Threat Intelligence / Actor / WageMole

WageMole

As of 2026-08-25, WageMole is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 14 threats spanning supply chain, malware, apt. Also known as Famous Chollima, nickel tapestry, purplebravo, storm-1877.

Nation: North Korea (DPRK) · 14 tracked threat(s) · Categories: SUPPLY_CHAIN, MALWARE, APT

Also known as: WageMole, Famous Chollima, nickel tapestry, purplebravo, storm-1877, unc5267, void dokkaebi, waterplum, Contagious Interview — DEV#POPPER, Contagious Interview (DPRK) — DEV#POPPER, PolinRider loader family, alternate hypothesis: UNC5342

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence