logo

Inside the Scam: North Korea’s IT Worker Threat

ID: 89d4919c-4523-5f65-a522-d7fc3b52453d

STIX ID: report--89d4919c-4523-5f65-a522-d7fc3b52453d

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-02-13

Date Updated: 2026-04-28

...
...

Executive Summary: North Korea-linked clusters PurpleBravo (TAG-120) and TAG-121 exploit remote hiring and front companies to place fraudulent IT workers into global organizations—particularly in the cryptocurrency sector—using BeaverTail infostealer, InvisibleFerret and OtterCookie backdoors to gather credentials, fingerprint systems, exfiltrate data, and maintain persistence; Insikt Group observed C2 infrastructure, Astrill VPN usage, multiple victims across countries, and recommends stronger identity verification, tighter remote-work controls, and enhanced intelligence-sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.