Famous Chollima is a North Korea-linked threat cluster associated with financially motivated cyber operations, fraudulent remote-employment schemes, and malware campaigns targeting the cryptocurrency, Web3, fintech, and software development ecosystems. The group is widely assessed as operating in support of DPRK state interests, including revenue generation and access acquisition, and has been linked by multiple vendors to broader Lazarus-aligned activity. Reported aliases include WaterPlum, CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, PurpleBravo, and Tenacious Pungsan. The actor is notable for combining social engineering with insider-threat tradecraft. A defining pattern is the use of fake recruiter outreach, fraudulent job offers, and interview lures to target software engineers, developers, and job seekers. In some operations, operators have posed as legitimate candidates or employees to obtain freelance or full-time roles inside foreign companies, particularly in cryptocurrency and technology firms. Public reporting also describes the use of stolen identities, fabricated résumés, generative AI, and real-time deepfake video manipulation during hiring processes to evade vetting and gain trusted access. Famous Chollima has also been associated with software supply-chain and developer-focused intrusion activity. The group has distributed malicious code through trojanized applications, fake interview or conferencing software, code repositories, and malicious npm packages. These campaigns frequently target users likely to handle wallets, credentials, source code, or other sensitive assets. Victimology consistently includes cryptocurrency companies, Web3 projects, software developers, and related service providers, with additional reporting indicating activity in Latin America and against organizations in countries including Argentina, Brazil, and Uruguay. Malware attributed to the cluster includes BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and related tooling. Reporting describes these families as cross-platform or Node.js-based malware used for credential theft, cryptocurrency wallet theft, file exfiltration, clipboard monitoring, screenshot capture, keylogging, browser data theft, remote command execution, and persistence. OtterCookie in particular has been observed evolving through multiple versions, adding capabilities such as browser credential theft, wallet-data extraction, file-upload modules, and virtual-machine detection. Campaign names associated with the actor include Contagious Interview, ClickFake Interview, and Contagious Trader. Operationally, the group blends espionage-style access methods with financially motivated objectives. Tradecraft described across reporting includes fake employment workflows, malicious package ecosystems, trojanized developer tools, remote desktop abuse, VPN and proxy layering, anti-analysis measures, obfuscation, and staged malware delivery. The actor’s objectives commonly include theft of cryptocurrency and credentials, monetization through fraudulent employment, and establishment of persistent access inside targeted organizations. This combination of insider access, developer-centric lures, and evolving malware makes Famous Chollima a significant DPRK cyber threat cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in connection with North Korea-themed cyber threat intelligence concerning job adverts hosted on Google Docs.
Referenced as a named threat actor in connection with a CrowdStrike technology threat landscape report.
Referenced in connection with a supply chain RAT campaign involving MicrosoftSystem64 and exfiltration to HuggingFace.
Referenced in connection with North Korea's abuse of Cloudflare Workers and Pages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.