Understanding DPRK IT Worker Activity - Conversations and Insights
2025-06-24 • Ketman •
https://www.ketman.org/understanding-dprk-it-workers-conversations-and-insight.html
Ketman analyzes DPRK IT worker activity across GitHub, Telegram, freelance job boards, open-source communities, and Web3 projects, where actors build fabricated developer personas to obtain work and evade sanctions controls. The investigation centers on the “Motoki Masuo” persona, linking interviews and Telegram engagement to GitHub accounts including motokimasuo, bestselection18, and kirbyAttack, as well as activity around the private AssetX-dex-frontend repository. Observed tradecraft includes persona cultivation, social-graph manipulation, repository activity used for credibility and reconnaissance, KYC and interview evasion, and proxy or remote-access infrastructure. Video-interview mistakes exposed identity artifacts including [email protected] and [email protected], while language and behavioral inconsistencies undermined the claimed Japanese identity. The report matters for DPRK-focused tracking because it shows how GitHub and freelance ecosystems can support both revenue generation and operational coordination by sanctioned IT workers.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | calendly.com | 2024-10-29 | 2026-03-02 |
| URL | https://calendly.com/7codewizar… | 2025-06-24 | 2025-12-04 |
| [email protected] | 2025-06-24 | 2025-06-24 | |
| [email protected] | 2025-06-24 | 2025-06-24 | |
| URL | https://calendly.com/davidcolma… | 2025-06-24 | 2025-06-24 |
| [email protected] | 2025-04-16 | 2025-06-24 |