Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware
Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware
Understanding the DPRK Cybercrime Ecosystem
Following a recent assessment of multiple events linked to North Korea, we wanted to bring our findings together in one place. This article examines three investigations into past events that were not attributed to the DPRK, as well as legitimate structures being used for illegitimate activities.
The compromise of partners or employers is not new, and DPRK IT workers have used this approach even within the cybercrime sector, as the first investigation into FakeCalls shows. This is why, as an analyst, I do not draw a hard line between cybercrime and state actors: the two can work together, while cybercrime groups can also be infiltrated, influenced or redirected by a state.
This research is based on passive analysis of publicly available data.
Linking the FakeCalls Trojan to DPRK-Linked Gambling Operations
We recently observed a stealer log leak involving an actor linked to the DPRK, nicknamed “Bismarck.” The actor used two IP addresses that overlap with indicators of compromise (IOCs) documented by Check Point Research in its analysis of FakeCalls, an Android banking trojan targeting South Korea. Because we had already clustered this threat actor and linked him to the North Korean fake IT worker environment, we assess that these attacks are likely attributable to the DPRK.
This actor's data leaked on December 22, 2023, and the article from Check Point Research was published on March 14, 2023, which fall within a similar timeframe.
Compared with other actors linked to the DPRK, this actor consumed a high volume of North Korean state-owned news, including DPRKdaily, uriminzokkiri and kcnawatch. He was also observed administering multiple gambling-related websites (see Annex 1) that may have been used to launder money. We found autofill fields containing 코인거래 주의사항, meaning “Cryptocurrency Trading Precautions,” as well as operational chats between some of “Bismarck's” associates.
The associates appear to have been suspicious of “Bismarck.” After these messages, one associate wanted to formalize the relationship with a contract and appeared aware of the risks involved. The circumstances of their initial contact remain unclear.
They can also modify the “RTP” (Return to Player) rate, the theoretical percentage of money wagered that is returned to players. In this case, they claim that it can be modified at any time.
Our reconstruction and sequencing may be imperfect, but the evidence suggests that the actors organized themselves across multiple countries to establish several gambling businesses. The casinos do not appear to be properly regulated, and the games are copies of legitimate titles from other publishers. Research into gitslotpark[.]com (see Annex 1) identified a lawsuit filed in Virginia, United States, by Pragmatic Play concerning copies of its games. This also aligns with chat excerpts identified through Google Translate.

The lawsuit also contained the name “E. Vasilyevich,” which overlaps with a name found in Bismarck's autofill data.
We assess that DPRK actors may have reused IP addresses from the gambling operation because the domains were purchased by the associates rather than by “Bismarck” or other North Korean operatives. We believe that a team operated behind "Bismarck" during the operation, given the size of the infrastructure, as we understand that "Bismarck" was the system administrator and developer for this operation.
Based on the IPs found in the metadata of "Bismarck's" session cookies, we were able to see that he established connections from a mobile ISP in Moscow, Russia, which may indicate that he conducted his operations from Moscow.
The metadata comes mainly from DPRKtoday, a North Korean news website widely used by overseas workers. It also serves as a pivot point that we use to track threat actors laterally through stealer log data.

DPRK Fake IT Workers and Emotet Botnet Activity
We assessed a DPRK-related actor, identified in a stealer log, who appeared to work as a manager. Two IP addresses stored in his password vault were associated with the delivery of Emotet, modular malware first observed in 2014. Emotet began as a banking trojan before evolving into a loader used to deliver other payloads. We assess with moderate confidence that the manager used the two IPs listed below to deploy Emotet.
The credentials were stolen from the manager's WinSCP vault in 2021. Cross-referencing the history of 160.16.143[.]191, this IP began being used as a loader in early 2022, according to VirusTotal history.

One notable aspect of this profile is that the entire system is in Japanese. This is not the first time we have observed this pattern. Based on his notes, which were written partly in Japanese and partly in Korean, this cell appears to have targeted Japan exclusively. The notes described missions carried out by the team in 2021.

