NEWS From "Hello, I'm your new analyst" to "oh, where's my crypt?". Anatomy of the internal system of hackers of the DPRK

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,793
The DPRK has learned to penetrate into corporate networks without a single hack.
1779787175614.png
North Korea is no longer operating online as a set of scattered hacker groups. According to Krypt3ia, the cyber operations of the DPRK have turned into a connected system where they use fake employees, attack developers, steal cryptocurrency and spy, working for one common goal: they extract money, circumvent sanctions and get access to other people’s data.

Experts believe that the usual labels for groups are worse and worse described the real picture. Operations that used to look like individual campaigns now often use the same servers, accounts, tools, fake personalities, and ways to log in to corporate networks.

One of the main directions was schemes with fictitious remote employees. North Korean experts use stolen documents, fictional biographies, intermediaries, virtual private networks and so-called laptop farms to get a job in foreign companies under the guise of ordinary workers or contractors. After employment, attackers get legal access to internal systems, mail, cloud services and work processes.

Such access is more difficult to notice than conventional malicious software. For protective systems, the employee looks legitimate, enters the network in the usual way and uses corporate tools. As a result, the DPRK receives a long-term presence within companies without noisy hacks.

In parallel, North Korean hackers are actively attacking developers through fake vacancies and technical interviews. The victims are offered to pass a test task, download a repository or start a project to test skills. Within such projects, malicious addictions, scripts and settings that infect the developer’s computer can hide.

The value of such attacks is not limited to one infected device. Developers often have access to source code, cloud environments, assembly systems, tokens, internal chat rooms and accounts. Through one specialist, attackers can enter the company’s infrastructure, the supply chain or cryptocurrency services.

North Korean hackers continue to steal cryptocurrency, but the approach has become more difficult. Attackers are becoming less and less likely to start with a direct hack of the exchange or wallet. First, they collect credentials, are fixed in cloud services, use access to fictitious employees and compromise developers. By the time of theft, operators already have an understanding of internal processes, access rights and means of protection of the victim.

After embezzlement, the funds are quickly crushed, transferred between wallets, networks and exchange services. Decentralized financial services, mixers and multi-step translation schemes are used to hide the traces. This speed prevents the blocking of assets and complicates the investigation.

Krypt3ia also points to an increase in abuse of trusted platforms. Instead of a prominent infrastructure for malware management, North Korean operators are increasingly using GitHub, cloud services, collaboration platforms, remote administration tools, and software repositories. Such traffic is more easily mixed with normal corporate activity.

As a result, the DPRK is not building separate campaigns, but a stable cyber system, where every successful access can be reused. A fake recruit can lead to developer infection, developer infection can open the way to the cloud, the cloud can help steal cryptocurrency or collect intelligence. This model makes the operations flexible, survivable and difficult to accurately attribute to a particular group.

The main conclusion of the report is that North Korea has learned to use trust as a weapon. Confidence in remote employees, developers, cloud platforms, open repositories and familiar services has become part of an attacking strategy. For companies, this means that the protection can no longer be limited to searching for malicious files. You need to check people, accounts, access rights, cloud environments and development chains.
 
6,811Threads
90,697Messages
6,195Members
THE DUSK COUNCILLatest member
Top Bottom