From One North Korean To Four North Koreans To Five Threats

2025-04-01 Ketman

https://www.ketman.org/one-north-korean-four-north-koreans.html

Thumbnail for From One North Korean To Four North Koreans To Five Threats

Ketman expands the Nick L Franklin investigation into a broader DPRK IT worker cluster centered on Aqua Protocol and related GitHub personas. The source says Aqua Protocol was a fake Web3 lending application built around Aave V3 code, seeded with nearly $800,000 in liquidity, and connected to accounts including NickLFranklin, SonataM, CrazyDream000, and jewelas. Ketman links the cluster to several threat types: AppleJeus-style payload delivery against security researchers, WageMole-style employment attempts, fake Web3 protocol credibility building, memecoin phishing pages, rug-pull activity, and a possible connection to the suspicious difx.com exchange. The article argues that DPRK-linked operators are mixing IT worker placement, malware delivery, phishing, and direct Web3 scams within the same network.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-04-01 2026-04-08
DOMAIN users.noreply.github.com 2025-04-01 2025-11-29
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
EMAIL [email protected] 2025-04-01 2025-04-01
URL https://arky-drab.vercel.app/ 2025-04-01 2025-04-01
URL https://ufobirddog.vercel.app/ 2025-04-01 2025-04-01
URL https://louie-iota.vercel.app/ 2025-04-01 2025-04-01
URL https://orken.vercel.app/ 2025-04-01 2025-04-01
URL https://decoy-nu.vercel.app/ 2025-04-01 2025-04-01
URL https://scambrokersreviews.com/… 2025-04-01 2025-04-01
URL https://www.louieraccoon.com/ 2025-04-01 2025-04-01
URL https://peku.vercel.app/ 2025-04-01 2025-04-01
URL https://vodcat-self.vercel.app/ 2025-04-01 2025-04-01
URL https://liquina.vip/ 2025-04-01 2025-04-01
URL https://www.steveerc.com/ 2025-04-01 2025-04-01
DOMAIN cexdifx.com 2025-04-01 2025-04-01
DOMAIN gamil.com 2025-04-01 2025-04-01
DOMAIN atholdex.com 2025-04-01 2025-04-01
DOMAIN ordifx.com 2025-04-01 2025-04-01
DOMAIN difx.com 2025-04-01 2025-04-01
DOMAIN liquina.ai 2025-04-01 2025-04-01
DOMAIN scambrokersreviews.com 2025-04-01 2025-04-01
DOMAIN thedifx.com 2025-04-01 2025-04-01
DOMAIN liquina.vip 2025-04-01 2025-04-01

Related Reports

« Back