Cyber Saga: In the Footsteps of the DPRK IT Workers

2026-04-08 Group-IB

https://www.group-ib.com/blog/dprk-fake-remote-developers

Thumbnail for Cyber Saga: In the Footsteps of the DPRK IT Workers

Group-IB traced a DPRK IT worker ecosystem from a previously reported email address to GitHub accounts, portfolio sites, resume materials, freelance platform activity, and archived persona packages that supported fake remote developer identities. The activity used synthetic or repurposed personas such as Nicolas Sammaritano, Caddo Smith, Dominic Williams, Dejan Teofilovic, Mirko Djuricic, Aaron Groenke, and Atsuo Koizumi, with overlapping repositories, emails, images, and hosted portfolios indicating centralized reuse of materials. The investigation highlights a labor-enabled access model rather than a malware chain: operators build credible developer histories, acquire or seek verified freelancing accounts, prepare AI-assisted job responses, and maintain communication and payment infrastructure. The report matters because companies hiring these personas face insider, data theft, revenue-generation, and sanctions-compliance risks tied to DPRK remote worker operations.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN outlook.com 2018-09-06 2026-04-17
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
EMAIL [email protected] 2026-04-08 2026-04-08
DOMAIN liam.perrin.dev 2026-04-08 2026-04-08
DOMAIN felix-moore.netlify.com 2026-04-08 2026-04-08
DOMAIN robertlopez9216.github.io 2026-04-08 2026-04-08
DOMAIN healer1064.github.io 2026-04-08 2026-04-08
DOMAIN tech-veteran.onrender.com 2026-04-08 2026-04-08
DOMAIN ranko746.dev 2026-04-08 2026-04-08
DOMAIN bruno.jackson.dev 2026-04-08 2026-04-08
DOMAIN starmastar1126.github.io 2026-04-08 2026-04-08
DOMAIN skydev-hub.github.io 2026-04-08 2026-04-08
DOMAIN jacob.rd.dev 2026-04-08 2026-04-08
DOMAIN flosports.tv 2026-04-08 2026-04-08
EMAIL [email protected] 2025-04-01 2026-04-08

Related Actors

Related Reports

« Back