North Korean threat actor deploying Hermes ransomware in financial SWIFT compromises.
Analyst brief
STARDUST CHOLLIMA (also tracked as Sapphire Sleet) is a likely North Korean state-sponsored threat actor linked to the deployment of Hermes ransomware during the 2017 SWIFT compromise of Taiwan's Far Eastern International Bank (FEIB). It primarily targets financial institutions, focusing on SWIFT infrastructure compromise. Known TTPs include custom ransomware (Hermes) execution during intrusion, though open-source data remains limited. Defenders should concentrate on SWIFT environment segmentation, anomalous transaction monitoring, and potential TTP overlaps with the broader Lazarus Group.
STARDUST CHOLLIMA
Sapphire Sleet
unknown
Open-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public reported as part of the “Lazarus Group”), because Hermes was executed on a host during the SWIFT compromise of FEIB in October 2017.
Which victim organization is linked to STARDUST CHOLLIMA's deployment of Hermes ransomware?+
STARDUST CHOLLIMA is reported to have deployed Hermes ransomware during the SWIFT compromise of Taiwan's Far Eastern International Bank (FEIB) in October 2017.