Investigating North Korean IT Worker Infiltration
Driven by OSINT & HUMINT | Founded by @0xfigo
- NorthScan is growing 🔎 With support from the Ethereum Security QF round hosted through @Giveth, NorthScan received community donations and matching funds to strengthen our research A special thank you to @thedaofund @Quantstamp and @wintermute_t for their major contributions,
- 🧵 New investigation: Fake personas on GitHub building trust through open-source activity, suspicious contribution patterns, and coordinated account behavior This research looks at GitHub activity linked to a suspected DPRK IT worker cluster and how fake developer personas🙏Glad to share a new series of short investigations into North Korean IT workers using GitHub to build fake identities, manufacture credibility, and infiltrate companies: The GitHub Diaries of DPRK IT workers
- 🇨🇭Nuestra charla en Insomni'hack se encuentra en YouTube! Investigación en colaboración con @MauroEldritch y @anyrun_app detallando el proceso de falsos trabajadores IT remotos norcoreanos Allí evidenciamos este vector, detallando sus más recientes técnicas y métodos para
- New NorthScan investigation is live! We have published a new investigation into Beejern LLC, a company established in Oklahoma, and its wider connected cluster, including DreamHi and QN Software We mapped suspicious infrastructure overlaps, shared contact details, corporate🧵 New investigation: Beejern, an active Oklahoma LLC, appears linked to a suspected DPRK IT worker cluster first identified through GitHub activity The case connects GitHub aliases, company records, Upwork activity, manipulated imagery, shared infrastructure, and external DPRK



