logo

Threat Spotlight: Red Flags for Red Star Hackers: Hunting for North Korean Insiders

ID: b9bc97fc-8e47-5cd3-b1d4-406f2059bc13

STIX ID: report--b9bc97fc-8e47-5cd3-b1d4-406f2059bc13

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2025-05-08

Date Updated: 2026-04-29

...
...

ReliaQuest investigated over 25 cases of North Korean insider operatives posing as freelance/contract IT workers to infiltrate Western firms, using AI-generated profiles, Astrill VPN, VPS infrastructure, IP-KVM devices and shared fixed-line IPs (laptop farms); the report details IP and device indicators, TTPs, and recommended mitigations such as COBO policies, USB allowlisting, blocking unauthorized RMM tools, and strengthened hiring and threat-hunting practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.