Famous Chollima is a North Korea-aligned threat cluster associated with fraudulent IT worker operations, recruiter-themed social engineering, and developer-focused malware delivery. Widely used aliases include Wagemole, UNC5267, Nickel Tapestry, PurpleBravo, Storm-1877, Tenacious Pungsan, Void Dokkaebi, WaterPlum, BadClone, and DPRK IT worker network/operations. The activity is linked to the DPRK’s broader effort to generate illicit revenue, evade sanctions, infiltrate foreign companies, and in some cases obtain access that can support follow-on cyber operations. A defining characteristic of Famous Chollima is the use of fabricated or stolen identities, fake companies, AI-enhanced personas, and fraudulent résumés to secure remote employment, especially in technology, software development, blockchain, and Web3 roles. Operators have been observed posing as job seekers to obtain salaried positions inside Western firms, sometimes with assistance from facilitators outside North Korea. This activity has been tied to long-term access inside victim environments, illicit salary withdrawals, and attempts to leverage privileged access for malware deployment or broader intrusion support. The cluster is also associated with the Contagious Interview ecosystem, in which operators impersonate recruiters or business contacts and lure targets into fake interviews, coding tests, or technical assessments. These lures commonly pressure victims into executing malicious code locally, including ClickFix-style instructions to paste attacker-supplied commands into a terminal or run trojanized developer projects. Reported malware and related tooling associated with this ecosystem include BeaverTail, InvisibleFerret, OTTERCOOKIE-like payloads, PylangGhost, GolangGhost, DEV#POPPER, and OmniStealer. Observed capabilities include credential theft, cryptocurrency wallet theft, browser data theft, clipboard theft, keylogging in some malware sets, file exfiltration, remote shell access, persistence, and post-exploitation through modular RAT functionality. Famous Chollima-linked operations have also expanded into software supply chain compromise. Activity tracked as PolinRider has been tied to compromised maintainer accounts, tampered legitimate repositories, malicious npm, Go, Packagist, and browser-extension artifacts, hidden JavaScript loaders, Git history rewriting, and blockchain-based payload retrieval. These campaigns target developers and organizations that rely on trusted open-source packages, with the apparent goal of stealing developer secrets, cloud tokens, source code, browser sessions, and cryptocurrency assets while maintaining resilient access. Targeting consistently centers on software developers, cryptocurrency and blockchain organizations, Web3 firms, and technology companies, but reporting also shows interest in legal, advisory, compliance, investment, and business roles that may have access to wallets, sensitive data, or corporate systems. The actor’s dominant motivation is financial, although the access obtained through fraudulent employment and malware operations can also create opportunities for espionage or disruptive follow-on activity in support of DPRK state objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
76 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
294 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korean-associated activity cluster referenced as methodologically linked to this campaign; known here for fake job and developer recruitment lures, with this operation expanding beyond those delivery themes into fake macOS update and ClickFix-style infection chains.
Conducting fake job interview and recruiter-themed social engineering campaigns against cryptocurrency-sector personnel, especially non-technical staff, to deliver remote access trojans, steal credentials and crypto wallet data, and generate revenue for North Korea.
Ongoing North Korean software supply-chain operation using malicious npm packages and blockchain-based C2 to deliver RAT and infostealer payloads to developers and Node.js environments.
Threat actor/malware cluster tied to an active npm supply-chain compromise affecting Joyfill beta packages, delivering a Node.js RAT via blockchain-resolved payload stages and maintaining persistence through developer tools and desktop applications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.