Given the UTC+8 time zone, we assess that he could be located in North Korea.
North Korean Universities and DPRK Fake IT Worker Operations
During our research, we identified multiple universities connected to the fake IT worker operation. The most significant in our assessment were Kim Chaek University of Technology, Jinung Institute of IT Development at Kim Il Sung University, and PYITC, which we attribute with medium confidence to the Pyongyang Information Technology Center.
These were often North Korean universities. In the cases we assessed, the activity appeared to involve fake IT workers operating from within these institutions rather than students. We observed a naming convention of <university acronym>-<number>, with numbering beginning at 001. Using this convention, we ran a bulk lookup on Hudson Rock from <university acronym>-001 to <university acronym>-999, which provided additional context on activity within these institutions.
For the building reconstruction/GEOINT analysis, we are unsure whether the machine naming convention refers to a base or to a named physical location. For this analysis, we assumed that it referred to a named location.
1. Kim Chaek University of Technology and DPRK Fake IT Worker Activity

With low confidence, we reconstructed a small part of Kim Chaek University of Technology using the naming convention found on computers within the assessed cluster. These machines were marked internally as “units” and used tags such as “4-2-205,” which could refer to “Building/Floor/Room.” We see this pattern frequently in stealer logs and assess that these machines are likely not portable. Across different units, only the first digit changed, leading us to assess that it may identify the building. Our goal was to cross-reference these identifiers with satellite imagery to determine whether they reveal additional capabilities. The methodology is outlined below.
To do this, we can count the windows to estimate the number of floors and exclude buildings with fewer than two floors, narrowing the possible locations. We were unsure whether the area marked in blue formed part of the campus.

Based on the data observed, the most frequently represented fake IT worker teams from this university were 41/42/43 KUT and several sub-teams. We understand the hierarchy to be: KUT → Department → Team.
We found limited information on their network infrastructure, but assess that they are probably using the 192.168.142.XXX/24 subnet.
2. Jinung Institute of IT Development and DPRK Fake IT Worker Activity
The Jinung Institute of IT Development appears to be less well documented than the other universities. However, the Kim Il Sung University website briefly references the institute and its activities as a university unit.

We initially clustered a group of IT workers using the naming pattern UnivJN-<number>. One individual stated that he was from “Jinung” and part of a team named JN+<number>. The teams identified as JN1 and JN2 appear to consist mainly of developers.
To identify the exact site, we referred to a 38 North article that identified “Jinung solar panel manufacturing.” Assuming the units are grouped together, we examined the area around that facility using “3-4-XX” as a reference.

One assessed profile used a 10-character password resembling a Chinese student ID. We do not know whether they adopted the same naming convention as Chinese universities, although it is plausible.
3. PYITC and DPRK Fake IT Worker Infrastructure
We are unsure whether PYITC refers to the Pyongyang Information Technology Center, as the acronym appears only within the IT worker teams we assessed. However, we can say with high confidence that the entity is linked to a North Korean university because we observed the same patterns documented in the previous cases. The infrastructure we reconstructed makes extensive use of an HFS solution, probably Rejetto, across PYITC teams (see Annex 2), with “Student Management” appearing as a title.
We observed a pattern in fake IT worker usernames consisting of three digits in the format “3-X-X.” This appears more likely to be an organizational or military naming convention than a building identifier and differs from the machine-name patterns assessed earlier.
Across both networks, we observed the same dashboard name on hosts ending in “.8,” which may reflect an internal convention used by this entity.
The role of students remains unclear. We observed indications that students may participate in the fake IT worker operation, and this is the first time we have encountered the term “student” rather than “units.”
Inside the DPRK Fake IT Worker “Base” System
By cross-referencing sources including stealer logs and the ZachXBT leak, we developed the following understanding of the “Base” system's structure.
Five known bases have been identified, although their locations are not publicly known. A “base” is described as a location where workers can access the internet. Connectivity is provided in two ways: a wired fiber-optic connection, which is stable but slow, or what they call “Wi-Fi,” which is actually a router with a SIM card using the cellular network. The latter is faster but less stable and can support three to five people at a time.
A dedicated support team handles requests for new routers and other technical issues. Workers can move between bases depending on decisions made by the “base boss” and the individual team member. However, they are not required to work from these bases; some companies and universities in North Korea already have internet access.

Turn Threat Intelligence Into Action
Understanding how cybercrime and state-linked activity intersect is critical to staying ahead of emerging threats. Kudelski Security can help you understand the threats facing your organization and turn intelligence into meaningful action. Contact our team for more information.
Sources and Research References
Hudson rock for the stealer logs
// FakeCalls, Casino part
https://research.checkpoint.com/2023/south-korean-android-banking-menace-fakecalls/
// Emotet part
https://github.com/pr0xylife/Emotet/blob/main/e4_emotet_18.03.2022.txt
// Jinung Institute of IT Development (Kim Il Sung university)
// Base
https://investigation.io/dprk-itw-breach/ password:123456
The translation from Korean to English has been made by AI
ANNEX
ANNEX 1 – Gambling administration Link
ANNEX 2 – PYITC network
ANNEX 3 – Bonus – North Korean word list found in an autofill
Translated with AI

.avif)


.webp)



.webp)

