NICKEL TAPESTRY Infrastructure Associated with Crowdfunding Scheme

2025-01-15 Secure Works

https://www.secureworks.com/blog/nickel-tapestry-infrastructure-associated-with-crowdfunding-scheme

Thumbnail for NICKEL TAPESTRY Infrastructure Associated with Crowdfunding Scheme

Secureworks links NICKEL TAPESTRY's North Korean IT worker operations to infrastructure that also appeared in a 2016 IndieGoGo crowdfunding scam. The report cites OFAC-designated Yanbian Silverstar and Volasys Silver Star, FBI evidence that freelancer accounts were accessed from 36.97.143[.]26 in Jilin, China, and historical WHOIS data for silverstarchina.com. The same registrant email and Yanbian street address appeared on kratosmemory.com, which was later tied to the Kratos portable wireless memory campaign whose backers reported never receiving products or refunds. Secureworks treats the overlap as evidence that DPRK-linked operators experimented with earlier revenue schemes before more mature IT worker operations.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN silverstarchina.com 2025-01-15 2025-01-15
DOMAIN kratosmemory.com 2025-01-15 2025-01-15
IPv4 36.97.143.26 2025-01-15 2025-01-15

Related Actors

Related Reports

« Back