북한 IT 인력 위장 취업 OSINT 분석 보고서

2026-03-09 Logpresso OSINT Analysis Report on North Korean IT Workers Disguised as Employees

https://logpresso.com/ko/blog/2026-03-09-dprk-remote-it-worker-osint

Thumbnail for 북한 IT 인력 위장 취업 OSINT 분석 보고서

Logpresso analyzed 1,045,645 infostealer telemetry records collected since 2024 against 1,879 known DPRK remote IT worker account patterns to study fraudulent remote employment operations. The research correlated email accounts, IP addresses, hardware IDs, passwords, and shared passwords, assigning confidence levels based on overlapping signals such as IP, password, and hardware ID reuse. Key findings included single hardware IDs tied to as many as five personas, foreign-name profiles exposing Korean keyboard settings, and repeated password families such as keyboard-walk and themed variants. The activity also showed an operational stack involving SMS activation services, Astrill VPN, AnyDesk, GitHub, LinkedIn, Freelancer, Payoneer, Stripe, and concentration in infrastructure such as Russia’s TransTeleCom ASN and Hong Kong access events. The report frames DPRK IT worker fraud as organized multi-identity infrastructure that can create downstream risk through access to internal systems, source-code repositories, and cloud credentials.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2026-03-09 2026-03-09
EMAIL [email protected] 2026-03-09 2026-03-09
EMAIL [email protected] 2026-03-09 2026-03-09
EMAIL [email protected] 2026-03-09 2026-03-09
EMAIL [email protected] 2026-03-09 2026-03-09
EMAIL [email protected] 2026-03-09 2026-03-09
EMAIL [email protected] 2026-03-09 2026-03-09
DOMAIN sms-activate.org 2026-03-09 2026-03-09
DOMAIN angel.co 2026-03-09 2026-03-09
EMAIL [email protected] 2025-08-19 2026-03-09

Related Reports

« Back