---Advertisement---

DPRK Fake IT Workers Exposed Stealer Logs Reveal North Korea Network Infrastructure

By xploitzone
July 20, 2026 5:29 PM
---Advertisement---

Kudelski Security researcher Clifford used stealer logs and passive analysis to map evolving DPRK fake IT worker infrastructure revealing new network segments team structures Kim Chaek University links Ryonbong connections and offensive clusters including Astrill and Mullvad VPN exit nodes routing through Russia toward US and Japan targets.

Imagine a North Korean IT worker sitting in front of a Huawei HiLink router somewhere inside a country that officially does not employ remote freelancers and quietly configuring their gateway address while an infostealer running on that very machine logs the entire session.

That log then makes its way into a public database where a security researcher at Kudelski picks it up months later and suddenly the internal network architecture of a sanctioned state sponsored IT fraud operation becomes visible layer by layer. That exact scenario played out and Kudelski researcher Clifford published the findings on July 17 2026 as a follow up to their earlier groundbreaking research on DPRK fake IT worker networks.

DPRK Fake IT Worker Attack Explained

This investigation relied entirely on passive analysis of publicly available data meaning no active probing or intrusion of any kind touched DPRK systems. The foundation came from stealer logs which are datasets produced when information stealing malware runs on a victim machine and automatically captures screenshots credentials browser history and system configuration details before exfiltrating everything to the malware operator.

In the DPRK case researchers found stealer logs belonging to the fake IT workers themselves meaning the very operatives running fraud campaigns against Western companies had their own machines compromised by commodity malware they encountered during their operations.

The infrastructure map Kudelski built divides into three conceptual layers. Blue represents the target space where victim organizations employing fake IT workers sit. Grey represents neutral space through which the operation routes traffic including commercial VPN services and Russian transit networks. Red represents the adversary space including command and control servers internal administrative networks and offensive infrastructure clusters.

The public facing IP tracking revealed meaningful changes since Kudelski previous report. Two IP addresses previously attributed to the investstroytrest-gw transtelecom domain and located in Khabarovsk Russia shifted to the SevDirInfr-gw transtelecom domain and relocated to Moscow suggesting a deliberate infrastructure migration by the network operations team managing DPRK exit nodes.

Public routing analysis showing infrastructure movement and VPN transit nodes observed by Kudelski researchers. Kudelski Security

The Skyfreight Limited associated IP range at 83.234.227.x remained completely unchanged and continues to serve Team 821-39 which researchers assess as likely having a physical presence in Russia given the stability of that infrastructure over an extended observation period.

The VPN layer provides the clearest picture of how fake IT workers manufacture the appearance of legitimate US and Japan based employment. Astrill VPN appears as the most commonly used provider and its appeal stems from the difficulty researchers face in fingerprinting its server infrastructure.

Kudelski cross referenced IP data from Spur and OTX to find profiles and observed that fake IT worker exit nodes share overlap with offensive team nodes suggesting either shared infrastructure or shared VPN accounts between the income generating fraud operation and the active hacking units.

Mullvad emerged as the second most common VPN choice with its infrastructure more readily identifiable through dedicated named IP ranges including M247 Japan ranges covering 37.120.154.0/24 and 185.242.4.0/24.

One operationally significant observation involves Cluster B which makes remarkably little effort to conceal its command and control IP addresses. The address 175.45.178.222 has been attributed to a DPRK attacker team for more than five years and that team continues reusing it sometimes behind a single proxy and sometimes with no VPN protection whatsoever.

This behavioral pattern suggests either operational complacency institutional knowledge gaps within the team or a deliberate acceptance of exposure risk in exchange for operational simplicity.

How DPRK Cyber Operations Are Organized

The private IP address mapping delivered the most surprising insights of the entire investigation. Kudelski had previously encountered internal acronyms like HMB RS and S.E.C. without being able to resolve them. A leaked dataset published by ZachXBT provided the key. HMB maps to HamBuk.

RS maps to RedStar which aligns with the RedStar OS North Korean operating system developed internally. S.E.C. maps to the Second Economy Committee which operates as a key institution managing foreign currency earning operations for the North Korean state.

The gateway discovery came through a specific stealer log showing a fake IT worker actively configuring a Huawei HiLink router and accessing its admin interface through 192.168.8.1 on a network associated with Team 313.

