KorDLL is a malware framework associated with North Korean cyber operations and assessed to be an early foundational codebase in the lineage that later evolved into the Hawup framework and subsequently into tooling used by the DPRK-linked clusters now tracked as Golden Chollima, Pressure Chollima, and the espionage-focused Labyrinth Chollima. It is best understood as part of the tactical and developmental DNA behind later North Korean malware ecosystems rather than as a single narrowly scoped payload family.
KorDLL is linked to a period of DPRK activity spanning roughly 2009 to 2015, when North Korean operators conducted a mix of disruptive, destructive, espionage, and later financially motivated operations. Reporting ties the framework’s descendants to campaigns targeting government, defense, aerospace, manufacturing, logistics, shipping, critical infrastructure, fintech, and cryptocurrency organizations. Shared code lineage and tradecraft derived from KorDLL and Hawup indicate centralized coordination and long-term malware development within the DPRK intelligence apparatus.
Because the available facts characterize KorDLL primarily as a common origin framework, high-confidence details about its exact standalone infection chain, payload role, and platform-specific behavior are limited. However, its descendants have been used in operations involving espionage, cryptocurrency theft, trojanized software, employment-themed social engineering, and messaging-based delivery, illustrating the strategic importance of the framework in the evolution of North Korean offensive tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Labyrinth Chollima evolved from the Kordll framework (2009-2015) through Hawup into three specialized subgroups with divergent malware paths and objectives.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Shared malware framework/tooling lineage used across multiple DPRK-linked operational subgroups.
A DPRK-linked malware framework lineage referenced as an early foundation (2009–2015) for later toolchains.
Framework referenced as tied to the infection vector for earlier WannaCry-related activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.