Timeline

CrowdStrike details North Korea's 'Famous Chollima' AI-enabled fake IT worker scheme

The cybersecurity firm logged over 320 such incidents in twelve months, a 220% year-on-year rise, funding North Korea's sanctioned weapons programmes.

  • Security & misuse
  • Notable

CrowdStrike published a threat-hunting report detailing “Famous Chollima,” a North Korean operation in which operatives use fabricated identities to win remote IT jobs at Western companies. The firm said it had identified more than 320 such incidents over the preceding twelve months, a 220% increase on the year before.

The report described operatives using generative AI to draft resumes tailored to job postings and to alter or “deepfake” their appearance and voice during video interviews, making it harder for hiring managers to catch inconsistencies between an applicant’s claimed identity and location. Once hired, workers channel their salaries back to North Korea, in some cases while also extracting company data for potential extortion — CrowdStrike noted a subset of cases in which access was later used to threaten data leaks after termination.

The scheme has been understood since at least 2024 as a significant funding stream for North Korea’s sanctioned nuclear and missile programmes, run through networks of laptop farms and facilitators inside target countries who receive and forward company hardware. CrowdStrike’s report marked one of the first detailed accounts of generative AI being folded into the scheme specifically to defeat interview-stage identity checks, rather than only to generate resumes or code, and it prompted renewed advisories to US employers about verifying remote hires.

The report added to a broader pattern researchers had been tracking through 2025, in which North Korean state-linked operators used AI tools not just to disguise identity but to sustain cover across an entire employment lifecycle — passing technical screens, participating in video calls and producing enough ordinary work output to avoid suspicion for months at a time. CrowdStrike and other researchers reported the technique escalating further over the following year, including to real-time deepfake video during live interviews, making it one of the more concrete illustrations of generative AI lowering the cost of large-scale, state-sponsored fraud rather than of catastrophic misuse.