labyrinth Chollima has been active since 2009. This marks the start of the long-running DPRK cyber operation later assessed to have split into multiple units.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.