Assessment of DPRK IT Worker Tradecraft
2025-04-29 • NISOS •
https://nisos.com/research/dprk-it-worker-tradecraft-assessment/
Attachments
Nisos assessed DPRK IT worker tradecraft from 2022 through 2025, focusing on fabricated developer personas used for freelance and remote employment. The observed personas evolved from cartoon or stock images to AI-manipulated profile photos, portfolio websites built from public templates, and reused resume introductions for blockchain and Web3 roles. Nisos also found GitHub account reuse across multiple personas, including redsky500 links to Code Solution, CodeJourney, and Ryosuke Yamamoto, plus shared contact patterns such as the 0302 handle. The assessment gives recruiters and security teams practical indicators for detecting DPRK worker personas before they gain corporate access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-04-29 | 2025-04-29 | |
| DOMAIN | bootstrapmade.com | 2025-04-29 | 2025-04-29 |