North Korean operators are expanding access and revenue-generation operations through fraudulent remote employment, targeted intrusions, and cryptocurrency theft. The DPRK-linked Famous Chollima group—also tracked as UNC5267 and Jasper Sleet—uses fabricated identities, falsified documents, AI-assisted communications, proxy interviewers, laptop farms, and payment fraud to secure remote IT roles at technology, aerospace, defense, software, blockchain, cryptocurrency, and DeFi organizations. The workers gain legitimate internal access by abusing recruiting, onboarding, payroll, and remote-work processes, with activity concentrated in the United States and increasingly observed in Europe.
Other DPRK-linked activity demonstrates a broader intrusion capability. Andariel has used watering-hole compromises, spearphishing attachments, malicious macros, and exploitation of client-side ActiveX vulnerabilities—including zero-days—to access targets, then deploys additional tools, enumerates systems and network connections, and collects files for exfiltration; it has also concealed executables in PNG files using steganography. Separately, the FBI, DC3, and Japan's National Police Agency attributed the theft of approximately $308 million from Bitcoin.DMM.com to North Korean actors tracked as TraderTraitor, underscoring the financial risk to cryptocurrency businesses and organizations with digital-asset exposure.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group identified increased coordinated DPRK-linked fake-worker operations in several European countries.
The DPRK-linked fake IT worker scam emerged, using fraudulent identities to place operatives in remote jobs at foreign organizations and gain trusted access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.barracuda.com
Open sourcefbi.gov
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.