Spotted a Weird Github Organization? It Might be DPRK!
2025-10-01 • Ketman •
https://www.ketman.org/dprk-it-workers-github-organizations.html
Ketman describes GitHub organizations allegedly established and maintained by DPRK IT workers as hubs for credibility building, codebase management, recruitment fronts, malware-spreading opportunities, and crypto scams. The report focuses on organizations such as m8s-lab and HyperbuildX, which are described as fake outsourcing agencies around Solana, Web3, AI, crypto trading bots, and casino or lottery dApps. It details tactics including copied code presented as original work, inflated stars and followers, job-begging on social platforms, frequent identity changes, facilitator recruitment, and coordinated boosting between accounts. The source names multiple personas, emails, GitHub profiles, social accounts, and one on-chain address, giving defenders and hiring teams concrete identity-linkage signals for DPRK IT worker screening.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |
| DOMAIN | calendly.com | 2024-10-29 | 2026-03-02 |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| [email protected] | 2025-10-01 | 2025-10-01 | |
| URL | https://calendly.com/nailrusty-… | 2025-10-01 | 2025-10-01 |
| URL | https://futuresea.fun | 2025-10-01 | 2025-10-01 |
| URL | https://www.matthiasli.com/ | 2025-10-01 | 2025-10-01 |
| URL | https://adamglab.dev/ | 2025-10-01 | 2025-10-01 |
| URL | https://www.mooncity.io | 2025-10-01 | 2025-10-01 |
| DOMAIN | matthiasli.com | 2025-10-01 | 2025-10-01 |
| DOMAIN | nailrusty.dev | 2025-10-01 | 2025-10-01 |
| DOMAIN | adamglab.dev | 2025-10-01 | 2025-10-01 |
| DOMAIN | hyperbuildx.com | 2025-10-01 | 2025-10-01 |
| DOMAIN | futuresea.fun | 2025-10-01 | 2025-10-01 |