AUTO-UPDATED

North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says

North Korean hacking group FAMOUS CHOLLIMA conducted nearly half of all state-sponsored cyberattacks on global technology firms between April 2025 and March by posing as remote IT workers.

Key Points

  • FAMOUS CHOLLIMA accounted for 47% of hands-on-keyboard intrusions targeting tech companies across North America, Europe, and Asia.
  • The group infiltrated organizations by securing remote software developer roles to deploy malware and steal cryptocurrency from blockchain developers.
  • Hackers utilized AI tools to increase the speed and sophistication of their attacks, significantly reducing detection windows for targeted companies.
  • A coalition of 16 governments, led by the United States, has launched a coordinated campaign to disrupt the group's technology and financial operations.
  • Anthropic is releasing its Mythos model, which can exploit major operating systems, to select partners for defensive security testing.

Why it Matters

These sophisticated infiltration tactics highlight a growing vulnerability in remote hiring practices that state-sponsored actors exploit to fund illicit weapons programs. As AI accelerates the speed of cyberattacks, companies face increasing pressure to bolster their defensive infrastructure and identity verification processes to prevent unauthorized access.
Forbes Published by Ty Roush, Forbes Staff, Ty Roush, Forbes Staff https://www.forbes.com/sites/tylerroush/
Read original