North Korea's Famous Chollima group was responsible for 47% of all state sponsored intrusions against U.S. Operatives use AI tools like ChatGPT and Gemini to create deepfake video interviews, fake LinkedIn profiles, and stolen identities to get hired as remote developers—CrowdStrike investigated over 320 such cases,...

Create a landscape editorial hero image for this Studio Global article: What does CrowdStrike's latest annual report reveal about North Korean hacking activity targeting U.S. tech companies, including the prevale. Article summary: Here is what CrowdStrike's latest reports reveal across each of your questions.. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "CrowdStrike's experts reveal how threat actors are evading traditional defenses by weaponizing AI, targeting unmanaged edge devices. North Korea Outpace AI-" source context "CrowdStrike 2026 Global Threat Report | Key Cyber Threat Trends" Reference image 2: visual subject "CrowdStrike's experts reveal how threat actors are evading traditional defenses by weaponizing AI, targeting unmanaged edge devices. North Korea Outpace AI-" source context "CrowdSt
A single North Korean hacking group is now responsible for nearly half of all state-backed digital break-ins targeting America’s technology sector. According to newly released threat reports from cybersecurity firm CrowdStrike, the group tracked as “Famous Chollima” operates a sprawling, AI-powered employment-fraud scheme that places regime operatives inside Western companies as remote software developers. Once hired, they steal intellectual property, exfiltrate sensitive data, and siphon salaries back to Pyongyang—while a parallel wave of crypto heists generated over $2 billion last year alone .
The 130% year-over-year spike in North Korea-linked cyber incidents documented by CrowdStrike is not driven by traditional malware. Instead, threat hunters are responding to an avalanche of insider threat cases where North Korean nationals have obtained legitimate access to corporate networks .
The latest data, spanning April 2025 to May 2026, shows North Korean threat actors executed 47% of all state-sponsored “hands-on-keyboard” intrusions into U.S. tech firms—and Famous Chollima alone accounted for that entire share . This is a significant escalation from 2024, when CrowdStrike tracked 304 Famous Chollima incidents, 40% of which involved the adversary acting as a trusted insider
.
Famous Chollima’s core tradecraft is both sophisticated and disturbingly simple: get a job. Active since at least 2018, the group specializes in obtaining fraudulent freelance or full-time equivalent employment, typically as remote software developers .
What has changed recently is the industrialization of the hiring fraud. CrowdStrike’s 2025 Threat Hunting Report describes a "clear picture of an adversary deeply interweaving GenAI-powered tools that automate and optimize workflows at every stage of the hiring and employment process" .
The specific tactics documented in CrowdStrike’s reports include:
CrowdStrike’s OverWatch threat hunting team investigated over 320 distinct cases of Famous Chollima operatives obtaining fraudulent employment in a 12-month period—a staggering 220% increase over the prior year . The success rate of these disguised hires also surged by 220%, and CrowdStrike’s head of counter adversary operations, Adam Meyers, noted his team is now responding to roughly one such incident every day
.
The motivation is a dual-revenue pipeline for the sanctioned regime.
The first stream is straightforward salary theft. Famous Chollima operatives collect paychecks from the companies they infiltrate, funneling the wages to North Korea. The second—and more damaging for victims—is intellectual property theft. Once inside a network with legitimate credentials, the operatives steal proprietary source code, trade secrets, and other sensitive IP .
Parallel to the IT worker scheme, the wider North Korean cyber ecosystem runs a massive cryptocurrency theft operation. CrowdStrike’s 2026 Financial Services Threat Landscape Report found that DPRK-nexus groups stole a combined $2.02 billion in digital assets during 2025, a 51% increase compared to the previous year . The largest single heist—$1.46 billion in cryptocurrency—was attributed to the related group PRESSURE CHOLLIMA, which deployed trojanized software through a supply-chain compromise
.
The ultimate destination of these funds is explicit. Stolen billions are “almost certainly laundered and will be used to fund the regime’s military and nuclear weapons programs," the 2026 Financial Services Threat Landscape Report states .
While Famous Chollima’s public reporting emphasizes infiltration and theft, data exfiltration carries a second potential payoff. Broader North Korean cyber operations have adopted data-theft extortion tactics—threatening to leak stolen information unless a ransom is paid.
CrowdStrike’s earlier Global Threat Report tracked a 76% increase in victims named on dedicated leak sites as data-theft extortion became a preferred monetization route for many adversaries . The firm notes that DPRK-nexus actors have been observed conducting data theft and extortion campaigns without deploying ransomware, applying pressure through the threat of exposing sensitive data
.
CrowdStrike has also confirmed that in service engagements involving Famous Chollima, data theft was confirmed in 50% of cases . That exfiltrated information could be leveraged for extortion, though the public report summaries focus more directly on the group’s insider infiltration and salary-crypto theft pipeline. The exact details of Famous Chollima’s post-detection ransom playbook may be available only in the full, unredacted threat reports rather than the public summaries available to date.
The scale and sophistication of the operation represents a new paradigm in nation-state cyber intrusion, shifting the threat from perimeter attacks to trusted insiders who get hired, get paid, and steal from within.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
North Korea's Famous Chollima group was responsible for 47% of all state sponsored intrusions against U.S.
North Korea's Famous Chollima group was responsible for 47% of all state sponsored intrusions against U.S. Operatives use AI tools like ChatGPT and Gemini to create deepfake video interviews, fake LinkedIn profiles, and stolen identities to get hired as remote developers—CrowdStrike investigated over 320 such cases, a 220%...
The regime's cyber program stole a record $2.02 billion in cryptocurrency in 2025, with the funds laundered to support North Korea's nuclear weapons and ballistic missile programs.