Infected by GTA 5 Cheats: How an Infostealer Infection Unmasked a North Korean Agent

2026-03-02 Hudson Rock

https://www.hudsonrock.com/blog/6236

Thumbnail for Infected by GTA 5 Cheats: How an Infostealer Infection Unmasked a North Korean Agent

Hudson Rock analyzes a suspected DPRK IT worker machine infected with LummaC2, using the stolen telemetry to expose an Indonesian proxy node tied to fake IT-worker and fraud activity. The investigation began with Funnull CDN credentials in the log, then found the operator using Indonesian-facing aliases, multiple browser profiles, synthetic identities, cloud and hosting accounts, and localized browsing behavior to maintain cover. Installed tools and search history indicate use of OBS VirtualCam, video-editing utilities, AI text/video and voice tools, and deepfake workflows for identity verification and interviews. Browser artifacts also show development and administration of scam infrastructure, including cloned crypto-exchange interfaces, “steal-U” USDT-draining smart-contract source searches, CraxsRAT interest, scam dashboards, wallet segregation, and direct access to fake portals. The case matters for DPRK-focused tracking because an infostealer compromise exposed operational tradecraft, infrastructure laundering links, identity-synthesis tooling, and cryptocurrency-fraud development from inside a suspected operator environment.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://grab-alibaba.com/admin/… 2026-03-02 2026-03-02
URL https://www.mediafire.com/file/… 2026-03-02 2026-03-02
URL https://www.ymwu.com/ 2026-03-02 2026-03-02
URL https://www.mediafire.com/file/… 2026-03-02 2026-03-02
URL https://mesta.cc/admin/dashboar… 2026-03-02 2026-03-02
URL https://director.grab-amazon.com 2026-03-02 2026-03-02
DOMAIN ymwu.com 2026-03-02 2026-03-02
DOMAIN director.grab-amazon.com 2026-03-02 2026-03-02
DOMAIN funnull.com 2026-03-02 2026-03-02
DOMAIN grab-amazon.com 2026-03-02 2026-03-02
DOMAIN grab-alibaba.com 2026-03-02 2026-03-02
IPv4 180.252.20.71 2026-03-02 2026-03-02

Related Reports

« Back