Github를 통한 북한 IT 개발자 위장 취업 캠페인

2025-02-18 Igloo North Korean IT Developer Fake Employment Campaign Using GitHub

https://www.igloopedia.com/19ef216a-760c-8008-a248-dde97abdadf3

Thumbnail for Github를 통한 북한 IT 개발자 위장 취업 캠페인

IGLOO analyzed two GitHub accounts, CryptoNinja0331 and ican0220, as likely infrastructure for North Korean IT worker fake-employment activity. The repositories held resume and portfolio material, fake profile images, email and Upwork account data, project research, commit-author manipulation scripts, and references to Astrill VPN, TeamViewer, and AnyDesk. The report also found a Zoom-themed malicious file in an Upwork account folder, with a bundled loader and Ramsay malware, showing that the employment-fraud setup included developer-facing malware delivery artifacts. The activity is relevant to remote hiring controls because it combines stolen or synthetic identities, freelance platform workflows, remote access tooling, cryptocurrency payment movement, and repository manipulation.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN smspva.com 2025-02-18 2025-11-07
DOMAIN laborx.com 2025-02-18 2025-08-28
HASH 9a9b4f36809506529a85e915d3cf5057 2025-02-18 2025-02-18
HASH 4036fee4fbe561315ff183e1dcc3e83f 2025-02-18 2025-02-18
HASH ae10f33eabaa385d671b184bc13bdfe7 2025-02-18 2025-02-18
URL https://githubachievements.com/ 2025-02-18 2025-02-18
URL https://sms-activate.guru/en 2025-02-18 2025-02-18
URL https://cvbuilder.standout-cv.c… 2025-02-18 2025-02-18
URL https://servers.fivem.net/ 2025-02-18 2025-02-18
URL https://selfmadewebdesigner.com… 2025-02-18 2025-02-18
URL https://www.adcisolutions.com/k… 2025-02-18 2025-02-18
URL https://discadia.com/ 2025-02-18 2025-02-18
URL https://simplelogin.io 2025-02-18 2025-02-18
URL https://www.wappalyzer.com/ 2025-02-18 2025-02-18
URL https://trends.builtwith.com/we… 2025-02-18 2025-02-18
URL https://smspva.com/ 2025-02-18 2025-02-18
URL https://laborx.com/ 2025-02-18 2025-02-18
URL https://felixmerchant.com/ 2025-02-18 2025-02-18
URL https://logomakr.com/ 2025-02-18 2025-02-18
DOMAIN trends.builtwith.com 2025-02-18 2025-02-18
DOMAIN felixmerchant.com 2025-02-18 2025-02-18
DOMAIN selfmadewebdesigner.com 2025-02-18 2025-02-18
DOMAIN servers.fivem.net 2025-02-18 2025-02-18
DOMAIN githubachievements.com 2025-02-18 2025-02-18
DOMAIN cvbuilder.standout-cv.com 2025-02-18 2025-02-18
DOMAIN sms-activate.guru 2025-02-18 2025-02-18
DOMAIN discadia.com 2025-02-18 2025-02-18
DOMAIN logomakr.com 2025-02-18 2025-02-18

Related Reports

« Back