Github를 통한 북한 IT 개발자 위장 취업 캠페인
2025-02-18 • Igloo • North Korean IT Developer Fake Employment Campaign Using GitHub •
https://www.igloopedia.com/19ef216a-760c-8008-a248-dde97abdadf3
IGLOO analyzed two GitHub accounts, CryptoNinja0331 and ican0220, as likely infrastructure for North Korean IT worker fake-employment activity. The repositories held resume and portfolio material, fake profile images, email and Upwork account data, project research, commit-author manipulation scripts, and references to Astrill VPN, TeamViewer, and AnyDesk. The report also found a Zoom-themed malicious file in an Upwork account folder, with a bundled loader and Ramsay malware, showing that the employment-fraud setup included developer-facing malware delivery artifacts. The activity is relevant to remote hiring controls because it combines stolen or synthetic identities, freelance platform workflows, remote access tooling, cryptocurrency payment movement, and repository manipulation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | smspva.com | 2025-02-18 | 2025-11-07 |
| DOMAIN | laborx.com | 2025-02-18 | 2025-08-28 |
| HASH | 9a9b4f36809506529a85e915d3cf5057 | 2025-02-18 | 2025-02-18 |
| HASH | 4036fee4fbe561315ff183e1dcc3e83f | 2025-02-18 | 2025-02-18 |
| HASH | ae10f33eabaa385d671b184bc13bdfe7 | 2025-02-18 | 2025-02-18 |
| URL | https://githubachievements.com/ | 2025-02-18 | 2025-02-18 |
| URL | https://sms-activate.guru/en | 2025-02-18 | 2025-02-18 |
| URL | https://cvbuilder.standout-cv.c… | 2025-02-18 | 2025-02-18 |
| URL | https://servers.fivem.net/ | 2025-02-18 | 2025-02-18 |
| URL | https://selfmadewebdesigner.com… | 2025-02-18 | 2025-02-18 |
| URL | https://www.adcisolutions.com/k… | 2025-02-18 | 2025-02-18 |
| URL | https://discadia.com/ | 2025-02-18 | 2025-02-18 |
| URL | https://simplelogin.io | 2025-02-18 | 2025-02-18 |
| URL | https://www.wappalyzer.com/ | 2025-02-18 | 2025-02-18 |
| URL | https://trends.builtwith.com/we… | 2025-02-18 | 2025-02-18 |
| URL | https://smspva.com/ | 2025-02-18 | 2025-02-18 |
| URL | https://laborx.com/ | 2025-02-18 | 2025-02-18 |
| URL | https://felixmerchant.com/ | 2025-02-18 | 2025-02-18 |
| URL | https://logomakr.com/ | 2025-02-18 | 2025-02-18 |
| DOMAIN | trends.builtwith.com | 2025-02-18 | 2025-02-18 |
| DOMAIN | felixmerchant.com | 2025-02-18 | 2025-02-18 |
| DOMAIN | selfmadewebdesigner.com | 2025-02-18 | 2025-02-18 |
| DOMAIN | servers.fivem.net | 2025-02-18 | 2025-02-18 |
| DOMAIN | githubachievements.com | 2025-02-18 | 2025-02-18 |
| DOMAIN | cvbuilder.standout-cv.com | 2025-02-18 | 2025-02-18 |
| DOMAIN | sms-activate.guru | 2025-02-18 | 2025-02-18 |
| DOMAIN | discadia.com | 2025-02-18 | 2025-02-18 |
| DOMAIN | logomakr.com | 2025-02-18 | 2025-02-18 |