← Threat Actors / Global / STARDUST CHOLLIMA
DOSSIER // STARDUST-CHOLLIMA

STARDUST CHOLLIMA

▲ High Threat
Primary Aliases: APT38 APT45 Citrine Sleet DEV-0139
Confidence Rating 70% (Grounded)

Open-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public reported as part of the “Lazarus Group”), because Hermes was executed on a host during the SWIFT compromise of FEIB in October 2017.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (56 TTPs)

📥 Download Navigator JSON
Persistence & Privilege Escalation 2
Lateral Movement & Collection 1
Copied to clipboard

LINK COPIED TO CLIPBOARD