DPRK IT WORKERS UNVEILED
ID: 8afa71eb-9db5-5254-9c77-72af5422c4a3
STIX ID: report--8afa71eb-9db5-5254-9c77-72af5422c4a3
Feed Name: THE RAVEN FILE
This research profiles suspected DPRK IT workers who create fake identities and public developer/resume profiles (GitHub, CodeSandbox, freelancing sites) and use deepfakes, proxying, and recruitment campaigns to secure remote work and conduct malicious operations; it compiles suspected account URLs, resume links, observed pitches/queries, and links the activity to DPRK entities (Department 53) and Lazarus-related campaigns, citing major incidents including Operation Dream Job and the Bybit ~$1.4–1.5B crypto heist while noting geopolitical ties to Russia and China.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
