Stardust Chollima

North Korea


STARDUST CHOLLIMA is an adversary associated with the Democratic People’s Republic of Korea (DPRK) that has been active operationally since at least 2015 and is affiliated with large-scale currency generation operations. CrowdStrike Intelligence assesses that STARDUST CHOLLIMA may represent an element of Bureau 121 of the DPRK’s Reconnaissance General Bureau (RGB) based on public disclosures by th...

Community Identifiers



  • xbzUrlVEGvygX0M
  • Cw6aepmiD9HBGcNlVPM8kAx


  • yl8Jh1LjU6mbEPX
  • fKVQYqPw

Contact our team about
IOCs for this adversary


During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.