Unmasking DPRK Cyber Threat Actors: Fake IT Worker Infrastructure

2026-04-22 Team Cymru

https://www.team-cymru.com/post/dprk-fake-it-worker-cyber-threat-actors-infrastructure

Thumbnail for Unmasking DPRK Cyber Threat Actors: Fake IT Worker Infrastructure

Team Cymru examines infrastructure tied to DPRK-linked fake IT worker activity after ZachXBT connected luckyguys[.]site to related cryptocurrency payments. The domain resolved to 163.245.219[.]19, where network telemetry showed concentrated Astrill, Mullvad, and Proton VPN usage, plus residential IP activity involving Gmail, ChatGPT, and Workana. A second certificate-linked IP, 216.158.225[.]144, was also identified, and both IPs showed sharp traffic declines after public exposure. The report assesses the activity as consistent with distributed fake remote-worker or facilitator infrastructure, possible laptop-farm operations, and sanctions-evasion workflows.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 163.245.219.19 2026-04-22 2026-04-22
IPv4 216.158.225.144 2026-04-22 2026-04-22

Related Reports

« Back