No items found.
July 17, 2026
·
0
Minutes Read

DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure

Threat Research
Threat Hunting
Research
July 17, 2026
·
0
Minutes Read

DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure

Threat Research
Threat Hunting
Research
July 17, 2026
·
0
Minutes Read
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

This report is a follow-up to our previous research on the internal network of DPRK IT workers. Using stealer logs, we expand our understanding of these threat actors’ internal infrastructure, much of which appears to be located in North Korea. This includes newly identified network segments, further insight into their organizational structure and new clusters within the previously documented offensive infrastructure.

This research is based on the passive analysis of publicly available data.

Infrastructure Tracking Overview

Figure 1: DPRK infrastructure

We divided the infrastructure in 3 parts

Blue = Target space
Grey = Neutral space
Red = Adversary space

This report is divided into two parts. The first examines the public-facing infrastructure, while the second presents relevant observations on clusters identified within either the offensive ecosystem or the fake IT worker operation.

Tracking Public-Facing IP Addresses

Following our previous article on this infrastructure, we observed that actors linked to the DPRK fake IT worker cluster had changed several parts of their infrastructure. However, the infrastructure associated with Skyfreight Limited remained unchanged.

IP Initial Reverse DNS or Pivoting Point Remarks
188.43.33[.]253
(Inactive)
investstroytrest-gw[.]transtelecom[.]net Changed to SevDirInfr-gw[.]transtelecom[.]net and, instead of being in Khabarovsk, this IP is now located in Moscow.

This might indicate a shift in their infrastructure.
188.43.33[.]252
(Inactive)
investstroytrest-gw[.]transtelecom[.]net Changed to SevDirInfr-gw[.]transtelecom[.]net and, instead of being in Khabarovsk, this IP is now located in Moscow.

This might indicate a shift in their infrastructure.
80.83.238[.]59 80.83.238.0/24 We observed that they use IPs belonging to the Vladivostok, Far East division of Mobile Telesystems PJSC as an exit node.
188.43.235[.]177 DZHV-gw[.]transtelecom[.]net As this is linked to a train company, it will not be changed by the DPRK ITW network team.
188.43.136[.]32
(Inactive)
  Initially located in Bodaybo, Irkutsk, and flagged because it matched a DPRK FITW time zone found in a stealer log, it is now located in Khabarovsk. This IP might have been reattributed.
188.43.136[.]34
(Inactive)
  Initially located in Moscow and flagged because it matched a DPRK FITW time zone found in a stealer log, it is now located in Khabarovsk. This IP might have been reattributed.
83.234.227[.]9
83.234.227[.]10
83.234.227[.]20
83.234.227[.]41
83.234.227[.]51
Skyfreight_Limited Remain unchanged and are used by Team 821-39, which may indicate that this unit has a presence in Russia.

Considering all known locations and the context gathered before the infrastructure shift, we can trace an apparent path from North Korea to western Russia.

Figure 2: Mapping of Russian exit nodes used by fake IT workers

Over time, we observed that their primary targets appear to be the United States and Japan. To support their operations, they use VPNs to obtain exit nodes in these countries. DPRK IT workers use a wide range of commercial VPN services, so we used this pattern as a pivot point when analyzing stealer logs.

Figure 3: Astrill exit nodes identified in stealer log screenshots

Astrill VPN may appeal to malicious actors because its servers are difficult for researchers to fingerprint. We therefore relied primarily on IP addresses identified by Spur and OTX to find additional profiles. Fake IT workers appear to share some exit nodes with offensive teams. Researchers can therefore use IP addresses associated with previous campaigns as pivot points in OTX to identify potential overlaps. The keyword “Lazarus” also produced useful results in this context.

Based on our observations, Mullvad is the second most commonly used VPN provider among fake IT workers. Its infrastructure is relatively easy to identify because it uses dedicated, named ranges.

M247 Japan Ranges
37.120.154.0/24
185.242.4.0/24

We then used Hudson Rock to identify profiles matching known patterns associated with fake IT workers or North Korean operators.

One distinction between Cluster A and Cluster B is how they conceal their public IP addresses. Cluster A appears to take greater care to protect the source IP addresses of its command-and-control infrastructure. Cluster B takes the opposite approach and makes less effort to conceal them. For example, 175.45.178[.]222 has been attributed to an attacker team for more than five years, yet the team continues to reuse it, sometimes behind a single proxy and sometimes without a VPN or proxy.

Figure 4: DPRK public-facing infrastructure

As part of the C2 operations, we observed a high volume of DNS requests sent through MikroTik routers around the world.

