Famous Chollima is a North Korean state-sponsored threat cluster associated with fraudulent remote-employment operations and financially motivated intrusion activity. It is widely linked to DPRK IT-worker schemes in which operators use stolen or fabricated identities, manipulated résumés, VPNs, remote-access infrastructure, and, in some cases, real-time AI deepfakes to obtain software engineering and other technical roles at foreign organizations. Once embedded, operators can siphon wages to the DPRK and potentially gain insider access for data theft or further compromise. The cluster has targeted cryptocurrency, Web3, fintech, blockchain, and software-development organizations, including through fake job-interview lures and trojanized developer tooling. Famous Chollima has been associated with the Contagious Interview, ClickFake Interview, and Contagious Trader activity clusters and with Node.js-based malware including BeaverTail, OtterCookie, and OtterCandy. These tools support theft of browser credentials and cryptocurrency-wallet data, keylogging, clipboard monitoring, screenshot capture, file collection and exfiltration, remote command execution, and cross-platform compromise of Windows, macOS, and Linux systems. Delivery methods include malicious software packages, trojanized code repositories and applications, and social-engineering lures distributed through job-recruitment channels. Reported aliases include WaterPlum, CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, PurpleBravo, and Tenacious Pungsan. Famous Chollima is also described as operating within the broader Lazarus-linked DPRK cyber ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in connection with an alleged malicious npm transitive-dependency delivery chain involving ulid-xyz; the post provides no further attribution evidence or operational detail.
Referenced in connection with North Korea-themed cyber threat intelligence concerning job adverts hosted on Google Docs.
Referenced as a named threat actor in connection with a CrowdStrike technology threat landscape report.
Referenced in connection with a supply chain RAT campaign involving MicrosoftSystem64 and exfiltration to HuggingFace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.