DPRK IT Workers | A Network of Active Front Companies and Their Links to China

2024-11-20 Sentinel One

https://www.sentinelone.com/labs/dprk-it-workers-a-network-of-active-front-companies-and-their-links-to-china/

Thumbnail for DPRK IT Workers | A Network of Active Front Companies and Their Links to China

SentinelLabs linked several active software-consulting front companies to the DPRK IT worker scheme and to a wider set of organizations being created in China. The report describes websites for Independent Lab LLC, Shenyang Tonywang Technology, Tony WKJ LLC, and HopanaTech that presented themselves as legitimate outsourcing or software-development firms while copying content and branding from real companies such as Kitrum, Urolime, ArohaTech, and ITechArt. Several domains used NameCheap registration and overlapping hosting, including InterServer infrastructure at 174.138.181[.]198, while HopanaTech used Asia Web Services hosting. The activity supports North Korean revenue generation by helping IT workers appear to be non-DPRK professionals and front companies when seeking remote work or client engagement.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN inditechlab.com 2024-11-20 2025-07-31
DOMAIN wkjllc.com 2024-11-20 2025-07-31
DOMAIN tonywangtech.com 2024-11-20 2025-07-31
DOMAIN hopanatech.com 2024-11-20 2025-07-31
EMAIL [email protected] 2024-11-20 2024-11-20
DOMAIN huguotechltd.com 2024-11-20 2024-11-20
DOMAIN jswc.com.cn 2024-11-20 2024-11-20
IPv4 174.138.181.198 2024-11-20 2024-11-20
IPv4 103.15.29.44 2024-11-20 2024-11-20
IPv4 180.235.135.177 2024-11-20 2024-11-20

Related Reports

« Back