No items found.
August 12, 2026
·
0
Minutes Read

Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware

Threat Research
Threat Hunting
Research
August 12, 2026
·
0
Minutes Read

Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware

Threat Research
Threat Hunting
Research
August 12, 2026
·
0
Minutes Read
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Understanding the DPRK Cybercrime Ecosystem

Following a recent assessment of multiple events linked to North Korea, we wanted to bring our findings together in one place. This article examines three investigations into past events that were not attributed to the DPRK, as well as legitimate structures being used for illegitimate activities.

The compromise of partners or employers is not new, and DPRK IT workers have used this approach even within the cybercrime sector, as the first investigation into FakeCalls shows. This is why, as an analyst, I do not draw a hard line between cybercrime and state actors: the two can work together, while cybercrime groups can also be infiltrated, influenced or redirected by a state.

This research is based on passive analysis of publicly available data.

Linking the FakeCalls Trojan to DPRK-Linked Gambling Operations

We recently observed a stealer log leak involving an actor linked to the DPRK, nicknamed “Bismarck.” The actor used two IP addresses that overlap with indicators of compromise (IOCs) documented by Check Point Research in its analysis of FakeCalls, an Android banking trojan targeting South Korea. Because we had already clustered this threat actor and linked him to the North Korean fake IT worker environment, we assess that these attacks are likely attributable to the DPRK.

This actor's data leaked on December 22, 2023, and the article from Check Point Research was published on March 14, 2023, which fall within a similar timeframe.

Collected IPs that overlap with the FakeCalls Trojan Context
182.16.42[.]18:20001
182.16.42[.]18:20001/powerpoker/
Username: 본사 / HQ?
188.114.97[.]3 This IP has been found in an autofill without any context with this one 82.118.29[.]239 and belongs to “Express VPN” and has been likely used with an account with this mail account expressvpn2021-3@outlook[.]com

Compared with other actors linked to the DPRK, this actor consumed a high volume of North Korean state-owned news, including DPRKdaily, uriminzokkiri and kcnawatch. He was also observed administering multiple gambling-related websites (see Annex 1) that may have been used to launder money. We found autofill fields containing 코인거래 주의사항, meaning “Cryptocurrency Trading Precautions,” as well as operational chats between some of “Bismarck's” associates.

The associates appear to have been suspicious of “Bismarck.” After these messages, one associate wanted to formalize the relationship with a contract and appeared aware of the risks involved. The circumstances of their initial contact remain unclear.

Associate A: "I will. But bro Tell me, I hope that won't put me in troubles. I have some Bank accounts and won't that affect that. If anything related to the business"

Associate A: "If you use the site for money laundering, I will go to jail 🤣"

Associate A: “I should pay you to learn me the technical matters🤣”

They can also modify the “RTP” (Return to Player) rate, the theoretical percentage of money wagered that is returned to players. In this case, they claim that it can be modified at any time.

Associate A:” Are you able to copy a casino system if I give you the front and back?”

Unknown Associate: No, the ones that I have are also copies.

Associate A: Stake[.]com has 44 exclusive Pragmatic games. If I ask you to copy them, can you do that?

Bismarck: "RTP adjustable per game"

Bismarck: "Manager can directly award winnings using RTP call"


Unknown Associate: “Work retail. Manually. Via PC. In Russia mostly and a bit CIS”

Unknown Associate:” Speaking to a friend from Russia”


Associate A: “The one I introduced from Turkey”

Associate A:” Not sure if Domenico will be happy to hear that I am working with you lol”

Our reconstruction and sequencing may be imperfect, but the evidence suggests that the actors organized themselves across multiple countries to establish several gambling businesses. The casinos do not appear to be properly regulated, and the games are copies of legitimate titles from other publishers. Research into gitslotpark[.]com (see Annex 1) identified a lawsuit filed in Virginia, United States, by Pragmatic Play concerning copies of its games. This also aligns with chat excerpts identified through Google Translate.

Figure 1: Court lawsuit

The lawsuit also contained the name “E. Vasilyevich,” which overlaps with a name found in Bismarck's autofill data.

We assess that DPRK actors may have reused IP addresses from the gambling operation because the domains were purchased by the associates rather than by “Bismarck” or other North Korean operatives. We believe that a team operated behind "Bismarck" during the operation, given the size of the infrastructure, as we understand that "Bismarck" was the system administrator and developer for this operation.

Based on the IPs found in the metadata of "Bismarck's" session cookies, we were able to see that he established connections from a mobile ISP in Moscow, Russia, which may indicate that he conducted his operations from Moscow.