Tracking Private IP Addresses

Following the leak published by ZachXBT (password: 123456), we identified several overlaps with our findings. Before the leak, we had identified only acronyms such as “HMB,” which we can now link to “HamBuk”; “RS,” which refers to “RedStar”; and “S.E.C.,” which refers to the Second Economy Committee. We would not have been able to resolve these terms without the leaked information. Many other terms remain unresolved. Even when teams do not use acronyms, some rely on North Korean cultural references that provide little indication of their actual purpose. The internal infrastructure suggests that multiple sectors are involved in the fake IT worker scheme.

During our infrastructure assessment, we were unable to identify a gateway until we found a stealer log belonging to a DPRK IT worker who was configuring a Huawei HiLink router. The worker accessed the router through 192.168.8[.]1 on a network used by Team 313.

Figure 5: Team 313 network

As we could not observe any other configuration tasks on the other routers and never saw any other internal IPs ending in "1," we assess with low confidence that they use the first usable address (192.168.*.1/24) as a convention for their gateway addresses. Using the first usable address is a common networking convention, although some networks use the last usable address instead.

We attributed “RB” to “Ryonbong,” a sanctioned North Korean company linked to the defense sector. From an infrastructure perspective, RB appears to perform a support function by providing and collecting administrative reports from DPRK employees.

On the “RB proxy,” we identified the URL hxxp://192.168.109[.]2/call, which we linked to a WebRTC call server on the same network. The actors appear to use two methods for internal communication: this server and a separate tool called “CallPC,” which we identified across several other networks.

Figure 6: RB administrative network

We also found references to “KUT” and Ryonbong in several stealer log profiles. Based on the subdomain and the contact email kut[@]star-co[.]net[.]kp, we linked KUT to Kim Chaek University of Technology.

Figure 7: KUT website

A stealer log contained references to 13 teams, ranging from 41-KUT and 42-KUT to HQ and Ryonbong. The log did not contain the teams’ private IP addresses. We do not yet know what this structure represents. Although the teams are linked to the university, the naming convention does not appear to correspond to university classes.

Figure 8: Unmarked KUT network

In our earlier research, we assessed the offensive infrastructure described in this article. We have since added a new cluster, labeled “PUG,” although we have not determined what the acronym means. We still do not know where this infrastructure is located or what its purpose is. One user is associated with a team named “Yuhang.” Yuhang is also the name of a district in Hangzhou, but this is not a sufficiently strong indicator to support attribution at this stage.

Figure 9: Offensive infrastructure

Informational part: We noticed that a server with the following address 192.168.143[.]66 host public YouTube videos to learn English.

URLs from 192.168.143[.]66
http://192.168.143[.]66:1000/wp-content/uploads/english/5 things you MUST KNOW to master Professional English _ Business English.mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/C1-level Grammar and Vocabulary in 1 Hour! (Advanced Level English).mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/How to use to take _ Learn English with Lucy.mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/I say this EVERY day! Daily British English (through story!).mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/I use these phrases Every. Damn. Day... So YOU should probably learn them too! ✌🏻🇬🇧.mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/If you master this ONE word, you will speak English with EASE! _ 20-minute HAVE Masterclass.mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/Learn English - how to use to get _ EnglishWithLucy.mp4
http://192.168.143[.]66:1000/wp-content/uploads/english/Make or Do_ Learn English for FREE with Lucy!.mp4

Sources

Hudson rock for the stealer logs
https://blog.lexfo.fr/ressources/Lexfo-WhitePaper-The_Lazarus_Constellation.pdf

https://investigation.io/dprk-itw-breach/ (password: 123456)

Content

IOC’s

IP Description
175.45.178[.]222 DPRK attacker exit node
175.45.176[.]27 C2 operations
175.45.176[.]40 C2 operations
175.45.176[.]160 C2 operations
175.45.176[.]180 C2 operations
175.45.176[.]144 C2 operations
175.45.176[.]69 DPRK Fake IT worker exit node
104.253.7[.]202 Polaris Team
104.253.43[.]239 Polaris Team
104.253.75[.]110 Polaris Team
104.253.160[.]77 Polaris Team
104.253.201[.]228 Polaris Team
162.253.129[.]2 MyoHyangGyongSong team
91.239.130[.]102 Team 128-710
83.234.227[.]10 Team 821-39

Relevant Antivirus Solutions to Note

Antivirus Solution Description
360 安全卫士 Qihoo 360
电脑管家系统防护 Tencent PC Manager
Lenovo Anti-Virus powered by Huorong Security Lenovo antivirus based on Huorong
(Huorong Network Technology Co.)
金山毒霸铠甲防御 Kingsoft Antivirus
(Beijing Lingbao Intelligent Technology Co.)
Related Post