Huntress analyzed several incidents involving DPRK remote workers (Famous Chollima) in partner environments. Learn key indicators to detect and prevent North Korean threats.
Researchers have identified a North Korean hacking group called Famous Chollima conducting a targeted campaign against cryptocurrency professionals using ClickFix social engineering lures. The attack delivers trojans designed to compromise both Windows and macOS systems, expanding the threat landscape for Web3 professionals beyond traditional single-platform attacks.
Russian APT BlueDelta leverages webhook.site and Microsoft Edge to conceal command-and-control communications for HOOKEDGE espionage operations targeting European government defense and diplomatic entities. The group, linked to Russia's GRU and overlapping with APT28, exploits the legitimate webhook testing service to hide malicious traffic from detection. Recorded Future's Insikt Group documented the campaign, revealing how the threat actor abuses developer tools to conduct sustained espionage against European government infrastructure.
North Korean remote workers are expanding beyond traditional IT roles into sales, marketing, and medical positions, according to Huntress research. These actors present a distinctive threat vector by securing legitimate remote employment and performing their assigned duties rather than immediately compromising systems, making them difficult to detect through conventional security controls. The threat highlights how nation-state actors are diversifying their workforce infiltration strategies across multiple business functions.
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via