ai-cybersecuritytrade-pressNewsThe Broadside2 min read

DPRK actors use AI for supply chain access, CrowdStrike reports

The vendor's taxonomy is proprietary, but AI-compressed initial access and IT-worker infiltration track with DOJ's own recent findings.


TL;DR

CrowdStrike's 2026 threat hunting report identifies North Korea's "Famous Chollima" group building AI-generated fake companies: websites, GitHub accounts, and email domains deployed to execute supply chain attacks and place remote IT workers inside tech firms. The group accounted for 55% of nation-state intrusions in CrowdStrike's telemetry from July 2025 to June 2026. The IT-worker infiltration pattern aligns with DOJ's June 2025 coordinated actions across 16 states, lending the vendor's broader AI-in-initial-access thesis more weight than the usual threat-report fare.

CrowdStrike's 2026 threat hunting report, covering July 2025 through June 2026, stakes a big claim: North Korean threat actors are no longer just using AI to write better phishing emails. They're using it to build entire fake companies that pass casual due diligence and get remote IT workers placed inside target organizations. CrowdStrike calls the group Famous Chollima and says it accounted for 55% of nation-state intrusions in the company's telemetry and 44% of all reported intrusions targeting the tech sector. Those percentages reflect one vendor's customer base, not the internet, and the naming convention doesn't map neatly onto the U.S. government's Kimsuky-Andariel-Lazarus taxonomy. But the underlying pattern isn't just marketing.

The IT-worker infiltration vector is independently documented. In June 2025, DOJ announced coordinated actions across 16 states targeting DPRK schemes that placed remote workers inside more than 100 U.S. companies using stolen identities. The sweep included indictments of U.S.-based facilitators and the seizure of roughly 200 computers and 29 financial accounts from suspected laptop farms. CISA's July 2024 advisory on the RGB 3rd Bureau, tracked as Andariel or Onyx Sleet, had already flagged the group's focus on defense, aerospace, nuclear, and engineering targets. What CrowdStrike adds is the AI layer: LLM-generated infrastructure that scales the deception, and AI-assisted reverse shells and reconnaissance scripts that compress the time between vulnerability disclosure and exploitation. Chinese actors Vault Panda and Genesis Panda were observed launching attacks within 24 hours of a critical web-app vulnerability going public, according to the report.

For the practitioner, the shift is real even if the vendor percentages are squishy. Supply chain due diligence that relies on checking a partner's website and GitHub presence now has a known blind spot. Remote hire identity verification needs to assume AI-generated supporting materials. And vulnerability management timelines measured in days no longer cut it when the adversary's clock starts the moment the CVE drops.


Published ·Deep Fathom