Inside the Scam: North Korea’s IT Worker Threat

2025-02-13 Recorded Future

https://www.recordedfuture.com/research/inside-the-scam-north-koreas-it-worker-threat

Attachments

cta-nk-2025-0213.pdf (2 MB)

Thumbnail for Inside the Scam: North Korea’s IT Worker Threat

Recorded Future describes North Korean IT-worker operations that use false identities and remote employment to generate regime revenue while creating insider risk for international companies. Insikt Group links the broader threat to PurpleBravo activity overlapping Contagious Interview, including BeaverTail, InvisibleFerret, and OtterCookie malware against cryptocurrency-sector software developers, and says at least three crypto-adjacent organizations were targeted in late 2024. The report also identifies TAG-121 as a separate cluster running front companies in China that spoof legitimate IT firms in several countries. Recommended defenses center on stricter identity checks, remote-work monitoring, limits on remote desktop software, port review, and controls that can detect unauthorized access or suspicious worker locations.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-02-13 2025-02-13
EMAIL [email protected] 2025-02-13 2025-02-13
EMAIL [email protected] 2025-02-13 2025-02-13
EMAIL [email protected] 2025-02-13 2025-02-13
EMAIL [email protected] 2025-02-13 2025-02-13
DOMAIN agencyhill99.com 2025-02-13 2025-02-13
IPv4 65.108.20.73 2025-02-13 2025-02-13
DOMAIN freeconference.com 2024-10-23 2025-02-13

Related Actors

Related Reports

2025-02-20 • 31% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: BeaverTail, InvisibleFerret • Published within a week
« Back