A new report from cybersecurity giant CrowdStrike finds that North Korean hackers posing as remote IT employees or online recruiters accounted for nearly half of all documented “keyboarding” intrusions at U.S. tech companies in the past year.
The company's latest annual report on the state of cybersecurity highlights the growing threat from North Korean operatives, who have become a significant source of cyber intrusions across the technology industry. Hackers linked to Kim Jong Un's regime continue to target companies and developers with schemes aimed at stealing information and cryptocurrencies used to fund North Korea's nuclear weapons program, which is prohibited by international law.
According to CrowdStrike, during the period covered by the report (April 2025 to May 2026), the North Korean hacking group it calls Famous Chillima accounted for 47% of all state-sponsored activity targeting the tech sector.
Security giants track keyboard intrusions because they are typically caused by real hackers conducting malicious and evasive cyber activity, rather than automated malware that traditional security tools can catch. These attacks typically begin with password or credential theft and then exploit legitimate tools already present on the target system to maintain persistent access over an extended period of time.
Cholima is known for posing as a developer, programmer, IT or other technology worker and applying for remote jobs at technology companies in the United States, Europe, and Asia under false pretenses. To do this successfully, hackers use AI to generate real-time deepfake images to disguise real people's faces, and then combine the images with fraudulent identification documents, such as stolen passports or driver's licenses, to impersonate Americans or other foreign nationals. This is because North Korea is under severe sanctions from Western countries and the United Nations for continuing to develop nuclear weapons.
The hackers also receive salaries from the companies they breach, which are then funneled to the North Korean regime, while stealing intellectual property and other sensitive company information. Stolen information is often used as a weapon. When the operatives are eventually caught, they often threaten to reveal what they have stolen unless the company pays a ransom.
Hackers are also targeting blockchain developers to steal large amounts of cryptocurrencies that the Kim regime is using to circumvent widespread access to Western banking systems. North Korea has made billions of dollars in stolen cryptocurrencies over the years, about $2 billion in 2025 alone.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

