STARDUST CHOLLIMA
Intelligence Profile
Open-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public reported as part of the “Lazarus Group”), because Hermes was executed on a host during the SWIFT compromise of FEIB in October 2017.
Intelligence Assessment
STARDUST CHOLLIMA, also known as Sapphire Sleet, is a highly sophisticated, financially motivated threat group. This group has been associated with the Hermes ransomware and has been linked to the Lazarus Group.
STARDUST CHOLLIMA's tradecraft includes obfuscated files or information (T1027.002), data destruction (T1565.003), and command and scripting interpreters (T1059.005). They also leverage bypass user account control (T1548.002) and system network configuration discovery (T1016).
STARDUST CHOLLIMA is currently active, with its last activity recorded on 2026-03-18. The group exhibits high sophistication, indicating a continued and significant threat.
Threat Analysis
STARDUST CHOLLIMA is a high-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of financial.
Financially motivated threat actors like STARDUST CHOLLIMA prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.
With high sophistication, STARDUST CHOLLIMA is capable of targeted intrusions using adapted commodity tools alongside custom implants, maintaining operational security and evading standard detection mechanisms.