Unmasking DPRK Cyber Threat Actors: Fake IT Worker Infrastructure
2026-04-22 • Team Cymru •
https://www.team-cymru.com/post/dprk-fake-it-worker-cyber-threat-actors-infrastructure
Team Cymru examines infrastructure tied to DPRK-linked fake IT worker activity after ZachXBT connected luckyguys[.]site to related cryptocurrency payments. The domain resolved to 163.245.219[.]19, where network telemetry showed concentrated Astrill, Mullvad, and Proton VPN usage, plus residential IP activity involving Gmail, ChatGPT, and Workana. A second certificate-linked IP, 216.158.225[.]144, was also identified, and both IPs showed sharp traffic declines after public exposure. The report assesses the activity as consistent with distributed fake remote-worker or facilitator infrastructure, possible laptop-farm operations, and sanctions-evasion workflows.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 163.245.219.19 | 2026-04-22 | 2026-04-22 |
| IPv4 | 216.158.225.144 | 2026-04-22 | 2026-04-22 |