Inside the Scam: North Korea’s IT Worker Threat
ID: 89d4919c-4523-5f65-a522-d7fc3b52453d
STIX ID: report--89d4919c-4523-5f65-a522-d7fc3b52453d
Feed Name: Recorded Future Blog
Executive Summary: North Korea-linked clusters PurpleBravo (TAG-120) and TAG-121 exploit remote hiring and front companies to place fraudulent IT workers into global organizations—particularly in the cryptocurrency sector—using BeaverTail infostealer, InvisibleFerret and OtterCookie backdoors to gather credentials, fingerprint systems, exfiltrate data, and maintain persistence; Insikt Group observed C2 infrastructure, Astrill VPN usage, multiple victims across countries, and recommends stronger identity verification, tighter remote-work controls, and enhanced intelligence-sharing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