IP Enrichment
213.87.149[.]35 Location: Moscow, Moscow
Country: Russia
ASN: AS8359 MTS PJSC
213.87.90[.]110 Location: Moscow, Moscow
Country: Russia
ASN: AS8359 MTS PJSC
213.87.144[.]144 Location: Moscow, Moscow
Country: Russia
ASN: AS8359 MTS PJSC

The metadata comes mainly from DPRKtoday, a North Korean news website widely used by overseas workers. It also serves as a pivot point that we use to track threat actors laterally through stealer log data.

Figure 2: Metadata session cookies DPRKtoday

DPRK Fake IT Workers and Emotet Botnet Activity

We assessed a DPRK-related actor, identified in a stealer log, who appeared to work as a manager. Two IP addresses stored in his password vault were associated with the delivery of Emotet, modular malware first observed in 2014. Emotet began as a banking trojan before evolving into a loader used to deliver other payloads. We assess with moderate confidence that the manager used the two IPs listed below to deploy Emotet.

IP Context
160.16.143[.]191:10022
160.16.143[.]191:22
Following the IOC list https://github.com/vmware-samples/tau-research/blob/emotet-report/2022-H2-Emotet-Resurrection/ioc_c2_config.csv
we can note this line who contains our IOC
IP address Port Epoch JARM fingerprint AS number First seen
160.16.143[.]191 7080 5   9370 2022-05-20 21:00:41 UTC
160.16.218[.]63 For this one we don’t have much context, just an IP and a port from this source: https://github.com/pr0xylife/Emotet/blob/main/e4_emotet_18.03.2022.txt

The credentials were stolen from the manager's WinSCP vault in 2021. Cross-referencing the history of 160.16.143[.]191, this IP began being used as a loader in early 2022, according to VirusTotal history.

Figure 3: Unknown Fake IT worker cell from 2021

One notable aspect of this profile is that the entire system is in Japanese. This is not the first time we have observed this pattern. Based on his notes, which were written partly in Japanese and partly in Korean, this cell appears to have targeted Japan exclusively. The notes described missions carried out by the team in 2021.

Figure 4: “RUR” computer screenshot

Given the UTC+8 time zone, we assess that he could be located in North Korea.

North Korean Universities and DPRK Fake IT Worker Operations

During our research, we identified multiple universities connected to the fake IT worker operation. The most significant in our assessment were Kim Chaek University of Technology, Jinung Institute of IT Development at Kim Il Sung University, and PYITC, which we attribute with medium confidence to the Pyongyang Information Technology Center.

These were often North Korean universities. In the cases we assessed, the activity appeared to involve fake IT workers operating from within these institutions rather than students. We observed a naming convention of <university acronym>-<number>, with numbering beginning at 001. Using this convention, we ran a bulk lookup on Hudson Rock from <university acronym>-001 to <university acronym>-999, which provided additional context on activity within these institutions.

For the building reconstruction/GEOINT analysis, we are unsure whether the machine naming convention refers to a base or to a named physical location. For this analysis, we assumed that it referred to a named location.

1. Kim Chaek University of Technology and DPRK Fake IT Worker Activity

Figure 5: Kim Chaek University of Technology - Ryonbong; building assessment (Low confidence)

With low confidence, we reconstructed a small part of Kim Chaek University of Technology using the naming convention found on computers within the assessed cluster. These machines were marked internally as “units” and used tags such as “4-2-205,” which could refer to “Building/Floor/Room.” We see this pattern frequently in stealer logs and assess that these machines are likely not portable. Across different units, only the first digit changed, leading us to assess that it may identify the building. Our goal was to cross-reference these identifiers with satellite imagery to determine whether they reveal additional capabilities. The methodology is outlined below.

GEOINT attributes Objective
Marked internally as Building 1
// Marked by a purple pin
A building within the campus of Kim Chaek University of technology that has minimum 8 floors
Marked internally as Building 2
// Green area
A building within the campus of Kim Chaek University of technology that has minimum 4 floors
Marked internally as Building 4
// Green area
A building within the campus of Kim Chaek University of Technology that has minimum 2 floors
Not sure if this is a part of the KUT campus
// Blue area and a blue pin
Buildings that are linked to a university

To do this, we can count the windows to estimate the number of floors and exclude buildings with fewer than two floors, narrowing the possible locations. We were unsure whether the area marked in blue formed part of the campus.

Figure 6: Kim Chaek University of technology (KUT) campus [Low confidence]

Based on the data observed, the most frequently represented fake IT worker teams from this university were 41/42/43 KUT and several sub-teams. We understand the hierarchy to be: KUT → Department → Team.

We found limited information on their network infrastructure, but assess that they are probably using the 192.168.142.XXX/24 subnet.

2. Jinung Institute of IT Development and DPRK Fake IT Worker Activity

The Jinung Institute of IT Development appears to be less well documented than the other universities. However, the Kim Il Sung University website briefly references the institute and its activities as a university unit.

