logo

How LevelBlue OTX and Cybereason XDR Detected a North Korea-Linked Remote IT Worker

ID: afd72c53-9ddb-5ea4-bfee-ae5f6de2f559

STIX ID: report--afd72c53-9ddb-5ea4-bfee-ae5f6de2f559

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
68/100

Date Published: 2026-03-17

Date Updated: 2026-04-28

Author: Tue Luu

...
...

**Executive Summary:** SpiderLabs detected and blocked a suspected North Korea-linked infiltration in which an attacker obtained employment and accessed corporate resources using EntraID logins routed through Astrill VPN exit nodes; LevelBlue OTX threat intelligence correlated with Cybereason XDR behavioral analytics to flag anomalous geographic and unmanaged-device logins, leading to account revocation within ten days and no evidence of residual access or data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.