How do you catch a DPRK actor you ask
2025-04-19 • Cookie Connoisseur •
The archived post lists practical detection cues for DPRK remote IT-worker schemes during recruiting and onboarding. It advises employers to watch for VPN use during applications, formulaic developer-themed email addresses, virtual phone numbers, new or repurposed LinkedIn profiles, AI or virtual video presentation, and inconsistent claimed residence, resume address, and laptop shipping address. For issued devices, the source warns that facilitators may install remote management tools such as AnyDesk or attach IP-KVM hardware disguised as normal peripherals to give the DPRK worker access. It also recommends using Wi-Fi BSSID telemetry, resume metadata, HR payment records, and reference-phone checks to identify facilitator locations and synthetic applicant patterns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://luke.ford.dev | 2025-04-19 | 2025-04-19 |
| DOMAIN | luke.ford.dev | 2025-04-19 | 2025-04-19 |