Internal Team 313 gateway discovered through stealer log analysis showing the default network layout. Source Kudelski Security

This single log entry provided the first confirmed view of how internal networks structured their gateway addressing convention which researchers assess with low confidence follows the common practice of assigning the first usable address in each subnet as the gateway.

The Ryonbong connection carries particular significance given that Ryonbong General Corporation sits on international sanctions lists as a North Korean entity linked to weapons programs. From an infrastructure perspective Ryonbong appears to perform a support and administrative function providing resources to DPRK workers and collecting administrative reports from them.

The RB proxy network contained a WebRTC call server at 192.168.109.2 and references to a separate internal communication tool called CallPC which appears across multiple DPRK worker networks suggesting a standardized internal voice and video communication stack.

Administrative network containing the RB Proxy server and internal WebRTC communication infrastructure. Source: Kudelski Security

Kim Chaek University of Technology appeared through two separate evidence threads. A contact email address [email protected] linked to a subdomain that researchers connected to the university’s domain. A separate stealer log then revealed 13 team designations ranging from 41-KUT and 42-KUT through to entries labeled HQ and Ryonbong.

The teams carry labels suggesting university affiliation yet the naming convention does not correspond to any identifiable academic structure suggesting the university functions as an organizational umbrella or recruiting pipeline rather than an academic classification.

A new offensive cluster labeled PUG appeared in this research cycle though the meaning of the acronym remains unresolved. One associated user connects to a team called Yuhang which shares its name with a district in Hangzhou China though researchers explicitly note this geographic overlap provides insufficient evidence for attribution at this stage.

Internal offensive infrastructure containing GitLab, HTTP services, servers and the newly identified PUG cluster. Internal offensive infrastructure containing GitLab, HTTP services, servers and the newly identified PUG cluster. Source Kudelski Security

The offensive infrastructure section also revealed that a server at 192.168.143.66 hosted internal English language training videos covering business English grammar vocabulary and conversational phrases pulled from public YouTube channels and served internally.

The content included professional English instruction and advanced vocabulary training which aligns directly with the operational requirement for fake IT workers to communicate convincingly with hiring managers and colleagues at Western companies.

DPRK IT Worker Detection & Mitigation Guide

The antivirus software observed running on DPRK worker machines provides an unexpected attribution signal. The machines consistently ran Chinese language antivirus products including Qihoo 360 Tencent PC Manager Lenovo Anti-Virus powered by Huorong Security and Kingsoft Antivirus from Beijing Lingbao Intelligent Technology.

The exclusive presence of Chinese security software rather than globally common products like Windows Defender or international brands points toward procurement through Chinese commercial channels and possible operational infrastructure routing through Chinese technology supply chains.

Security teams defending against DPRK fake IT worker infiltration should treat the IOC list with appropriate nuance. The IP addresses listed including the Polaris Team cluster at 104.253.x.x ranges the MyoHyangGyongSong team at 162.253.129.2 Team 128-710 at 91.239.130.102 and the long running attacker exit node at 175.45.178.222 provide network level detection anchors.

However the observation that Cluster B reuses IPs for years while Cluster A actively rotates infrastructure suggests detection strategies need to combine static IP blocking with behavioral anomaly detection rather than relying solely on known bad IP lists.

For hiring managers and HR teams the practical threat posed by these networks extends beyond technical infrastructure. Fake IT workers actively use commercial VPNs to present US or Japan geolocated connections and use internal English training programs to improve the plausibility of their communication.

Identity verification processes that rely solely on video interviews conducted over standard platforms and resume details matching claimed credentials provide insufficient protection given the resources these operations deploy toward maintaining convincing cover identities.

Mandatory verified identity document checks through third party verification services combined with device fingerprinting during onboarding offer meaningfully stronger protection against this specific threat class.

The discovery of English training servers inside DPRK internal infrastructure removes any doubt that these operations invest heavily in the human performance layer of their deception. An operation sophisticated enough to maintain mapped internal networks separate offensive and income generating clusters dedicated VPN infrastructure and internal communication tools while simultaneously training workers in professional English represents a genuinely industrialized state-sponsored revenue generation operation that Western hiring infrastructure currently handles with tools designed for much simpler fraud scenarios.

xploitzone

Exploring the world of cybersecurity through in depth analysis of vulnerabilities,data breaches and emerging threats. Delivering real insights technical breakdowns and bug bounty discoveries for security enthusiasts and researchers.

Join Twitter

Join Now

Join Telegram

Join Now

Leave a Comment