Pivoting on DPRK IT Worker Infrastructure
2026-04-30 • 4rchib4ld •
https://plausible-deniability.co/blog/PullingTheThread-DPRKWorkers/
Plausible Deniability pivots from Team Cymru's reporting on DPRK IT worker infrastructure to identify a possible related Luckyguys cluster centered on luckyguys[.]cloud. The domain was registered close to luckyguys[.]site through the same registrar, hosted a Gitea instance, and resolved subdomains through 45.15.167[.]146, whose PTR record pointed to rbluckyguys[.]com. The exposed panel text, repeated Luckyguys naming, messaging-style subdomains, and later nonresponsive endpoints suggest reusable infrastructure that may have been abandoned after public exposure. Attribution is assessed only at moderate confidence because the infrastructure resembles the Team Cymru cluster but does not directly overlap by IP.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rbluckyguys.com | 2026-04-30 | 2026-04-30 |
| IPv4 | 45.15.167.146 | 2026-04-30 | 2026-04-30 |