Astrill VPN and DPRK Remote Worker Fraud
2024-12-19 • Spur •
Spur released a list of roughly 2,400 Astrill VPN IP addresses active as of December 19, 2024 because DPRK-linked remote worker personas have used the service to hide their locations. The post says intelligence and threat-analysis teams have observed North Korean state actors infiltrating organizations worldwide to earn funds for the regime, and customer reporting continued to show fraudulent remote worker campaigns from Astrill VPN addresses. The data is intended to help hiring, identity, and security teams flag anonymized access patterns associated with DPRK IT worker fraud.
Related Reports
Shares tag: ITWorker • Published within a month
Shares tag: ITWorker • Published within a month
2025-01-08 •
60% Match
Threat Landscape Update: North Korean IT Workers, OSINT, and Remote Monitoring and Management Abuse
Microsoft
Shares tag: ITWorker • Published within a month
Shares tag: ITWorker • Published within a month
Shares tag: ITWorker • Published within a week
2024-12-12 •
60% Match
Fourteen North Korean Nationals Indicted for Carrying Out Multi-Year Fraudulent Information Technology Worker Scheme and Related Extortions
USJustice
Shares tag: ITWorker • Published within a week