Pulling the Thread: Pivoting on DPRK IT Worker Infrastructure
ID: e0733ce8-4faa-52d0-b0cc-9427841c8ac3
STIX ID: report--e0733ce8-4faa-52d0-b0cc-9427841c8ac3
Feed Name: Plausible Deniablility
Date Published: 2026-04-29
Date Updated: 2026-08-11
Author: {"name"=>"", "avatar"=>"/assets/images/avatar-round.svg", "bio"=>"Cyber Threat Intelligence. Allegedly.", "links"=>[{"label"=>"Twitter", "icon"=>"fab fa-fw fa-twitter-square", "url"=>"https://twitter.com/4rchib4ld"}, {"label"=>"GitHub", "icon"=>"fab fa-fw fa-github", "url"=>"https://github.com/4rchib4ld"}, {"label"=>"LinkedIn", "icon"=>"fab fa-fw fa-linkedin", "url"=>"https://www.linkedin.com/in/axel-z-9a9a38117/"}]}
Following Team Cymru’s analysis of fake-IT-worker infrastructure around luckyguys.site, the author identified luckyguys.cloud (registered one month later with the same registrar) hosting a Gitea instance and a cluster of 18 subdomains all resolving to 45.15.167.146 (PTR rbluckyguys.com). The report lists observed IOCs, notes application artifacts referencing “RB Luckyguys Management,” and judges with moderate confidence that the infrastructure is related but possibly a separate segment; many endpoints were later unreachable, consistent with teardown after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
