Cyber Saga: In the Footsteps of the DPRK IT Workers
2026-04-08 • Group-IB •
Group-IB traced a DPRK IT worker ecosystem from a previously reported email address to GitHub accounts, portfolio sites, resume materials, freelance platform activity, and archived persona packages that supported fake remote developer identities. The activity used synthetic or repurposed personas such as Nicolas Sammaritano, Caddo Smith, Dominic Williams, Dejan Teofilovic, Mirko Djuricic, Aaron Groenke, and Atsuo Koizumi, with overlapping repositories, emails, images, and hosted portfolios indicating centralized reuse of materials. The investigation highlights a labor-enabled access model rather than a malware chain: operators build credible developer histories, acquire or seek verified freelancing accounts, prepare AI-assisted job responses, and maintain communication and payment infrastructure. The report matters because companies hiring these personas face insider, data theft, revenue-generation, and sanctions-compliance risks tied to DPRK remote worker operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected]… | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| [email protected] | 2026-04-08 | 2026-04-08 | |
| DOMAIN | liam.perrin.dev | 2026-04-08 | 2026-04-08 |
| DOMAIN | felix-moore.netlify.com | 2026-04-08 | 2026-04-08 |
| DOMAIN | robertlopez9216.github.io | 2026-04-08 | 2026-04-08 |
| DOMAIN | healer1064.github.io | 2026-04-08 | 2026-04-08 |
| DOMAIN | tech-veteran.onrender.com | 2026-04-08 | 2026-04-08 |
| DOMAIN | ranko746.dev | 2026-04-08 | 2026-04-08 |
| DOMAIN | bruno.jackson.dev | 2026-04-08 | 2026-04-08 |
| DOMAIN | starmastar1126.github.io | 2026-04-08 | 2026-04-08 |
| DOMAIN | skydev-hub.github.io | 2026-04-08 | 2026-04-08 |
| DOMAIN | jacob.rd.dev | 2026-04-08 | 2026-04-08 |
| DOMAIN | flosports.tv | 2026-04-08 | 2026-04-08 |
| [email protected] | 2025-04-01 | 2026-04-08 |