North Korean cyber operatives posing as remote IT workers and recruiters were responsible for nearly half of all documented state-backed intrusions targeting U.S. technology companies over the past year, according to a new report released by cybersecurity firm CrowdStrike.
The company’s latest annual assessment of the global threat landscape highlights the increasing sophistication and scale of cyber activities linked to North Korea. According to CrowdStrike, hackers connected to the regime of North Korean leader Kim Jong Un continue to target technology firms and software developers in an effort to steal sensitive information and cryptocurrency that can help finance the country’s nuclear weapons program, which remains subject to international sanctions.
CrowdStrike reported that during the period between April 2025 and May 2026, the North Korean threat group it tracks as “Famous Chollima” accounted for 47% of all state-sponsored hands-on-keyboard activity directed at the technology sector.
The cybersecurity company focuses closely on hands-on-keyboard intrusions because they involve actual human attackers actively operating within compromised systems, rather than automated malware that conventional security tools are often designed to detect. These attacks typically begin with stolen credentials before progressing into the misuse of legitimate administrative tools already present within an organization’s environment, enabling hackers to establish long-term access while avoiding detection.
According to CrowdStrike, Famous Chollima has become particularly known for infiltrating companies by posing as software developers, coders, and IT professionals seeking remote employment opportunities at firms across the United States, Europe, and Asia.
To support these schemes, the operatives reportedly use artificial intelligence technologies to generate real-time deepfake images capable of impersonating legitimate individuals during virtual interviews. These fabricated identities are often reinforced with fraudulent documents, including stolen passports and driver’s licenses, allowing the attackers to present themselves as American citizens or nationals of other countries.
The tactics reflect North Korea’s efforts to bypass extensive sanctions imposed by Western nations and the United Nations over the country’s continued pursuit of nuclear weapons capabilities.
Once hired, the operatives reportedly receive salaries from the companies they infiltrate, with those earnings ultimately being redirected to support the North Korean regime. At the same time, they gain access to valuable intellectual property, proprietary data, and other sensitive corporate information.
CrowdStrike noted that the stolen information is frequently leveraged for further exploitation. In many cases, when the fraudulent employees are eventually identified, they allegedly threaten to release the data they have obtained unless the targeted organization agrees to pay a ransom.
The report also emphasized North Korea’s continued focus on the cryptocurrency sector. Blockchain developers and companies involved in digital assets remain attractive targets because successful attacks can generate substantial financial returns that help the regime circumvent restrictions on its access to the international banking system.
According to CrowdStrike, North Korean-linked actors have stolen billions of dollars worth of cryptocurrency over the years. The report noted that approximately $2 billion in crypto assets alone were linked to North Korean theft operations during 2025.
The findings underscore the growing challenge organizations face as nation-state cyber threats increasingly blend traditional espionage techniques with advanced technologies such as artificial intelligence, social engineering, and identity fraud. As remote work remains widespread across the global technology industry, cybersecurity experts continue to warn companies to strengthen hiring verification processes and remain vigilant against increasingly sophisticated infiltration attempts.



