Pivoting on DPRK IT Worker Infrastructure

2026-04-30 4rchib4ld

https://plausible-deniability.co/blog/PullingTheThread-DPRKWorkers/

Thumbnail for Pivoting on DPRK IT Worker Infrastructure

Plausible Deniability pivots from Team Cymru's reporting on DPRK IT worker infrastructure to identify a possible related Luckyguys cluster centered on luckyguys[.]cloud. The domain was registered close to luckyguys[.]site through the same registrar, hosted a Gitea instance, and resolved subdomains through 45.15.167[.]146, whose PTR record pointed to rbluckyguys[.]com. The exposed panel text, repeated Luckyguys naming, messaging-style subdomains, and later nonresponsive endpoints suggest reusable infrastructure that may have been abandoned after public exposure. Attribution is assessed only at moderate confidence because the infrastructure resembles the Team Cymru cluster but does not directly overlap by IP.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rbluckyguys.com 2026-04-30 2026-04-30
IPv4 45.15.167.146 2026-04-30 2026-04-30

Related Reports

« Back