Unmasking DPRK IT Workers: Email Address Patterns as Hiring Red Flags
ID: 8ff37572-daf9-5ce8-b1fe-6f1724ce41a4
STIX ID: report--8ff37572-daf9-5ce8-b1fe-6f1724ce41a4
Feed Name: THE RAVEN FILE
This report analyzes two August 2025 public leaks of ~1,389 email addresses and associated artifacts attributed to North Korean remote IT workers (Microsoft-tracked as ‘Jasper Sleet’), describing their tactic of securing remote roles in Web3/crypto firms to gain access to corporate systems; it documents domain and username patterns, overlaps with large infostealer breaches (CutOut Pro, ALIEN TXTBASE), recovered passwords, an ETH wallet, and provides detection and mitigation recommendations for employers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
