"Taro" is part of a cell I've been calling "215"
2026-04-17 • meowmfer •
A thread links the fake identity "Taro Aikuchi" to a DPRK IT worker cluster labeled "215" through repeated numeric markers across GitHub handles, email addresses, commit metadata, and aliases. The excerpt connects 0xbomb215, xsen215, highgoal215, and related emails using Git history, shared social graphs, deleted accounts, and a database of confirmed DPRK-linked accounts. Reported tradecraft includes multiple fake national identities, applicant emails with recurring suffixes, GitHub follow networks used for social proof, and rotation across developer personas. The cluster is framed as part of a larger DPRK IT worker ecosystem operating at scale across crypto and software projects, with IOCs including GitHub accounts, emails, Telegram identifiers, a phone number, a VPN IP, and a LinkedIn profile.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2026-04-17 | 2026-04-17 | |
| [email protected] | 2026-04-17 | 2026-04-17 | |
| [email protected] | 2026-04-17 | 2026-04-17 | |
| [email protected] | 2026-04-17 | 2026-04-17 | |
| [email protected] | 2026-04-17 | 2026-04-17 | |
| [email protected] | 2026-04-15 | 2026-04-17 | |
| [email protected] | 2026-04-15 | 2026-04-17 | |
| IPv4 | 51.195.140.214 | 2025-01-26 | 2026-04-17 |
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |