Editor's note: This article is based on security vendor reports cited by secondary editorial sources. Direct access to the primary reports is not available.
Famous Chollima generated 47% of state-sponsored hacking attacks against the technology sector between April 2025 and May 2026. This is according to CrowdStrike, as reported by TechCrunch. The figure emerges within a broader picture: three North Korean groups — Famous Chollima, Kimsuky, and APT45 — are using generative AI with distinct but convergent tactics targeting the same ecosystem.
The findings, documented in the weeks leading up to August 10, 2026, do not indicate operational coordination among the groups. The available brief describes "complementary capabilities," not a unified pipeline or identical objective. Famous Chollima focuses on the remote recruitment vector; Kimsuky and APT45 operate on separate technical fronts.
- Famous Chollima generated 47% of state-backed attacks against the technology sector between April 2025 and May 2026, according to CrowdStrike as reported by TechCrunch.
- Kimsuky developed the HelloDoor malware with large language model assistance, with code comments containing emoji and machine-style grammatical errors, documented by Kaspersky in May 2026.
- APT45 employs "recursive prompting" — thousands of repeated LLM requests — to analyze software vulnerabilities, according to Google Threat Intelligence.
- Famous Chollima generates real-time deepfakes and fraudulent identity documents to infiltrate tech companies as remote workers, according to CrowdStrike.
- South Korea's National Cyber Security Center issued a forward-looking alert on "agentic" AI in June 2026.
Famous Chollima's 47%: Unresolved Geographic Ambiguity
CrowdStrike tracks "hands-on-keyboard" attacks — intrusions with active human operators, not automated malware. TechCrunch reports CrowdStrike's statement: "Famous Chollima accounted for 47% of all state-backed activity targeting the tech sector" during the period "April 2025 to May 2026."
TechCrunch's headline reads "US tech industry" but the body uses "tech sector" without geographic qualification. The source does not specify whether the data is global or limited to the United States. This ambiguity remains unresolved in the available material.
The CrowdStrike methodology, explained by TechCrunch, distinguishes attacks with human interaction because they represent "real human hackers conducting malicious and evasive cyber activity, rather than automated malware that traditional security tools can catch." Famous Chollima operates in this category, but with synthetic identities: real-time deepfakes and fraudulent documents replace the physical operator in interactions with victims.
"The cost to create credible identities, automate reconnaissance activities, and accelerate credential theft is now approaching zero" — Adam Meyers, Head of Counter Adversary Operations, CrowdStrike
HelloDoor and the AI Fingerprints in Kimsuky's Code
Kaspersky documented the HelloDoor malware, attributed to Kimsuky, in May 2026. The code comments contain emoji and "machine-style" grammatical errors — patterns attributable to large language model output. The source does not specify which model was used.
Kimsuky forged South Korean military identity documents with ChatGPT for phishing in September 2025. The group also targeted South Korean government certification infrastructure in the first half of 2026; precise dating is not available in the brief.
APT45 and Recursive Prompting for Vulnerability Analysis
Google Threat Intelligence documents that APT45 employs "recursive prompting": thousands of repeated LLM requests to test exploits against known vulnerabilities. The technique scales manual analysis, allowing a single operator to cover more targets. It is distinct from code generation: it is an automated verification loop to refine output through iterations.
The brief does not document APT45 or Kimsuky as active in the remote recruitment vector. The three groups' tactics remain separate within the same ecosystem.
Deepfakes and Remote Work: The Famous Chollima Vector
CrowdStrike, as reported by TechCrunch, describes the use of "AI to generate real-time deepfake images to spoof the faces of real people, and pair those with fraudulent identity documents like stolen passports and driver licenses to pose as Americans or other foreign nationals."
The vector is remote recruitment. Artificially crafted professional profiles pass video interviews with real-time generated faces. Access as a legitimate worker opens doors to code, infrastructure, and capital — with financial motivations alongside intelligence objectives.
Motivational Context: Crypto and Regime Funding
North Korean groups stole $643 million in cryptocurrency in the first half of 2026, accounting for 66% of global losses, according to TRM Labs as reported by The Crypto Gateway. The CrowdStrike Financial Services Threat Landscape Report 2026 cites $2.02 billion in digital assets stolen by DPRK-nexus actors in 2025, a 51% year-over-year increase. These figures provide motivational context; the brief does not link them directly to the three groups' AI tactics.
What Changes
The following observations are editorial inferences based on documented patterns, not directly suggested by the sources.
Genians detected the use of Ollama, GPT4All, Msty, and Cursor AI in North Korean offensive infrastructure. The source reports the detection; it does not derive operational consequences. The adoption of open-source tools is documented; the source does not specify how these reduce traceability or automate attack cycles.
South Korea's National Cyber Security Center issued an alert on "agentic" AI in June 2026. The alert is forward-looking: the source does not confirm that autonomous attacks have already occurred, but signals the risk of systems capable of "tens of thousands of malicious actions per second."
The convergence of the three tracks — AI-assisted malware, automated vulnerability analysis, deepfakes for workplace infiltration — shows a diversified ecosystem, not a coordinated operation. The brief does not document a unified pipeline among Kimsuky, APT45, and Famous Chollima.
Closing
The 47% figure positions Famous Chollima as the dominant actor in the CrowdStrike sample, but on a narrow field: state-backed attacks on the technology sector with detectable human interaction. The structural shift lies in the AI multiplier, not the complete replacement of the operator. Deepfakes, recursive prompting, and generative code assistance are parallel tactics that expand the attack surface more than traditional verification procedures are equipped to cover.
The source does not specify whether defenses based on static pattern recognition lose effectiveness in this scenario. Operational urgency remains an inference not directly documented in the available brief.
Information has been verified against cited sources and is current as of publication.
Sources
- https://cryptonomist.ch/2026/08/10/cyberattacchi-ai-corea-nord/
- https://en.cryptonomist.ch/2026/08/10/north-korean-ai-cyberattacks/
- https://techcrunch.com/2026/06/10/north-koreans-behind-nearly-half-of-us-tech-industry-hacks-says-crowdstrike/
- https://thecryptogateway.it/ai-hacking-attacchi-crypto-corea-del-nord/
- https://www.bitmat.it/sicurezza/cybercrime-finanziario-hacker-della-corea-del-nord-rubano-2-miliardi-in-criptovalute/
- https://this.weekinsecurity.com/
- https://www.securityweek.com/mandiant-shines-spotlight-on-apt45-behind-north-koreas-digital-military-machine/
- https://www.crowdstrike.com/en-us/blog/why-you-need-ai-and-machine-learning-to-combat-hands-on-keyboard-attacks/
- https://cryptonomist.ch/2026/08/08/hack-bybit-da-1-5-miliardi-di-dollari/