Somewhere in the hiring pipeline of a Western technology company last year, a developer submitted a polished résumé, aced a video interview with a convincing AI-generated face, and started drawing a salary — while quietly looting the company's intellectual property for Kim Jong Un. This is not a hypothetical. According to CrowdStrike's latest annual cybersecurity report, a North Korean hacking collective the firm calls "Famous Chollima" was responsible for 47% of all state-backed, hands-on-keyboard intrusions targeting the technology sector between April 2025 and May 2026. The scale of the operation is striking, but so is its method.
Unlike automated malware, which conventional security software can often detect and quarantine, hands-on-keyboard intrusions are driven by real human operators who adapt in real time. Famous Chollima typically enters a company's systems using stolen credentials, then pivots to legitimate software tools already installed on corporate networks — a technique that leaves few obvious traces. Because North Korea is subject to sweeping international sanctions over its nuclear weapons programme, the operatives must disguise their nationality entirely, using AI-generated deepfake video, fraudulent passports, and stolen driver's licences to present themselves as Americans or other foreign nationals when applying for remote roles across the United States, Europe, and Asia. The financial motive is layered.
The salaries these operatives collect are funnelled directly back to Pyongyang, providing hard currency that helps the regime circumvent a near-total exclusion from the Western banking system.