DPRK - ZEUS-DEV-919
2025-04-22 • Cookie Connoisseur •
https://docs.google.com/document/d/1IdVIzSr5NOi76ugu67Ob3t39K6b4Rz_P7an0Q0M9HWo/edit?tab=t.0
The excerpt presents raw, unfiltered OSINT links around a likely DPRK-linked GitHub persona identified as zeus-dev919, while repeatedly warning that the linkages require double verification. It describes repositories and public Google Drive folders that allegedly contain suspected DPRK personas, resumes, cover letters, operational procedures, Ethereum-related files, cookies, and other account artifacts. The material pivots across aliases and accounts including Zeus-dev907, HotCappuchino, Billy272, multiple email addresses, GitHub profiles, social accounts, Skype handles, and payment-related identifiers. Its value is as a lead set for DPRK IT-worker or persona infrastructure research, not as a fully validated attribution or intrusion analysis.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| [email protected] | 2025-04-22 | 2025-04-22 | |
| DOMAIN | hiration.com | 2025-04-22 | 2025-04-22 |