logo

Unmasking DPRK IT Workers: Email Address Patterns as Hiring Red Flags

ID: 8ff37572-daf9-5ce8-b1fe-6f1724ce41a4

STIX ID: report--8ff37572-daf9-5ce8-b1fe-6f1724ce41a4

Feed Name: THE RAVEN FILE

Threat Score
78/100

Date Published: 2025-08-19

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

This report analyzes two August 2025 public leaks of ~1,389 email addresses and associated artifacts attributed to North Korean remote IT workers (Microsoft-tracked as ‘Jasper Sleet’), describing their tactic of securing remote roles in Web3/crypto firms to gain access to corporate systems; it documents domain and username patterns, overlaps with large infostealer breaches (CutOut Pro, ALIEN TXTBASE), recovered passwords, an ETH wallet, and provides detection and mitigation recommendations for employers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.