Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

North Koreans behind nearly half of US tech industry hacks, says CrowdStrike

Дата публикации: 10-06-2026 19:57:04

North Korean hackers posing as remote IT workers and recruiters remain a major threat to U.S., European, and Asian companies, accounting for about half of all attacks over the past 12 months.

Основное содержимое страницы с новостью.

A new report by cybersecurity giant CrowdStrike found North Korean hackers posing as remote IT workers and online recruiters made up about half of all documented “hands-on-keyboard” intrusions at U.S. tech companies over the past year.

The company’s latest annual report on the cybersecurity landscape highlights the growing threat from North Korean operatives, which have become a significant source of cyber intrusions across the tech industry. Hackers associated with the Kim Jong Un regime continuously target companies and developers with schemes aimed at stealing information and cryptocurrency to fund Pyongyang’s nuclear weapons program, which is banned under international law.

CrowdStrike said that during the period covered by the report — April 2025 to May 2026 — the North Korean hacking group that the company calls “Famous Chollima” accounted for 47% of all state-backed activity targeting the tech sector.

The security giant keeps track of hands-on-keyboard intrusions because they typically represent real human hackers conducting malicious and evasive cyber activity, rather than automated malware that traditional security tools can catch. These attacks generally begin with stolen passwords or credentials, followed by the abuse of legitimate tools already present in the target’s systems to maintain persistent access over time.

Famous Chollima is known for posing as tech workers, such as developers, coders, and IT, then applying for remote jobs at U.S., European, and Asian tech companies under false pretenses. To pull it off, the hackers use AI to generate real-time deepfake images to spoof the faces of real people, and pair those with fraudulent identity documents like stolen passports and driver licenses to pose as Americans or other foreign nationals. This is because North Korea is heavily sanctioned by the West and the United Nations for its ongoing development of nuclear weapons. 

Once in, the hackers also earn a salary from the companies they infiltrate, which gets funneled back to the North Korean regime, all while stealing intellectual property and other sensitive corporate information. That stolen information is frequently weaponized; when the operatives are eventually caught, they often threaten to expose what they’ve taken unless the company pays a ransom.

The hackers also target blockchain developers with the intention of stealing large amounts of crypto, which the Kim regime uses to skirt its broad inability to use the Western banking system. North Korea has netted billions of dollars in stolen crypto over the years, with some $2 billion during 2025 alone.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CNN: Microsoft полагает, что хакеры из КНДР похитили важные данные у ее клиентов в США0031-12-2019
2Reuters: КНДР похитила с помощью кибератак $2 млрд для военных программ0006-08-2019
3South Korea hits Coupang with $400M+ fine for data breach that affected millions0811-06-2026
4Reuters: хакеры из Китая за последние несколько лет атаковали крупнейшие IT-компании мира0026-06-2019
5Хакеры совершили 3,4 тыс. кибератак на МИД Южной Кореи в январе-августе 2020 года0006-10-2020
6Американская компания FireEye заявила о кибератаках хакеров из КНДР на банки по всему миру0003-10-2018
7CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang0809-06-2026
8Amazon pins multiple open source compromises on North Korea09.1430-07-2026
9СМИ: хакеры из КНДР чаще всего атакуют цели в Южной Корее0013-08-2019
10Представитель Пхеньяна назвал фальсификацией доклад ООН о кибератаках хакеров КНДР0002-09-2019

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: -2. Информативность: 7. Источник: techcrunch.com.