Spotted a Weird Github Organization? It Might be DPRK!

2025-10-01 Ketman

https://www.ketman.org/dprk-it-workers-github-organizations.html

Thumbnail for Spotted a Weird Github Organization? It Might be DPRK!

Ketman describes GitHub organizations allegedly established and maintained by DPRK IT workers as hubs for credibility building, codebase management, recruitment fronts, malware-spreading opportunities, and crypto scams. The report focuses on organizations such as m8s-lab and HyperbuildX, which are described as fake outsourcing agencies around Solana, Web3, AI, crypto trading bots, and casino or lottery dApps. It details tactics including copied code presented as original work, inflated stars and followers, job-begging on social platforms, frequent identity changes, facilitator recruitment, and coordinated boosting between accounts. The source names multiple personas, emails, GitHub profiles, social accounts, and one on-chain address, giving defenders and hiring teams concrete identity-linkage signals for DPRK IT worker screening.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN outlook.com 2018-09-06 2026-04-17
DOMAIN calendly.com 2024-10-29 2026-03-02
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
EMAIL [email protected] 2025-10-01 2025-10-01
URL https://calendly.com/nailrusty-… 2025-10-01 2025-10-01
URL https://futuresea.fun 2025-10-01 2025-10-01
URL https://www.matthiasli.com/ 2025-10-01 2025-10-01
URL https://adamglab.dev/ 2025-10-01 2025-10-01
URL https://www.mooncity.io 2025-10-01 2025-10-01
DOMAIN matthiasli.com 2025-10-01 2025-10-01
DOMAIN nailrusty.dev 2025-10-01 2025-10-01
DOMAIN adamglab.dev 2025-10-01 2025-10-01
DOMAIN hyperbuildx.com 2025-10-01 2025-10-01
DOMAIN futuresea.fun 2025-10-01 2025-10-01

Related Reports

« Back