APT / THREAT GROUP💰 FINANCIALHIGH

STARDUST CHOLLIMA

2
aliases
Last seen:Mar 17, 2026

Intelligence Profile

Open-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public reported as part of the “Lazarus Group”), because Hermes was executed on a host during the SWIFT compromise of FEIB in October 2017.

Intelligence Assessment

STARDUST CHOLLIMA, also known as Sapphire Sleet, is a highly sophisticated, financially motivated threat group. This group has been associated with the Hermes ransomware and has been linked to the Lazarus Group.

STARDUST CHOLLIMA's tradecraft includes obfuscated files or information (T1027.002), data destruction (T1565.003), and command and scripting interpreters (T1059.005). They also leverage bypass user account control (T1548.002) and system network configuration discovery (T1016).

Outlook

STARDUST CHOLLIMA is currently active, with its last activity recorded on 2026-03-18. The group exhibits high sophistication, indicating a continued and significant threat.

Generated by the CTIWATCH analysis pipeline from this actor's tracked data (victims, campaigns, TTPs, activity). Attribution and assessments may be incomplete — verify against primary reporting before acting.

Threat Analysis

STARDUST CHOLLIMA is a high-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of financial.

Financially motivated threat actors like STARDUST CHOLLIMA prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.

With high sophistication, STARDUST CHOLLIMA is capable of targeted intrusions using adapted commodity tools alongside custom implants, maintaining operational security and evading standard detection mechanisms.

TTPs — Tactics, Techniques & Procedures (61)

T1027.002T1565.003T1059.005T1685T1686.002T1562.004T1218.011T1218.007T1135T1548.002T1110T1569.002T1690T1583.001T1686T1486T1204.001T1217T1053.003T1204.002T1082T1071.001T1115T1055T1005T1553.005T1543.003T1036.003T1059.003T1059.001T1518.001T1529T1083T1562.013T1588.002T1565.002T1112T1685.005T1033T1053.005T1036.006T1218.005T1565.001T1505.003T1480.002T1070.006T1566.001T1049T1070.004T1057T1105T1070.001T1189T1562.003T1140T1218.001T1106T1056.001T1485T1561.002T1562.001

Intelligence Reports Mentioning STARDUST CHOLLIMA

External References

Quick Facts

TypeAPT / Threat Group
Motivation💰 financial
Sophisticationhigh
Aliases2
SourceMalpedia

Also Known As

Sapphire SleetSTARDUST CHOLLIMA

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.