Threat Actor Profile

Famous Chollima

Famous Chollima is a North Korea-aligned threat actor that gets hired rather than breaking in. Operators use stolen and fabricated identities to land remote IT jobs, then steal data, source code, and cryptocurrency to fund the DPRK regime.

Threat Actor Profile

Famous Chollima

Country of Origin

Famous Chollima originates from North Korea (DPRK). This alignment is based on its operational tactics, motivations, and ties to the broader DPRK state-sponsored cyber framework.

Members

Details on individual members are scarce. The group has utilized numerous identities and aliases to mask its activities, often creating fake profiles and resumes to infiltrate organizations under a pretense.

Leadership

The specific leadership of Famous Chollima remains unknown. However, there are indications that the group operates under a coordinated command structure, likely linked to North Korea's broader cyber operations apparatus.

Famous Chollima TTPs

Tactics

Famous Chollima blends financially motivated fraud with intelligence collection. Rather than breaking in, operators get hired — securing legitimate credentials and long-term access, then using it to collect salaries, steal data, and drain cryptocurrency assets.

Techniques

Famous Chollima's core technique is employment fraud. Operators use stolen and fabricated identities — doctored resumes, altered profile photos, and borrowed work histories — to get hired as remote IT, engineering, and blockchain staff at companies worldwide. Once inside, they draw a salary and, in some cases, access source code, sensitive data, and cryptocurrency wallets. U.S.-based facilitators keep the illusion going by hosting "laptop farms": they receive company-issued laptops at their homes and connect them to KVM devices so overseas operators can log in and appear to be working stateside.

A second track targets job seekers instead of employers. Fake recruiters and counterfeit interview sites push candidates to run bogus "driver updates" or copy-paste PowerShell and curl commands, delivering custom malware — GolangGhost on macOS, PylangGhost on Windows — to steal credentials, browser data, and crypto wallets.

Procedures

Common methods include: Malware delivery via fake interview steps, driver installations, and browser theft extensions. Exploiting victims via PowerShell or curl commands to initiate malicious downloads. Establishing long-term persistence for data exfiltration and espionage.

Want to Shut Down Threats Before They Start?

Notable Cyberattacks

Recent campaigns include the May 2025 discovery of PylangGhost targeting Windows users, marking an evolution from their earlier macOS focus. Social engineering tactics evolved simultaneously, enhancing their success rate.


Law Enforcement & Arrests

Law enforcement has taken repeated action against the DPRK remote IT worker schemes this activity falls under, though most of the North Korean operators remain out of reach.

In June 2025, the Justice Department announced coordinated actions across 16 states, including two indictments, an arrest, a guilty plea, searches of 29 known or suspected laptop farms, and the seizure of 29 financial accounts, 21 fraudulent websites, and roughly 200 computers. A separate indictment in the Northern District of Georgia charged four North Korean nationals with stealing more than $900,000 in cryptocurrency from an Atlanta blockchain company and a Serbia-based token company after being hired under false identities.

In April 2026, two U.S. facilitators, Kejia Wang and Zhenxing Wang, were sentenced to 108 and 92 months for running laptop farms that helped North Korean IT workers get hired at more than 100 U.S. companies using the stolen identities of at least 80 Americans, generating over $5 million for the regime. Additional facilitators were sentenced between July 2025 and March 2026.

The FBI maintains wanted pages for DPRK IT workers and fraudulent remote IT workers from the DPRK, and the State Department is offering up to $5 million for information on individuals tied to these schemes. Because the operators themselves sit inside North Korea, arrests have concentrated on the U.S.-based enablers who make the scheme possible.

How to Defend Against Famous Chollima

1

Training employees with security awareness training to identify phishing and social engineering tactics.

2

Monitoring for malicious IOCs like domains and malware signatures.

3

Endpoint Detection and Response (EDR): Leverage tools to identify malware signatures and anomalous network behavior.

4

Harden your remote hiring process: verify identity documents and work history independently, require live on-camera interviews, watch for candidates who redirect equipment to a different address than the one on file, and flag mismatches between a candidate's stated location and their login geography.



Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free