Figure 7: Kim Il Sung University, Jinung documentation

We initially clustered a group of IT workers using the naming pattern UnivJN-<number>. One individual stated that he was from “Jinung” and part of a team named JN+<number>. The teams identified as JN1 and JN2 appear to consist mainly of developers.

To identify the exact site, we referred to a 38 North article that identified “Jinung solar panel manufacturing.” Assuming the units are grouped together, we examined the area around that facility using “3-4-XX” as a reference.

GEOINT attributes Objective
Marked internally as “Building 3”
// Probable area marked in Green
A building within the campus of Kim Il Sung University close to “Jinung Solar Panel Manufacturing Company” that have 4 floors minimum
Figure 8: Jinung Institute of IT Development (Kim Il Sung University) [Low confidence]

One assessed profile used a 10-character password resembling a Chinese student ID. We do not know whether they adopted the same naming convention as Chinese universities, although it is plausible.

3. PYITC and DPRK Fake IT Worker Infrastructure

We are unsure whether PYITC refers to the Pyongyang Information Technology Center, as the acronym appears only within the IT worker teams we assessed. However, we can say with high confidence that the entity is linked to a North Korean university because we observed the same patterns documented in the previous cases. The infrastructure we reconstructed makes extensive use of an HFS solution, probably Rejetto, across PYITC teams (see Annex 2), with “Student Management” appearing as a title.

We observed a pattern in fake IT worker usernames consisting of three digits in the format “3-X-X.” This appears more likely to be an organizational or military naming convention than a building identifier and differs from the machine-name patterns assessed earlier.

Network assessed Analyst note
192.168.147.XXX/24 http://192.168.147.8/#/app/dashboard
| Student Management
192.168.127.XXX/24 http://192.168.127.8/#/app/dashboard
| Student Management

Across both networks, we observed the same dashboard name on hosts ending in “.8,” which may reflect an internal convention used by this entity.

The role of students remains unclear. We observed indications that students may participate in the fake IT worker operation, and this is the first time we have encountered the term “student” rather than “units.”

Inside the DPRK Fake IT Worker “Base” System

By cross-referencing sources including stealer logs and the ZachXBT leak, we developed the following understanding of the “Base” system's structure.

Five known bases have been identified, although their locations are not publicly known. A “base” is described as a location where workers can access the internet. Connectivity is provided in two ways: a wired fiber-optic connection, which is stable but slow, or what they call “Wi-Fi,” which is actually a router with a SIM card using the cellular network. The latter is faster but less stable and can support three to five people at a time.

A dedicated support team handles requests for new routers and other technical issues. Workers can move between bases depending on decisions made by the “base boss” and the individual team member. However, they are not required to work from these bases; some companies and universities in North Korea already have internet access.

Figure 9: Fake IT workers structure [High confidence]

Turn Threat Intelligence Into Action

Understanding how cybercrime and state-linked activity intersect is critical to staying ahead of emerging threats. Kudelski Security can help you understand the threats facing your organization and turn intelligence into meaningful action. Contact our team for more information.

Sources and Research References

Hudson rock for the stealer logs

// FakeCalls, Casino part

https://research.checkpoint.com/2023/south-korean-android-banking-menace-fakecalls/

// Emotet part

https://web.archive.org/web/20221011061425/https://www.vmware.com/content/dam/learn/en/amer/fy23/pdf/1669005_Emotet_Exposed_A_Look_Inside_the_Cybercriminal_Supply_Chain.pdf

https://github.com/pr0xylife/Emotet/blob/main/e4_emotet_18.03.2022.txt

https://github.com/vmware-samples/tau-research/blob/emotet-report/2022-H2-Emotet-Resurrection/ioc_c2_config.csv

// Jinung Institute of IT Development (Kim Il Sung university)

https://www.38north.org/2023/03/north-koreas-energy-sector-state-solar-electricity-research-and-manufacturing/

// Base

https://investigation.io/dprk-itw-breach/ password:123456

The translation from Korean to English has been made by AI

ANNEX

ANNEX 1 – Gambling administration Link

Link Context Activity during the analysis
backoffice[.]honorlink[.]org
obdb[.]honorlink[.]org
Platform that provides casino API and white-label Casino solutions UP
zeu-000[.]com The DPRK linked actor had access to the following endpoint / CustomerList DOWN
admin[.]moo-gadang[.]com DOWN
185[.]254[.]241[.]135:8081 TITLE: 회원 관리 | Admin - Online Gaming
Member management
TITLE: 대시 보드 | Admin - Online Gaming
Dashboard
Logins: Admin / devuser004
DOWN
prd-sdv2-api[.]slotsdiamond[.]com Gambling related website UP
app-b[.]insvr[.]com Online gaming and betting application DOWN
adminv2[.]gitslotpark[.]com Login | Admin - Online Gaming DOWN
admin[.]loginxcasino[.]com Dashboard | Admin - Online Gaming DOWN

