← Back to feed
TechJun 993% confidenceConfidence 93% — the share of independent, credible sources corroborating the core facts.

North Korean Hacking Group FAMOUS CHOLLIMA Behind Nearly Half of State-Sponsored Tech Company Attacks, CrowdStrike Reports

Center 100%
3 sources

A CrowdStrike annual report found that a single North Korean hacking group, Famous Chollima, accounted for 47% of all state-sponsored, hands-on-keyboard intrusions targeting tech companies across North America, Europe, and Asia between April 2025 and March 2026. The group operates by posing as remote IT workers using AI-generated deepfakes and stolen identity documents to infiltrate companies, earning salaries and stealing cryptocurrency and intellectual property to fund North Korea's weapons programs. The findings underscore the growing scale of state-sponsored cyber threats and the difficulty of detecting human-operated intrusions that exploit legitimate workplace access.

CrowdStrike's latest annual cybersecurity report reveals that Famous Chollima, a North Korean state-backed hacking unit, was responsible for nearly half of all documented hands-on-keyboard intrusions targeting the technology sector over the past year. Unlike automated malware attacks, these intrusions involve real human operators actively controlling compromised systems, making them harder to detect with traditional security tools. The group gains access by applying for remote developer and IT roles using AI-generated deepfake images, fraudulent identity documents, and stolen credentials to impersonate American or other foreign nationals. Once embedded, operatives collect salaries that are funneled back to the North Korean regime, while simultaneously stealing intellectual property, sensitive corporate data, and cryptocurrency — particularly targeting blockchain developers. North Korea has reportedly stolen approximately $2 billion in cryptocurrency during 2025 alone, proceeds used to circumvent Western banking sanctions and fund ballistic missile and weapons of mass destruction programs. When operatives are discovered, they frequently resort to extortion, threatening to expose stolen data unless companies pay a ransom. CrowdStrike also noted that AI tools are accelerating the sophistication and speed of these attacks, further compressing the window companies have to detect and respond to intrusions.

What's missing

No source specifies the total number of intrusions from which the 47% figure is derived, making it difficult to assess the absolute scale of the threat.

How coverage differed

All three outlets reported the core facts consistently and neutrally. TechRadar placed slightly greater emphasis on the weapons-of-mass-destruction angle and North Korea's 'Hermit Kingdom' framing, while TechCrunch provided the most operational detail on attack methodology, including the extortion phase and the $2 billion cryptocurrency theft figure.

What different sources said

  • ForbesCenter

    North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says

  • North Koreans behind nearly half of US tech industry hacks, says CrowdStrike

  • TechRadarCenter

    North Korea accounts for almost half of all attacks against tech industry – and the proceeds go straight into developing new weapons of mass destruction for the Hermit Kingdom

Related

TechConfidence 69% — the share of independent, credible sources corroborating the core facts.

Samsung Galaxy S25 and S25 FE See Significant Price Cuts

Samsung's Galaxy S25 and Galaxy S25 FE smartphones are currently available at notably reduced prices, with the S25 FE dropping $201 (33%) to $449 on Woot for a limited time. The price reductions come amid a competitive smartphone market and ahead of anticipated future Samsung releases. The discounts make previously premium-priced devices more accessible to budget-conscious consumers.

2 sourcesJun 16
TechConfidence 100% — the share of independent, credible sources corroborating the core facts.

Anthropic Disables Fable 5 and Mythos 5 AI Models Globally After US Government Export Control Order

Anthropic has suspended all public access to its two most advanced AI models, Fable 5 and Mythos 5, after the US Commerce Department issued an export control directive ordering the company to block foreign nationals from accessing them on national security grounds. The order came just three days after Fable 5's public launch and reportedly stems from government concerns about a potential jailbreak that could enable the models to assist with cyberattacks, though Anthropic says it received only verbal evidence of a narrow, non-universal vulnerability. The shutdown affects all customers globally — including enterprise users and Anthropic employees — and marks a significant escalation of US efforts to restrict foreign access to advanced AI models themselves, rather than just the chips that power them.

4 sourcesJun 16
TechConfidence 89% — the share of independent, credible sources corroborating the core facts.

Xbox Free Play Days Offers Three Games Free to Play June 11–14

Microsoft's Xbox Free Play Days program is offering Hell Let Loose, State of Decay 2: Juggernaut Edition, and Blasphemous 2 at no cost from June 11 to June 14. Hell Let Loose requires an Xbox Game Pass Ultimate, Premium, or Essential membership, while State of Decay 2 and Blasphemous 2 (via a five-hour timed trial) are accessible to all Xbox console owners. Players who wish to keep any of the games can purchase them at a limited-time discount and retain any achievements earned during the free period.

2 sourcesJun 13