DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure
DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure
Summary
This report is a follow-up to our previous research on the internal network of DPRK IT workers. Using stealer logs, we expand our understanding of these threat actors’ internal infrastructure, much of which appears to be located in North Korea. This includes newly identified network segments, further insight into their organizational structure and new clusters within the previously documented offensive infrastructure.
This research is based on the passive analysis of publicly available data.
Infrastructure Tracking Overview
.png)
We divided the infrastructure in 3 parts
This report is divided into two parts. The first examines the public-facing infrastructure, while the second presents relevant observations on clusters identified within either the offensive ecosystem or the fake IT worker operation.
Tracking Public-Facing IP Addresses
Following our previous article on this infrastructure, we observed that actors linked to the DPRK fake IT worker cluster had changed several parts of their infrastructure. However, the infrastructure associated with Skyfreight Limited remained unchanged.
Considering all known locations and the context gathered before the infrastructure shift, we can trace an apparent path from North Korea to western Russia.

Over time, we observed that their primary targets appear to be the United States and Japan. To support their operations, they use VPNs to obtain exit nodes in these countries. DPRK IT workers use a wide range of commercial VPN services, so we used this pattern as a pivot point when analyzing stealer logs.

Astrill VPN may appeal to malicious actors because its servers are difficult for researchers to fingerprint. We therefore relied primarily on IP addresses identified by Spur and OTX to find additional profiles. Fake IT workers appear to share some exit nodes with offensive teams. Researchers can therefore use IP addresses associated with previous campaigns as pivot points in OTX to identify potential overlaps. The keyword “Lazarus” also produced useful results in this context.
Based on our observations, Mullvad is the second most commonly used VPN provider among fake IT workers. Its infrastructure is relatively easy to identify because it uses dedicated, named ranges.
We then used Hudson Rock to identify profiles matching known patterns associated with fake IT workers or North Korean operators.
One distinction between Cluster A and Cluster B is how they conceal their public IP addresses. Cluster A appears to take greater care to protect the source IP addresses of its command-and-control infrastructure. Cluster B takes the opposite approach and makes less effort to conceal them. For example, 175.45.178[.]222 has been attributed to an attacker team for more than five years, yet the team continues to reuse it, sometimes behind a single proxy and sometimes without a VPN or proxy.

As part of the C2 operations, we observed a high volume of DNS requests sent through MikroTik routers around the world.
Tracking Private IP Addresses
Following the leak published by ZachXBT (password: 123456), we identified several overlaps with our findings. Before the leak, we had identified only acronyms such as “HMB,” which we can now link to “HamBuk”; “RS,” which refers to “RedStar”; and “S.E.C.,” which refers to the Second Economy Committee. We would not have been able to resolve these terms without the leaked information. Many other terms remain unresolved. Even when teams do not use acronyms, some rely on North Korean cultural references that provide little indication of their actual purpose. The internal infrastructure suggests that multiple sectors are involved in the fake IT worker scheme.
During our infrastructure assessment, we were unable to identify a gateway until we found a stealer log belonging to a DPRK IT worker who was configuring a Huawei HiLink router. The worker accessed the router through 192.168.8[.]1 on a network used by Team 313.

As we could not observe any other configuration tasks on the other routers and never saw any other internal IPs ending in "1," we assess with low confidence that they use the first usable address (192.168.*.1/24) as a convention for their gateway addresses. Using the first usable address is a common networking convention, although some networks use the last usable address instead.
We attributed “RB” to “Ryonbong,” a sanctioned North Korean company linked to the defense sector. From an infrastructure perspective, RB appears to perform a support function by providing and collecting administrative reports from DPRK employees.
On the “RB proxy,” we identified the URL hxxp://192.168.109[.]2/call, which we linked to a WebRTC call server on the same network. The actors appear to use two methods for internal communication: this server and a separate tool called “CallPC,” which we identified across several other networks.

We also found references to “KUT” and Ryonbong in several stealer log profiles. Based on the subdomain and the contact email kut[@]star-co[.]net[.]kp, we linked KUT to Kim Chaek University of Technology.

A stealer log contained references to 13 teams, ranging from 41-KUT and 42-KUT to HQ and Ryonbong. The log did not contain the teams’ private IP addresses. We do not yet know what this structure represents. Although the teams are linked to the university, the naming convention does not appear to correspond to university classes.

In our earlier research, we assessed the offensive infrastructure described in this article. We have since added a new cluster, labeled “PUG,” although we have not determined what the acronym means. We still do not know where this infrastructure is located or what its purpose is. One user is associated with a team named “Yuhang.” Yuhang is also the name of a district in Hangzhou, but this is not a sufficiently strong indicator to support attribution at this stage.

Informational part: We noticed that a server with the following address 192.168.143[.]66 host public YouTube videos to learn English.
Sources
Hudson rock for the stealer logs
https://blog.lexfo.fr/ressources/Lexfo-WhitePaper-The_Lazarus_Constellation.pdf
https://investigation.io/dprk-itw-breach/ (password: 123456)

.avif)


.webp)



.webp)

