Understanding DPRK IT Worker Activity - Conversations and Insights

2025-06-24 Ketman

https://www.ketman.org/understanding-dprk-it-workers-conversations-and-insight.html

Thumbnail for Understanding DPRK IT Worker Activity - Conversations and Insights

Ketman analyzes DPRK IT worker activity across GitHub, Telegram, freelance job boards, open-source communities, and Web3 projects, where actors build fabricated developer personas to obtain work and evade sanctions controls. The investigation centers on the “Motoki Masuo” persona, linking interviews and Telegram engagement to GitHub accounts including motokimasuo, bestselection18, and kirbyAttack, as well as activity around the private AssetX-dex-frontend repository. Observed tradecraft includes persona cultivation, social-graph manipulation, repository activity used for credibility and reconnaissance, KYC and interview evasion, and proxy or remote-access infrastructure. Video-interview mistakes exposed identity artifacts including [email protected] and [email protected], while language and behavioral inconsistencies undermined the claimed Japanese identity. The report matters for DPRK-focused tracking because it shows how GitHub and freelance ecosystems can support both revenue generation and operational coordination by sanctioned IT workers.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN calendly.com 2024-10-29 2026-03-02
URL https://calendly.com/7codewizar… 2025-06-24 2025-12-04
EMAIL [email protected] 2025-06-24 2025-06-24
EMAIL [email protected] 2025-06-24 2025-06-24
URL https://calendly.com/davidcolma… 2025-06-24 2025-06-24
EMAIL [email protected] 2025-04-16 2025-06-24

Related Reports

« Back