Reporting highlighted multiple, unrelated threat developments rather than a single cohesive incident. One thread focused on North Korea-linked Chollima activity: a targeted spear-phishing operation attributed to Ricochet Chollima used Dropbox-hosted lures to deliver archives containing weaponized Windows shortcut (.LNK) files, with tradecraft designed to evade detection (including multi-stage execution and fileless, memory-resident behavior). Separately, a CrowdStrike-based report described a strategic reorganization of LABYRINTH CHOLLIMA into three operational groupings—GOLDEN CHOLLIMA (smaller, steady revenue theft), PRESSURE CHOLLIMA (high-payout crypto heists), and a core espionage unit—while retaining shared malware “DNA” via frameworks such as KorDLL and Hawup, indicating continued coordination across DPRK cyber operations.
Other items covered distinct, non-DPRK activity and should not be conflated with the Chollima reporting. One article described infostealer campaigns expanding to macOS, including Python-based cross-platform stealers and macOS families such as Atomic macOS Stealer (AMOS), using malvertising, fake installers/DMGs, and trusted platforms to harvest credentials, cookies, keychain data, crypto wallets, and developer secrets. Another described a fake Dropbox phishing campaign using PDF-based staging (including obfuscation techniques like FlateDecode and AcroForm objects) hosted on legitimate infrastructure (e.g., Vercel Blob storage) to redirect victims to a counterfeit login page and exfiltrate credentials via Telegram—a separate credential-harvesting operation not tied to the Chollima APT reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Genians Security Center and an analyst identified as S3N4T0R documented the stages, evasion methods, persistence, and Dropbox API-based command-and-control used in Operation: ToyBox Story. The public reporting revealed technical details of the campaign's infection chain and tradecraft.
CrowdStrike reported that the North Korean threat actor formerly known as LABYRINTH CHOLLIMA had restructured into GOLDEN CHOLLIMA, PRESSURE CHOLLIMA, and a core espionage unit retaining the LABYRINTH CHOLLIMA name. The report said the split enabled parallel espionage and cryptocurrency theft operations while the groups continued sharing tools and infrastructure.
Starting in March 2025, Ricochet Chollima targeted activists and organizations focused on North Korea with spear-phishing emails impersonating trusted North Korea security experts. The campaign delivered Dropbox links to ZIP archives containing malicious LNK files that launched a multi-stage, largely fileless malware chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.