// 4 ZERO-DAY · 4 CVE · 4 EXPLOIT IN THE LAST 24H
The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using real-time AI deepfakes and stolen identities to infiltrate companies as remote IT workers.

A perfect candidate for a remote software-developer role: solid résumé, convincing video interview, paperwork in order. Behind the screen, though, there is neither the real face nor the real name. It’s Famous Chollima, the North Korean hacking group that — according to TechCrunch citing CrowdStrike’s Technology Threat Landscape Report 2026 — executed 47% of all state-backed attacks against the technology sector between April 2025 and May 2026. The technique: real-time deepfakes and fabricated identities to plant IT workers inside target companies.

Key Takeaways
  • Famous Chollima conducted 47% of state-sponsored attacks on the tech sector from April 2025 to May 2026, per TechCrunch citing CrowdStrike.
  • The group uses real-time AI deepfakes and forged documents to land remote IT positions at U.S., European, and Asian firms.
  • Fake workers funnel salaries to the North Korean regime and exfiltrate intellectual property.
  • The 47% figure is filtered: TechCrunch reports the CrowdStrike report, which this article has not consulted directly.

The Method: Fake Interviews, Real Paychecks

According to TechCrunch, citing the CrowdStrike report, Famous Chollima employs generative AI to produce real-time deepfakes that swap the faces of real people during video interview calls. These synthetic images are paired with counterfeit identity documents — stolen passports and driver’s licenses — to pose as U.S. citizens or other nationalities.

Once hired, the bogus IT workers collect salaries that are routed to the North Korean regime while simultaneously stealing intellectual property and, if discovered, threatening extortion. The operation turns remote recruiting into a direct infiltration vector: the attacker enters with valid credentials and authorized access to internal systems.

Nearly Half of State Attacks: The Figure and Its Limits

The 47% share represents a majority of state-sponsored activity targeting the tech sector in the period examined. By comparison, Chinese actors accounted for over 58% of state intrusions against the sector, according to the same CrowdStrike analysis reported by Hardware Upgrade. The two figures are not mutually exclusive; they cover partially different timeframes and attack categories that may overlap.

The provenance chain must be stated explicitly: CrowdStrike’s Technology Threat Landscape Report 2026 was not consulted directly for this article. All citations pass through editorial outlets — primarily TechCrunch, with Cryptonomist and Hardware Upgrade republishing — which filter content and context. It is unclear whether the 47% refers to the global tech sector or specifically to U.S. tech companies: TechCrunch specifies “U.S. tech companies,” while other sources generalize.

"Famous Chollima accounted for 47% of all state-backed activity targeting the tech sector" — CrowdStrike, reported by TechCrunch on June 10, 2026

What to Do Now

The Famous Chollima case points to specific identity-verification measures for remote hiring. Tech companies recruiting remote IT roles — the exact profile the group targets — must treat candidate authentication as a security control, not just an administrative step.

Real-time biometric verification with challenges a deepfake cannot solve (random movements, responses to unexpected questions) is a documented countermeasure. Cross-validating identity documents against government databases, where available, reduces the risk of stolen passports and licenses. Segmenting access for new remote hires, with minimal permissions during the first weeks, limits exposure if an infiltrator clears initial checks.

The brief does not document whether these techniques are in continuous operational use or still experimental for Famous Chollima. The source does not specify the operation’s scale in terms of number of infiltrators or compromised companies.

Context: One Group, an Extraordinary Share

Famous Chollima is not the only North Korean actor active in cyberspace, but it is the one concentrating the highest share of state-backed attacks against the tech sector in the analyzed period. Distinctions from other documented groups — Kimsuky, APT45 — are not clarified in available sources; possible nomenclature overlaps are unverified.

The case underscores a qualitative shift in infiltration techniques. Compromising an external endpoint is no longer necessary: the attacker becomes the endpoint, with valid credentials. The attack surface moves from the technological perimeter to the identity-verification process.

Adam Meyers, CrowdStrike’s Head of Counter Adversary Operations, summarized the landscape in a statement reported by Hardware Upgrade: “Technology companies are creating the most valuable and most targeted assets in the world. Every innovation in AI creates both a competitive advantage and a new attack surface.” The quote — general to the tech sector, not specific to Famous Chollima — describes the environment in which the 47% figure sits.

Closing

The 47% figure does not mean North Korea “conquers” the tech sector. It means a specific group, with specific techniques, achieved a majority share in a specific category of attacks over a specific period. Precision matters: the brief does not support narratives of conquest or absolute dominance. It supports a sophisticated, documented operation that exploits generative AI to craft convincing false identities and infiltrate companies at their most vulnerable point: hiring.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. techcrunch.com
  2. cryptonomist.ch
  3. en.cryptonomist.ch
  4. edge9.hwupgrade.it
  5. cisa.gov
  6. this.weekinsecurity.com
  7. crowdstrike.com
  8. cybersecitalia.it
  9. securityweek.com