Infected by GTA 5 Cheats: How an Infostealer Infection Unmasked a North Korean Agent
ID: 850b4b52-b31d-5f7b-be89-b2080e9f3450
STIX ID: report--850b4b52-b31d-5f7b-be89-b2080e9f3450
Feed Name: infostealers.com
Threat Score
This report describes how a LummaC2 infostealer infection on a machine operated under an Indonesian front exposed a suspected North Korean (‘fake IT worker’) campaign: stolen CDN credentials, administrative access to scam panels, multiple segregated crypto wallets (one with ~$65k), tooling for deepfakes and identity synthesis, and detailed search/history artifacts that map an industrial-scale fraud operation and proxy “IP seasoning” tradecraft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
