Unmasking a new DPRK Front Company DredSoftLabs
2025-11-29 • Wickeren •
https://medium.com/@meeswicky1100/unmasking-a-new-dprk-front-company-dredsoftlabs-bf9ed544d690
The researcher attributes DredSoftLabs to WageMole, a DPRK state-sponsored remote-employment operation that uses fake identities, social engineering, job platforms, and stolen personal data to pursue Western remote work. A GitHub search pivot on an encoded api-server-mocha[.]vercel[.]app value exposed 77 active malicious repositories that the author says can lead to OtterCookie or BeaverTail infection when run. The report ties DredSoftLabs to malicious GitHub commits, victim reporting, suspicious web and social presence, and recruitment lures matching established WageMole tradecraft. The findings give defenders a repeatable fingerprint for hunting fraudulent DPRK developer-recruitment infrastructure and malicious coding-test repositories.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ca184ac5f2e659ee65272911f6b0795… | 2025-11-29 | 2025-11-29 |
| URL | https://api-server-mocha.vercel… | 2025-11-29 | 2025-11-29 |
| URL | https://api-server-mocha.vercel… | 2025-11-29 | 2025-11-29 |
| URL | https://api-server-mocha.vercel… | 2025-11-29 | 2025-11-29 |
| DOMAIN | carlosss91.github.io | 2025-11-29 | 2025-11-29 |
| DOMAIN | dredsoftlabs.com | 2025-11-29 | 2025-11-29 |