Ricochet Chollima

North Korea

Details

RICOCHET CHOLLIMA is a Democratic Peoples’ Republic of Korea (DPRK)-nexus targeted intrusion adversary that has been involved in espionage operations since at least 2016. RICOCHET CHOLLIMA’s observed operations have almost exclusively targeted the Republic of Korea (ROK) and are assessed to be focused on ROK government officials, non-governmental organizations (NGOs), academics, journalists, and D...

Community Identifiers

DKrmPusM9WOgdZQ

Objective

  • OIHRcuGqpyMPNv2Ugn1oBw5

Motivation

  • k09wGxFXn3dl5hH

Contact our team about
IOCs for this adversary

?

During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.