Cyber Crime & ForensicPress Release

CrowdStrike Report: North Korean Adversaries Steal Billions in Digital Assets

Adversaries Weaponising AI to Compress the Time From Access to Impact

CrowdStrike has released the CrowdStrike 2026 Financial Services Threat Landscape Report, revealing that DPRK-nexus adversaries stole billions in digital assets in 2025 while industrialising cybercrime with Artificial Intelligence (AI)-powered deception. Hands-on-keyboard intrusions against financial institutions spiked 43% globally and 48% in North America over the past two years, as adversaries exploited trusted identities and SaaS applications to evade legacy defenses.

CrowdStrike Report Highlights

Based on frontline intelligence from CrowdStrike Counter Adversary Operations tracking more than 280 named adversaries, the report reveals:

  • Digital Asset Theft Hits Record Levels: DPRK-nexus actors drove a 51% year-over-year increase in digital asset theft in 2025, stealing a reported USD $2.02 billion across the sector. PRESSURE CHOLLIMA conducted the largest financial theft ever reported—USD $1.46 billion in cryptocurrency through trojanised software distributed via a supply chain compromise. GOLDEN CHOLLIMA used recruitment-themed lures to divert cryptocurrency funds and access cloud environments at fintechs in Southeast Asia and Canada.
  • DPRK Scales Deception with AI: DPRK-nexus actors used AI to scale operations against the sector. FAMOUS CHOLLIMA doubled its operations using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks. STARDUST CHOLLIMA tripled its operational tempo, deploying AI-generated recruiter personas and synthetic video conferencing environments to target FinTechs across North America, Europe, and Asia.
  • China-Nexus Espionage Scales Globally: China-nexus adversaries posed the most significant intelligence collection threat. HOLLOW PANDA conducted intrusions at financial institutions in the Philippines, Indonesia, and Brazil. MURKY PANDA deployed an operational relay box network across more than 150 endpoints in 36 countries, targeting 340 organisations across more than 30 sectors, with financial services among the most frequently targeted.
  • eCrime Pressure on the Sector Intensifies: 423 financial services organisations appeared on dedicated leak sites, marking a 27% increase year-over-year. MUTANT SPIDER drove the highest intrusion volume through vishing campaigns, then sold access to ransomware groups, enabling faster and more scalable attacks. In the first half of 2025, SCATTERED SPIDER resumed aggressive ransomware operations against insurance entities after a four-month pause.

Listen to the Adversary Universe podcast for insights into threat actors and recommendations to amplify security.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *