North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs
ID: b3b8320a-c317-5cb0-8e5e-9144d06c64f7
STIX ID: report--b3b8320a-c317-5cb0-8e5e-9144d06c64f7
Feed Name: ANY.RUN's Cybersecurity Blog
Threat Score
## Executive summary: This report exposes a sophisticated DPRK-operated remote worker scheme—attributed to Lazarus/Famous Chollima—that obtains legitimate employment via forged identities and AI-assisted personas to gain persistent access to corporate and government systems; it documents recruitment tactics, malware used, network evasions, mule/payment infrastructure, and provides IOCs and SOC detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
