Famous Chollima — APT Profile
Famous Chollima represents North Korea large-scale IT worker fraud scheme. Thousands of operatives use stolen identities and AI personas to obtain remote IT jobs at Fortune 500 companies. Earnings fund weapons programs. FBI/DOJ/State warnings issued. Some workers install backdoors.Also tracked as
UNC5267, Wagemole, NK IT Workers, NICKEL TAPESTRY, Contagious Interview, UNC5342, Void Dokkaebi, PurpleBravo, Tenacious Pungsan, Storm-1877
Tools & malware
- AnyDesk remote-access
- Beavertail Stealer
- Caffeine mouse-jiggler
- Chrome Remote Desktop remote-access
- GoToRemote / LogMeIn remote-access
- InvisibleFerret Backdoor
- RustDesk remote-access
- TeamViewer remote-access
Vendor research
- Staying a Step Ahead: Mitigating the DPRK IT Worker Threat Google Cloud (Mandiant)
- NICKEL TAPESTRY Infrastructure Associated with Crowdfunding Scheme Secureworks (Sophos)
- Advisory on DPRK IT Workers CISA
- North Korean IT Workers: Industrial-Scale Social Engineering Mandiant
- Famous Chollima: DPRK IT Workers Infiltrating Western Companies CrowdStrike