North Korean hackers posing as remote IT professionals carried out nearly half of all manual cyber intrusions at US technology companies between April 2025 and May 2026 to fund Pyongyang’s illicit nuclear weapons programme, according to a new report by cybersecurity firm CrowdStrike.
The company’s latest annual report on the global threat landscape exposes the escalating danger posed by these state-sponsored operatives. Backed by the Kim Jong Un regime, these cybercriminals relentlessly target Western enterprises and software developers. Their primary objective is to exfiltrate critical corporate data and siphon cryptocurrency, bypassing international sanctions to fund North Korea’s prohibited nuclear weapons development.
The Rise of ‘Famous Chollima’ in the Tech Sector
CrowdStrike’s data reveals that during the period analysed, a specific North Korean hacking collective designated as “Famous Chollima” was responsible for 47% of all state-sponsored cyber campaigns aimed at the technology industry.
What are ‘Hands-on-Keyboard’ Attacks?
To combat these sophisticated threats, the security firm actively keeps track of hands-on-keyboard intrusions. Unlike automated malware that standard security software can easily detect, these manual attacks involve human threat actors actively navigating compromised networks. Typically initiated via compromised credentials or stolen passwords, the hackers exploit legitimate administrative tools already present within the victim’s infrastructure to establish a persistent, long-term foothold.
Deepfakes, Stolen Identities, and Corporate Infiltration
Famous Chollima’s tactics are remarkably deceptive. Operatives routinely masquerade as highly skilled remote IT workers, software engineers, and developers to secure employment at technology firms across the United States, Europe, and Asia.
To bypass stringent background checks, the hackers deploy artificial intelligence to generate highly convincing, real-time deepfake videos for virtual interviews. These digital masks are paired with forged or stolen identification documents, including driver’s licences and passports, allowing them to pose as Western or third-country nationals and evade United Nations sanctions.
Extortion and Cryptocurrency Theft
Once successfully onboarded, these state-backed moles collect legitimate salaries, which are directly funnelled back to the Pyongyang regime, whilst simultaneously harvesting proprietary code and sensitive intellectual property. The threat does not end with espionage; if these covert employees are detected and terminated, they frequently pivot to extortion, threatening to leak or sell the stolen corporate data unless a hefty ransom is paid.
Blockchain and cryptocurrency developers are particularly high-priority targets for these cyber operatives. By stealing vast sums of digital assets, the Kim regime successfully circumvents its exclusion from the global financial system. North Korea has amassed billions of dollars through these illicit operations over recent years, with an estimated $2 billion stolen in 2025 alone.
