logo

Misconfigured cloud server leaked clues of North Korean animation scam

ID: 003b948b-6725-5074-89af-9bfb5e270e3a

STIX ID: report--003b948b-6725-5074-89af-9bfb5e270e3a

Feed Name: The Register (Security)

Date Published: 2024-04-23

Date Updated: 2026-04-26

Author: Laura Dobberstein

...
...

A misconfigured cloud server tied to a North Korean IP exposed daily animation work artifacts that investigators from Stimson Center/38 North and Mandiant assessed as evidence of covert outsourcing to DPRK animators, likely linked to the sanctioned April 26 Animation Studio (SEK). Access logs showed predominant VPN use, with some logins from China and Spain, and files tied to projects from major studios (e.g., Amazon’s Invincible, HBO Max/Cartoon Network’s Iyanu, and BBC’s Octonauts), though there’s no indication the studios knew of the subcontracting. The findings suggest broader DPRK revenue-generation via disguised IT/creative work using relay servers, aligning with past advisories on North Korean illicit outsourcing practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.