DPRK IT Workers | A Network of Active Front Companies and Their Links to China
2024-11-20 • Sentinel One •
SentinelLabs linked several active software-consulting front companies to the DPRK IT worker scheme and to a wider set of organizations being created in China. The report describes websites for Independent Lab LLC, Shenyang Tonywang Technology, Tony WKJ LLC, and HopanaTech that presented themselves as legitimate outsourcing or software-development firms while copying content and branding from real companies such as Kitrum, Urolime, ArohaTech, and ITechArt. Several domains used NameCheap registration and overlapping hosting, including InterServer infrastructure at 174.138.181[.]198, while HopanaTech used Asia Web Services hosting. The activity supports North Korean revenue generation by helping IT workers appear to be non-DPRK professionals and front companies when seeking remote work or client engagement.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | inditechlab.com | 2024-11-20 | 2025-07-31 |
| DOMAIN | wkjllc.com | 2024-11-20 | 2025-07-31 |
| DOMAIN | tonywangtech.com | 2024-11-20 | 2025-07-31 |
| DOMAIN | hopanatech.com | 2024-11-20 | 2025-07-31 |
| [email protected] | 2024-11-20 | 2024-11-20 | |
| DOMAIN | huguotechltd.com | 2024-11-20 | 2024-11-20 |
| DOMAIN | jswc.com.cn | 2024-11-20 | 2024-11-20 |
| IPv4 | 174.138.181.198 | 2024-11-20 | 2024-11-20 |
| IPv4 | 103.15.29.44 | 2024-11-20 | 2024-11-20 |
| IPv4 | 180.235.135.177 | 2024-11-20 | 2024-11-20 |