Threat Spotlight: Red Flags for Red Star Hackers: Hunting for North Korean Insiders
ID: b9bc97fc-8e47-5cd3-b1d4-406f2059bc13
STIX ID: report--b9bc97fc-8e47-5cd3-b1d4-406f2059bc13
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest investigated over 25 cases of North Korean insider operatives posing as freelance/contract IT workers to infiltrate Western firms, using AI-generated profiles, Astrill VPN, VPS infrastructure, IP-KVM devices and shared fixed-line IPs (laptop farms); the report details IP and device indicators, TTPs, and recommended mitigations such as COBO policies, USB allowlisting, blocking unauthorized RMM tools, and strengthened hiring and threat-hunting practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
