National Cyber Warfare Foundation (NCWF)

Ricochet Chollima


0 user ratings
2024-06-18 15:21:21
blscott

 - archive -- 
Ricochet Chollima is an alternate name for the group known as APT37

Ricochet Chollima is an advanced persistent threat (APT) that has been identified by security researchers. It is believed to be linked to North Korea and was first discovered in 2016. The APT is known for its sophisticated techniques, including the use of custom malware and stealthy tactics such as using legitimate software tools like PowerShell or PsExec to avoid detection by security systems. It has been used in attacks against government agencies, financial institutions, and other organizations around the world.

Techniques, tactics and practices:

Ricochet Chollima is a highly sophisticated threat that employs various techniques to evade detection by security systems. Some of these tactics include the use of custom malware, stealthy behavior such as using legitimate software tools like PowerShell or PsExec to avoid detection, and advanced obfuscation methods to hide their activities from investigators. They also engage in targeted attacks against specific organizations, including government agencies, financial institutions, and other high-profile targets around the world. Overall, Ricochet Chollima is a highly skilled and persistent threat that requires careful monitoring and defense measures to prevent successful breaches of sensitive information.



Comments
new comment
Nobody has commented yet. Will you be the first?


Primary Names
APT37
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.