ANNEX 2 – PYITC network

PYITC internal IP Shared link
192.168.127[.]8 http://192.168.127[.]8/#/app/dashboard | Student Management
192.168.127[.]27 http://192.168.127[.]27:8167/bol/5 month Daily Report and Scores_v2.0(2023.5.14-2023.5.).xlsx
192.168.127[.]31 http://192.168.127[.]31:8167/4rr/abbreviations on messaging.docx
192.168.127[.]54 http://192.168.127[.]54:8167/b91/3-7-27-example.xlsx
http://192.168.127[.]54:8167/80n/5-2_v1.0(2023.5.5-2023.5.13).xlsx
http://192.168.127[.]54:8167/9yu/reference.xlsx
192.168.127[.]56 http://192.168.127[.]56:8167/8cf/_07ResumeSample.rar
192.168.127[.]60 http://192.168.127[.]60:8167/f0l/New Microsoft Excel Worksheet.xlsx
http://192.168.127[.]60:8167/omq/5-3(2023.5.14-2023.5.21).xlsx
http://192.168.127[.]60:8167/845/5-4(2023.5.23-2023.5.28).xlsx
http://192.168.127[.]60:8167/kb9/May Report_v1.0(2023.5.31).xlsx
192.168.127[.]62 http://192.168.127[.]62:8167/che/Daily Report Form.xlsx
192.168.127[.]66 http://192.168.127[.]66:8167/cyo/new_resume_Jhon.docx
http://192.168.127[.]66:8167/j4f/2_6_Michael%20John.png
http://192.168.127[.]66:8167/hcq/Bids.docx
http://192.168.127[.]66:8167/jd9/lingoes.rar
http://192.168.127[.]66:8167/euw/2-6-3.png
http://192.168.127[.]66:8167/3t8/2-6-3.png
http://192.168.127[.]66:8167/wo/2-6-3.png
http://192.168.127[.]66:8167/kml/Screenshot%202023-05-03%20003344.png
http://192.168.127[.]66:8167/8ye/Screenshot%202023-05-04%20010847.png
http://192.168.127[.]66:8167/kst/Screenshot%202023-05-05%20001208.png
http://192.168.127[.]66:8167/c7i/Screenshot%202023-05-06%20001249.png
192.168.127[.]69 http://192.168.127[.]69:8167/krc/websites.xlsx
192.168.127[.]75 http://192.168.127[.]75:8167/opd/manage-upwork-accounts.rar

ANNEX 3 – Bonus – North Korean word list found in an autofill

Translated with AI

Korean English
3대혁명 Three Revolutions
간직하자 Let us cherish
건설혁명 Construction revolution
경제조직 Economic organization
계절 Season
공산주의 Communism
광명한 Bright
구상 Concept/Plan
구상과 념원 Concept and aspiration
국기 National flag
국내 Domestic
국장 National emblem
김치 Kimchi
념원 Aspiration
농업 Agriculture
농촌 Countryside
농촌문제 Rural issue
농촌발전 Rural development
당면한 Pressing/Immediate
당을 The Party (obj.)
당의 The Party's
동지애 Comradeship
련포온실 Ryonpho greenhouse
문명발전 Cultural development
미풍 Fine custom
반일 Anti-Japanese
보도 Report/News
사랑 Love
사상공세 Ideological offensive
사상교양 Ideological education
사상교양사업 Ideological education work
사상사업 Ideological work
사회 Society
사회주의 Socialism
수령관 View of the leader
실력 Ability/Competence
애국가 National anthem
요람 Cradle
우월성 Superiority
인민군창건 Founding of the People's Army
일군들 Officials/Cadres
일군들은 Officials/Cadres (topic)
전쟁 War
조국해방전쟁 Fatherland Liberation War
조중친선 DPRK–China friendship
조충친선 DPRK–China friendship (variant)
주체의 Juche's
초급당비서 Primary Party secretary
충복 Loyal servant
충실성 Loyalty/Fidelity
통일단결 Unity and cohesion
필승불패 Ever-victorious/Invincible
하자고 Let us do
행복의 요람 Cradle of happiness
혁명성 Revolutionary spirit
혁명승리 Revolutionary victory
혁명적 수령관 Revolutionary view of the leader
현시기 Present period
화성지구 Hwasong district
가극 Opera
결심 Determination
3대혁명소조 Three Revolutions Team
농업생산 Agricultural production
당생활총화 Party life review
대외사업 External affairs work
련포 Ryonpho
반제계급의식 Anti-imperialist class consciousness
백두산지구 Mt. Paektu district
법무생활 Legal life/conduct
사회주의교양 Socialist education
인민 People
인민들 People (pl.)
초급당 Primary Party
Related Post