SparkDownloader is a North Korea-linked malware family associated with PRESSURE CHOLLIMA, the DPRK threat cluster publicly tracked as TraderTraitor and known for large-scale cryptocurrency theft operations. It appears to have succeeded an earlier implant referred to as SwDownloader around 2019 as PRESSURE CHOLLIMA diverged operationally from LABYRINTH CHOLLIMA. The malware is part of a specialized intrusion toolkit used in financially motivated campaigns against organizations holding significant digital assets.
SparkDownloader has been associated with technically advanced cryptocurrency-heist activity rather than broad commodity distribution. PRESSURE CHOLLIMA operations using this tooling have targeted high-value opportunities globally, especially entities in the cryptocurrency and fintech ecosystem. The broader operational pattern around this malware includes the use of trojanized software projects and malicious Node.js and Python packages to gain execution within victim environments and support follow-on deployment of additional implants. This places SparkDownloader within a malware lineage used for initial compromise and subsequent payload delivery in targeted intrusions.
The family is notable primarily for its role in DPRK cyber-enabled financial operations and its placement within a broader ecosystem of related malware used by coordinated North Korean units. Available information supports its use on Windows systems, but detailed public technical reporting on its internal functionality is limited in the supplied facts. High-confidence attribution links it to PRESSURE CHOLLIMA’s cryptocurrency theft mission and to the TraderTraitor activity cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PRESSURE CHOLLIMA operations likely diverged from LABYRINTH CHOLLIMA in February 2019 with experimental SwDownloader deployment, quickly replaced by SparkDownloader (tracked publicly as TraderTraitor).
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A downloader used by PRESSURE CHOLLIMA and publicly tracked as TraderTraitor.
A low-prevalence loader used by Pressure Chollima in cryptocurrency theft operations; successor to Swdownloader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.