Interview with the Chollima V

2025-11-08 Bitso

https://quetzal.bitso.com/p/interview-with-the-chollima-v

Thumbnail for Interview with the Chollima V

Bitso's Quetzal Team describes another attempted DPRK-aligned remote hiring infiltration involving a Colombian software engineer persona named Sebastian who failed live interview scrutiny. The excerpt says the persona claimed native Spanish ability, deleted online profiles when challenged, used AstrillVPN, and later explained a scheme in which candidates attend interviews while one of ten ghost developers performs the job after hiring. The activity aligns with Famous Chollima-style remote IT worker operations against companies, startups, and organizations hiring software engineers. Listed indicators include LinkedIn and Klimb profile URLs for the Sebastian Tamayo persona, while the operational takeaway is the need for stronger identity checks, background validation, and interview controls for developer hiring.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.klimbup.com/perfile… 2025-11-08 2025-11-08

Related Actors

Related Reports

« Back