The North Korean hacking group known as Famous Chollima was responsible for approximately 47% of all hands-on-keyboard cyber intrusions targeting technology companies in the US and beyond between April 2025 and mid-2026, according to a CrowdStrike report [1, 2].
Unlike automated malware attacks, these intrusions are human-controlled. Hackers pose as remote IT workers and recruiters, using AI-generated deepfake photos and stolen identity documents to gain access to firms in North America, Europe, and Asia [1, 2]. Once inside, the attackers steal intellectual property and sensitive data, as well as cryptocurrency from blockchain developers. They then funnel stolen funds back to the North Korean regime [1, 2].
The hackers often earn salaries from the companies they infiltrate, sometimes exceeding what they could make legally in North Korea [1, 2]. CrowdStrike highlighted that AI technology has greatly improved the speed, scale, and sophistication of these operations, making them more difficult to detect [2].
Between April 2025 and March or May 2026 (sources differ), Famous Chollima extensively targeted remote developer roles across multiple regions, focusing on key positions within major tech firms [1, 2].
In a coordinated effort, US Cyber Command joined forces with 15 other governments to target Famous Chollima’s technology and cryptocurrency networks in a campaign aimed at disrupting their operations [2].
CrowdStrike publicly released its detailed report on June 9, 2026, outlining the hacking group's tactics and impact on the tech industry [2]. Cybersecurity teams are now working to strengthen remote workforce protections in response to these findings.