Activity timeline
Famous Chollima appears in 19 tracked threats between and ; the busiest month was 2026-07 with 7 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 18 of 19 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 16 of 19 tracked threats
- T1005 Data from Local System — Collectionobserved in 15 of 19 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 14 of 19 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 13 of 19 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 12 of 19 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 11 of 19 tracked threats
- T1195 Supply Chain Compromise — Initial Accessobserved in 10 of 19 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 10 of 19 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 9 of 19 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 9 of 19 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 9 of 19 tracked threats
- T1204 User Execution — Executionobserved in 9 of 19 tracked threats
- T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 9 of 19 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 9 of 19 tracked threats
Tracked threats
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via Fake Job Interviews and npm/PyPI/Go/Rust Supply-Chain PackagesHIGH
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle MalwareHIGH
- Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script DetectionHIGH
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT and Credential StealerCRITICAL
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)HIGH
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider Cluster)HIGH
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign Leaks Its Own Operator CredentialsHIGH
- North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source PackagesHIGH
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome ExtensionsCRITICAL
- PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer)HIGH
- North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDropHIGH
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)HIGH
- Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style)HIGH
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview)HIGH
- DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RATHIGH
- Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code RepositoriesHIGH
- Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job InterviewsHIGH
- Famous Chollima (DPRK) npm Supply Chain — Pastebin Text Steganography Dead-Drop Resolver, 17 Malicious Packages, Vercel C2 InfrastructureHIGH
- Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed Lures, and Staged JavaScript ExecutionCRITICAL