Famous Chollima — APT Profile

CrowdStrike coined FAMOUS CHOLLIMA for North Korea's remote IT worker fraud program and assesses it active since at least 2018; the same operation is tracked as UNC5267 by Mandiant, as NICKEL TAPESTRY by Secureworks and as Wagemole in earlier public reporting. Thousands of DPRK operatives, stationed mainly in China and Russia, combine stolen and fabricated identities with generative-AI resumes, personas and live interview assistance to win remote engineering jobs; CrowdStrike alone worked more than 320 FAMOUS CHOLLIMA insider cases in the 12 months to 30 June 2025, a 220 percent year-over-year rise. Unit 42 assesses that individual workers earn up to $300,000 a year, that Pyongyang retains up to 90 percent of it, and that the scheme collectively yields hundreds of millions of dollars annually for UN-prohibited weapons programs. Employment is sustained by facilitators outside North Korea who operate laptop farms, hosting company-issued laptops at their homes behind KVM-over-IP switches so the work appears to originate in the target country. A Justice Department action on 30 June 2025 searched 29 laptop farms across 16 states and charged a scheme that used the identities of more than 80 US persons to obtain jobs at more than 100 US companies, including many Fortune 500 firms, and that took ITAR-controlled data from a California defense contractor. Since late 2024 Google Threat Intelligence and Secureworks have tracked expansion into Europe and Japan and an escalation to extortion, with dismissed workers threatening to leak stolen source code and proprietary data.

Also tracked as

UNC5267, Wagemole, NK IT Workers, NICKEL TAPESTRY, UNC5342, Void Dokkaebi

IntelFusions coverage (7)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions