• About
  • Subscribe
  • Contact
Sunday, May 17, 2026
  • Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
No Result
View All Result
FutureCISO
No Result
View All Result
Home FutureCISO

AI-Driven DPRK theft and escalating ransomware pressure on financial services

by FutureCISO Editors
May 15, 2026
AI-Driven DPRK theft and escalating ransomware pressure on financial services

Photo by Tima Miroshnichenko from Pexels: https://www.pexels.com/photo/man-in-black-hoodie-having-a-video-call-5380682/

Share on FacebookShare on Twitter

Crowdstrike's 2026 Financial Services Threat Landscape Report warns that DPRK-nexus adversaries increased digital asset theft in 2025 while using AI to accelerate attacks against the financial sector. The company also said China-nexus espionage activity remains a major intelligence-collection risk, and that ransomware-related intrusions are continuing to intensify.

Theft rises sharply in 2025

CrowdStrike’s report says DPRK-nexus groups drove a 51% year-over-year increase in digital asset theft across the financial sector during 2025, with $2.02 billion in reported thefts.

It identifies PRESSURE CHOLLIMA as responsible for the largest reported financial theft—$1.46 billion in cryptocurrency—linked to trojanized software delivered through a supply-chain compromise.

CrowdStrike also describes GOLDEN CHOLLIMA as using “recruitment-themed” lures to divert funds and obtain access to cloud environments at fintechs, citing activity across Southeast Asia and Canada.

AI deception lowers the “time-to-impact”

Beyond theft volume, CrowdStrike argues AI is changing attackers’ operational tempo by reducing the time between initial access and impact. The company alleges FAMOUS CHOLLIMA used AI-generated identities to double its operations, infiltrating cryptocurrency exchanges, fintech platforms, and consumer banks.

It further claims STARDUST CHOLLIMA tripled its operational pace by deploying AI-generated recruiter personas and synthetic video-conferencing environments to target fintechs across North America, Europe, and Asia.

China-nexus espionage threat remains prominent

CrowdStrike said China-nexus adversaries pose the most significant intelligence collection threat. It cites HOLLOW PANDA intrusions against financial institutions in the Philippines, Indonesia, and Brazil.

The report also highlights MURKY PANDA, describing an “operational relay box network” spanning more than 150 endpoints in 36 countries, targeting 340 organizations across more than 30 sectors, with financial services among the most frequently targeted.

Related:  Security pros miss one in three security breaches

Ransomware/eCrime pressure rises via leak sites and vishing

The report also points to heightened downstream consequences for financial firms. CrowdStrike states 423 financial services organizations appeared on dedicated leak sites, a 27% year-over-year increase.

It attributes the highest intrusion volume to MUTANT SPIDER, saying it used vishing to drive access before selling it to ransomware groups. CrowdStrike also claims SCATTERED SPIDER resumed aggressive ransomware activity against insurance entities in the first half of 2025 after a four-month pause.

Tags: CrowdStrikeespionageransomwarestate-sponsored threats

FutureCISO Editors

No Result
View All Result

Recent Posts

  • AI-Driven DPRK theft and escalating ransomware pressure on financial services
  • Permiso brings runtime security to autonomous AI agents
  • AI driven threats reshape Singapore security outlook
  • AI-driven phishing hits 86% as attackers shift from inbox to calendar and Teams
  • SailPoint Agentic fabric tackles the hidden security crisis of AI Identities

Categories

  • AI and Machine Learning
  • Artificial Intelligence
  • Blogs
  • CHRO
  • CISO
  • CISO strategies
  • Cloud, Platforms and Ecosystems
  • Cloud, Virtualization, Operating Environments and Middleware
  • Compliance and Governance
  • Compliance and Governance
  • Compliance and Governance|People
  • Compliance and Governance|Technology
  • Computer, Storage, Networks, Connectivity
  • Culture and Behaviour
  • Culture and Behaviour|People
  • Cyber risk management
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity careers
  • Cybersecurity operations
  • Cybersecurity operations
  • Data Protection
  • Data Protection
  • Endpoint Security
  • Future Workplace
  • FutureCISO
  • Governance, Risk and Compliance
  • Governance, Standards and Regulations
  • HR, education and Training
  • Incident Response
  • IT-OT integration
  • Network Security
  • Operations
  • People
  • Process
  • Remote work
  • Resources
  • Risk Management
  • Risk Management
  • Security
  • Tactics and Strategies
  • Technology
  • Training and awarenes
  • Videos
  • Vulnerabilities and threats
  • Vulnerabilities and threats
  • Webcasts/Podcasts
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

[wpli_login_link]

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
  • Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl