CrowdStrike reports that FAMOUS CHOLLIMA, a North Korean–linked group posing as remote IT contractors, was behind about 47% of "hands-on-keyboard" intrusions targeting tech firms across North America, Europe and Asia between April 2025 and March 2026. The operatives recruited for developer roles, then deployed malware and stole cryptocurrency. CrowdStrike warns AI has amplified attackers' scale and speed, and U.S. authorities coordinated action with 15 other governments.
North Korean Hackers Posing As Remote IT Staff Behind Nearly Half Of Tech Firm Attacks, CrowdStrike Says

CrowdStrike's annual report warns that a North Korean–linked hacking unit that infiltrated companies by posing as remote IT contractors was responsible for a disproportionate share of state-sponsored intrusions targeting technology firms.
Key Findings
The group, identified by CrowdStrike as FAMOUS CHOLLIMA, carried out roughly 47% of all "hands-on-keyboard" intrusions — attacks in which a human operator actively controls systems rather than relying solely on automated malware — directed at tech companies across North America, Europe and Asia between April 2025 and March 2026, the report found.
CrowdStrike says operators ran extensive campaigns hiring for remote software developer roles. After gaining access, operatives deployed malware and stole cryptocurrency from blockchain developers and other targets. The attackers exploited the surge in remote job openings and a North Korean education system that produces a substantial pool of skilled IT workers; salaries earned abroad were often far higher than typical domestic pay.
The report adds that FAMOUS CHOLLIMA used AI tools to increase the speed, scale and sophistication of operations, shortening the window organizations have to detect and respond to intrusions. CrowdStrike warned that advances in artificial intelligence are amplifying attackers' capabilities across multiple dimensions.
International Response and Broader Context
U.S. officials coordinated a campaign against FAMOUS CHOLLIMA’s technology infrastructure and cryptocurrency activity alongside 15 other unnamed governments, CrowdStrike said. The Treasury Department has previously sanctioned North Korean cyber groups and warned that officials use IT workers to raise funds for ballistic missile and other weapons programs, often relying on fake documents, stolen identities and false personas to infiltrate foreign companies.
The report also referenced concerns about AI research tools. It noted reporting that Anthropic’s Mythos project — described by the company as capable of probing vulnerabilities in major operating systems and browsers — raised debates about dual-use tools and how to balance defensive research with public risk.
CrowdStrike: Advances in AI are accelerating adversary capabilities and demanding faster detection and response from organizations.
For companies hiring remote developers, the report highlights the need for stronger onboarding checks, continuous monitoring of privileged access and tighter controls around blockchain-development environments and cryptocurrency operations.
Help us improve.




























