🇰🇵Famous Chollima
🇰🇵 Famous Chollima is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 9 detection use cases to this actor across 14 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-08-11 to 2026-08-13.
crit 2
9Use cases
2Articles
14Techniques
9IOCs
Known aliases
Famous Chollima
Top techniques
All other tracked techniques
T1047 · Windows Management InstrumentationT1059.001 · PowerShellT1071 · Application Layer ProtocolT1078.003 · Local AccountsT1090.003 · Multi-hop ProxyT1133 · External Remote ServicesT1204.001 · Malicious LinkT1219 · Remote Access ToolsT1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1566.002 · Spearphishing Link
Detection use cases (9)
Corporate sign-in from DPRK IT-worker VPS / AstrillVPN infrastructure (Famous Chollima) Managed endpoint network egress to DPRK IT-worker VPS / AstrillVPN IPs Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Network connections to article IPs / domains Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha)Threat-intel articles (2)
Tracked indicators
IP addresses (9)
104.250.148.58 107.150.38.250 185.152.67.39 192.200.115.226 199.168.112.175 206.217.134.34 45.77.71.42 62.33.223.165 89.187.185.11