
THREAT LEVEL - HIGH
25-09-2024
Famous Chollima APT on the Rise
Threat Level Description
IthacaLabs has maintained the Threat Level: High – An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.
Description
We have observed that there is an increased activity from the Advanced Persistent Threat (APT) group Famous Chollima, known for cyber espionage and disruptive attacks. This group has expanded its focus, targeting organizations globally, including those based in Cyprus.
Using advanced tactics, such as spear-phishing (including calendar invitations), custom malware, and exploitation of vulnerabilities, Famous Chollima aims to steal sensitive data, including intellectual property and classified information. Their attacks are highly sophisticated, often going undetected for extended periods, leading to significant data exfiltration.
Organizations should be aware of the heightened threat and act promptly to protect critical assets, given the potential for severe operational and reputational impact.
Recommendation(s)
You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.
The guidelines below will help you protect against security threats:
- Implement an EDR solution.
- DNS Shield – Advanced Security Control.
- Install anti-virus and spyware detection software on all computer systems. Free software may not provide protection against the latest threats compared with an industry standard product.
- Update your computers regularly with the latest versions and patches of both antivirus and antispyware software.
- Ensure systems are patched regularly, particularly operating system and key application with security patches.
- It is strongly recommended to implement a Security Awareness program, addressed to all your management and staff, designed to increase the level of understanding regarding Social Engineering and security threats in general.
References:



