Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:05:43 UTC Home > List all groups > List all tools > List all groups using tool Hawup Tool: Hawup Names Hawup Hawup RAT Category Malware Type Backdoor Description (CrowdStrike) Falcon Intelligence identified the file as a Hawup RAT binary attributed to LABYRINTH CHOLLIMA, an adversary believed to conduct espionage operations in support of DPRK intelligence requirements. Once executed, the RAT called out to C2 IP addresses waiting for a response. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool Hawup Changed Name Country Observed APT groups   Lazarus Group, Hidden Cobra, Labyrinth Chollima 2007-May 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa885b8f-3a91-4573-afa6-64178c72f35d https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa885b8f-3a91-4573-afa6-64178c72f35d Page 1 of 1