From One North Korean To Four North Koreans To Five Threats
2025-04-01 • Ketman •
https://www.ketman.org/one-north-korean-four-north-koreans.html
Ketman expands the Nick L Franklin investigation into a broader DPRK IT worker cluster centered on Aqua Protocol and related GitHub personas. The source says Aqua Protocol was a fake Web3 lending application built around Aave V3 code, seeded with nearly $800,000 in liquidity, and connected to accounts including NickLFranklin, SonataM, CrazyDream000, and jewelas. Ketman links the cluster to several threat types: AppleJeus-style payload delivery against security researchers, WageMole-style employment attempts, fake Web3 protocol credibility building, memecoin phishing pages, rug-pull activity, and a possible connection to the suspicious difx.com exchange. The article argues that DPRK-linked operators are mixing IT worker placement, malware delivery, phishing, and direct Web3 scams within the same network.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-04-01 | 2026-04-08 | |
| DOMAIN | users.noreply.github.com | 2025-04-01 | 2025-11-29 |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| [email protected] | 2025-04-01 | 2025-04-01 | |
| URL | https://arky-drab.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://ufobirddog.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://louie-iota.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://orken.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://decoy-nu.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://scambrokersreviews.com/… | 2025-04-01 | 2025-04-01 |
| URL | https://www.louieraccoon.com/ | 2025-04-01 | 2025-04-01 |
| URL | https://peku.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://vodcat-self.vercel.app/ | 2025-04-01 | 2025-04-01 |
| URL | https://liquina.vip/ | 2025-04-01 | 2025-04-01 |
| URL | https://www.steveerc.com/ | 2025-04-01 | 2025-04-01 |
| DOMAIN | cexdifx.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | gamil.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | atholdex.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | ordifx.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | difx.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | liquina.ai | 2025-04-01 | 2025-04-01 |
| DOMAIN | scambrokersreviews.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | thedifx.com | 2025-04-01 | 2025-04-01 |
| DOMAIN | liquina.vip | 2025-04-01 | 2025-04-01 |