Famous Chollima — APT Profile
CrowdStrike coined FAMOUS CHOLLIMA for North Korea's remote IT worker fraud program and assesses it active since at least 2018; the same operation is tracked as UNC5267 by Mandiant, as NICKEL TAPESTRY by Secureworks and as Wagemole in earlier public reporting. Thousands of DPRK operatives, stationed mainly in China and Russia, combine stolen and fabricated identities with generative-AI resumes, personas and live interview assistance to win remote engineering jobs; CrowdStrike alone worked more than 320 FAMOUS CHOLLIMA insider cases in the 12 months to 30 June 2025, a 220 percent year-over-year rise. Unit 42 assesses that individual workers earn up to $300,000 a year, that Pyongyang retains up to 90 percent of it, and that the scheme collectively yields hundreds of millions of dollars annually for UN-prohibited weapons programs. Employment is sustained by facilitators outside North Korea who operate laptop farms, hosting company-issued laptops at their homes behind KVM-over-IP switches so the work appears to originate in the target country. A Justice Department action on 30 June 2025 searched 29 laptop farms across 16 states and charged a scheme that used the identities of more than 80 US persons to obtain jobs at more than 100 US companies, including many Fortune 500 firms, and that took ITAR-controlled data from a California defense contractor. Since late 2024 Google Threat Intelligence and Secureworks have tracked expansion into Europe and Japan and an escalation to extortion, with dismissed workers threatening to leak stolen source code and proprietary data.Also tracked as
UNC5267, Wagemole, NK IT Workers, NICKEL TAPESTRY, UNC5342, Void Dokkaebi
IntelFusions coverage (7)
- North Korea's hacking machine is bigger than Lazarus 2026-09-07 · Nation-State
- North Korean fake workers move into healthcare and sales 2026-08-28 · Nation-State
- State hackers now log in instead of dropping malware 2026-08-20 · Nation-State
- North Korean fake hires used ChatGPT to pass interviews 2026-08-18 · Nation-State
- Attackers weaponize most public exploits within 48 hours 2026-08-03 · Vulnerabilities
- Fake Cloudflare page hidden in an npm package redirects victims to a phishing site 2026-07-05 · Cyber Incidents
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10 · Nation-State
Tools & malware
- AnyDesk remote-access
- Beavertail Stealer
- Caffeine mouse-jiggler
- Chrome Remote Desktop remote-access
- GoToRemote / LogMeIn remote-access
- InvisibleFerret Backdoor
- RustDesk remote-access
- TeamViewer remote-access
Vendor research
- the original report Recorded Future
- DPRK IT Workers Expanding in Scope and Scale Google Threat Intelligence Group
- NICKEL TAPESTRY expands fraudulent worker operations Secureworks
- NICKEL TAPESTRY Infrastructure Associated with Crowdfunding Scheme Secureworks (Sophos)
- Staying a Step Ahead: Mitigating the DPRK IT Worker Threat Google Cloud (Mandiant)
- Advisory on DPRK IT Workers CISA
- Famous Chollima: DPRK IT Workers Infiltrating Western Companies CrowdStrike
- North Korean IT Workers: Industrial-Scale Social Engineering Mandiant
Countries linked to this actor
- Australia targets
- North Korea origin
- Bosnia and Herzegovina targets