logo

DPRK IT WORKERS UNVEILED

ID: 8afa71eb-9db5-5254-9c77-72af5422c4a3

STIX ID: report--8afa71eb-9db5-5254-9c77-72af5422c4a3

Feed Name: THE RAVEN FILE

Threat Score
87/100

Date Published: 2025-08-28

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

This research profiles suspected DPRK IT workers who create fake identities and public developer/resume profiles (GitHub, CodeSandbox, freelancing sites) and use deepfakes, proxying, and recruitment campaigns to secure remote work and conduct malicious operations; it compiles suspected account URLs, resume links, observed pitches/queries, and links the activity to DPRK entities (Department 53) and Lazarus-related campaigns, citing major incidents including Operation Dream Job and the Bybit ~$1.4–1.5B crypto heist while noting geopolitical ties to Russia and China.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.