🇰🇵Famous Chollima
🇰🇵 Famous Chollima is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 14 detection use cases to this actor across 34 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-06-11 to 2026-06-11.
crit 1
14Use cases
1Articles
34Techniques
0IOCs
Known aliases
Famous Chollima
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1059.001 · PowerShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1071.004 · DNST1098.001 · Additional Cloud CredentialsT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1176 · Software ExtensionsT1190 · Exploit Public-Facing ApplicationT1195.001 · Compromise Software Dependencies and Development ToolsT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.004 · Spearphishing VoiceT1569.002 · Service ExecutionT1574.002 · T1574.002T1588.001 · Malware