Unmasking a new DPRK Front Company DredSoftLabs

2025-11-29 Wickeren

https://medium.com/@meeswicky1100/unmasking-a-new-dprk-front-company-dredsoftlabs-bf9ed544d690

Thumbnail for Unmasking a new DPRK Front Company DredSoftLabs

The researcher attributes DredSoftLabs to WageMole, a DPRK state-sponsored remote-employment operation that uses fake identities, social engineering, job platforms, and stolen personal data to pursue Western remote work. A GitHub search pivot on an encoded api-server-mocha[.]vercel[.]app value exposed 77 active malicious repositories that the author says can lead to OtterCookie or BeaverTail infection when run. The report ties DredSoftLabs to malicious GitHub commits, victim reporting, suspicious web and social presence, and recruitment lures matching established WageMole tradecraft. The findings give defenders a repeatable fingerprint for hunting fraudulent DPRK developer-recruitment infrastructure and malicious coding-test repositories.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ca184ac5f2e659ee65272911f6b0795… 2025-11-29 2025-11-29
URL https://api-server-mocha.vercel… 2025-11-29 2025-11-29
URL https://api-server-mocha.vercel… 2025-11-29 2025-11-29
URL https://api-server-mocha.vercel… 2025-11-29 2025-11-29
DOMAIN carlosss91.github.io 2025-11-29 2025-11-29
DOMAIN dredsoftlabs.com 2025-11-29 2025-11-29

Related Actors

Related Reports

« Back