logo

Cyber Saga: In the Footsteps of the DPRK IT Workers

ID: ffb8a294-9765-590d-842e-86b51120ea49

STIX ID: report--ffb8a294-9765-590d-842e-86b51120ea49

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2026-04-08

Date Updated: 2026-06-04

...
...

This Group-IB analysis details a persistent DPRK-linked operation that builds and deploys synthetic developer identities across GitHub, freelancing platforms, and payment services to secure remote jobs, evade sanctions, and potentially obtain insider access; the report includes persona archives (e.g., Dominic Williams, Dejan Teofilovic), AI-assisted application workflows, operational support infrastructure, IOCs (emails, GitHub accounts, portfolio domains), and practical mitigation guidance for HR, finance, and security teams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.