Inside the Scam: North Korea’s IT Worker Threat
2025-02-13 • Recorded Future •
https://www.recordedfuture.com/research/inside-the-scam-north-koreas-it-worker-threat
Attachments
cta-nk-2025-0213.pdf (2 MB)
Recorded Future describes North Korean IT-worker operations that use false identities and remote employment to generate regime revenue while creating insider risk for international companies. Insikt Group links the broader threat to PurpleBravo activity overlapping Contagious Interview, including BeaverTail, InvisibleFerret, and OtterCookie malware against cryptocurrency-sector software developers, and says at least three crypto-adjacent organizations were targeted in late 2024. The report also identifies TAG-121 as a separate cluster running front companies in China that spoof legitimate IT firms in several countries. Recommended defenses center on stricter identity checks, remote-work monitoring, limits on remote desktop software, port review, and controls that can detect unauthorized access or suspicious worker locations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-02-13 | 2025-02-13 | |
| [email protected] | 2025-02-13 | 2025-02-13 | |
| [email protected] | 2025-02-13 | 2025-02-13 | |
| [email protected] | 2025-02-13 | 2025-02-13 | |
| [email protected] | 2025-02-13 | 2025-02-13 | |
| DOMAIN | agencyhill99.com | 2025-02-13 | 2025-02-13 |
| IPv4 | 65.108.20.73 | 2025-02-13 | 2025-02-13 |
| DOMAIN | freeconference.com | 2024-10-23 | 2025-02-13 |