Famous Chollima is a North Korea-linked threat cluster associated with state-sponsored cyber operations and illicit remote-employment schemes. The actor is widely tracked under multiple aliases including WaterPlum, CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, PurpleBravo, and Tenacious Pungsan, and is frequently discussed in relation to broader DPRK cyber activity and, in some reporting, the Lazarus ecosystem. Its operations combine financially motivated intrusion activity with covert workforce infiltration intended to generate revenue for the North Korean regime and obtain access to targeted organizations. The group is best known for social-engineering campaigns built around fake job offers, interview lures, and fraudulent recruitment workflows targeting software developers, job seekers, and technical staff. It has also conducted insider-style operations in which operators obtain freelance or full-time roles under false identities, including the use of stolen personas, fabricated resumes, generative AI, and real-time deepfake video manipulation during interviews. Targeting has been especially prominent against cryptocurrency, Web3, fintech, and software engineering environments, with additional reporting indicating interest in broader corporate roles and strategic industries. Famous Chollima has been linked to malware families including BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and Tsunami-Framework, as well as malicious npm-based supply-chain activity and trojanized developer tooling or applications. Reported capabilities include credential theft, cryptocurrency wallet theft, keylogging, screenshot capture, clipboard monitoring, file theft, remote shell execution, persistence, anti-analysis measures, and cross-platform operation across Windows, macOS, and Linux. Delivery methods have included malicious packages, trojanized repositories, fake interview sites, and recruiter-themed lures distributed through common collaboration and freelance platforms. Campaigns associated with Famous Chollima include Contagious Interview, ClickFake Interview, and Contagious Trader. These operations have targeted the cryptocurrency ecosystem and software supply chain through deceptive development workflows, malware-laced coding tasks, and weaponized trading or developer tools. The actor has also been associated with abuse of cloud-hosted services and modern developer infrastructure to stage or support operations. Geographically, the actor has been observed targeting organizations in Latin America, including Argentina, Brazil, and Uruguay, through fraudulent employment and infiltration activity. Reporting also indicates targeting of Japanese software developers and broader global victimology tied to cryptocurrency and technology sectors. Famous Chollima’s dominant motivation is financial, particularly theft of cryptocurrency and revenue generation through fraudulent employment, though the actor’s state nexus and access-oriented tradecraft also create espionage and insider-risk implications once embedded inside victim organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in connection with North Korea-themed cyber threat intelligence concerning job adverts hosted on Google Docs.
Referenced as a named threat actor in connection with a CrowdStrike technology threat landscape report.
Referenced in connection with a supply chain RAT campaign involving MicrosoftSystem64 and exfiltration to HuggingFace.
Referenced in connection with North Korea's abuse of Cloudflare Workers and Pages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.