{"id":2433,"date":"2025-03-07T10:01:50","date_gmt":"2025-03-07T10:01:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/07\/north-korean-it-workers-using-github-to-attack-organization-globally\/"},"modified":"2025-03-07T10:01:50","modified_gmt":"2025-03-07T10:01:50","slug":"north-korean-it-workers-using-github-to-attack-organization-globally","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/07\/north-korean-it-workers-using-github-to-attack-organization-globally\/","title":{"rendered":"North Korean IT Workers Using GitHub To Attack Organization Globally"},"content":{"rendered":"<p>    North Korean IT Workers Using GitHub To Attack Organization Globally<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity research firm NISOS has uncovered a network of suspected North Korean IT workers who are leveraging GitHub to create elaborate fake personas aimed at securing employment with companies in Japan and the United States.<\/p>\n<p>These individuals pose as Vietnamese, Japanese, and Singaporean nationals while seeking positions in remote engineering and full-stack blockchain development.<\/p>\n<p>The ultimate goal appears to be generating foreign currency to fund North Korea\u2019s weapons programs, including ballistic missile and nuclear development.<\/p>\n<p>The operation demonstrates sophisticated identity creation techniques, with the actors reusing and building upon established <a href=\"https:\/\/cybersecuritynews.com\/github-enterprise-server-vulnerability-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub<\/a> accounts to create believable backstories for their personas.<\/p>\n<p>These workers maintain a presence on employment websites, freelance platforms, and <a href=\"https:\/\/cybersecuritynews.com\/best-devops-tools-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">software development tools<\/a>, but notably lack authentic social media footprints.<\/p>\n<p>NISOS researchers <a href=\"https:\/\/nisos.com\/research\/dprk-github-employment-fraud\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that at least two of the fake personas have successfully obtained employment at small companies with fewer than 50 employees.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhXlyNMV5nSTTmVBeqxm7twd9pfb_DGSyA3ola0h_kzwR2PuP5ksuGhtGyxMleRC5aPNo56B_eiXi488wq1INAWXiOOhOgCTuHeWKOLaev4VCEJmG50AX2Zm1Yn3onrf3XAYV6P0BRiyKEIdf95smNR94Qxpgnp1UlpykG2Ppk2wRws6JZSCvype9kIvAg\/s16000\/Network%2520map%2520of%2520likely%2520DPRK-affiliated%2520personas%2520%28Source%2520-%2520NISOS%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Network map of likely DPRK-affiliated personas (Source \u2013 NISOS)<\/figcaption><\/figure>\n<\/div>\n<p>Several technical indicators help identify these North Korean IT workers. They typically claim expertise in three specific domains: web and mobile application development, proficiency in multiple programming languages, and blockchain technology knowledge.<\/p>\n<p>Their email addresses often follow patterns, including the frequent use of the number \u201c116\u201d and the word \u201cdev\u201d in their addresses. These consistent patterns across multiple accounts enabled researchers to link the various personas to a single coordinated network.<\/p>\n<p>The personas demonstrate elaborate technical deception techniques to establish credibility.<\/p>\n<p>Their GitHub repositories often show manufactured contribution histories, with researchers finding instances where accounts co-authored commits with previously identified DPRK-affiliated accounts.<\/p>\n<p>For example, a GitHub account \u201cnickdev0118\u201d was found to have co-authored code commits with another suspected North Korean account \u201cAnacondaDev0120.\u201d<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiKbuIewF0mXy6l25NQIC7dNG0ZiFkI7S0Pi5NGZMfto2JwUFwlIyEmxRLuBoi0aM95GOXD_xKD1XYa26pdtvsJwIxUBGS1JBFa7loaymKrHU6Q0U_hSnTnARvGOEkYz4_bv6lQOskEJ8hB8tb8VJaHCfN62w31p_wPUEvAaMp58daEoRhGZox11i5s9qw\/s16000\/An%2520example%2520of%2520a%2520commit%2520AnacondaDev0120%2520and%2520nickdev0118%2520co-authored%2520%28Source%2520-%2520NISOS%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">An example of a commit AnacondaDev0120 and nickdev0118 co-authored (Source \u2013 NISOS)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>A Case in Focus: Huy Diep\/HuiGia Diep<\/strong><\/h2>\n<p>One primary example detailed in the report is the persona \u201cHuy Diep\u201d (also using the name \u201cHuiGia Diep\u201d), who reportedly secured employment as a software engineer at Japanese consulting company Tenpct Inc since September 2023.<\/p>\n<p>This persona maintained an elaborate personal website linking to his supposed employer and showcasing his technical credentials.<\/p>\n<p>Investigators found the persona claimed eight years of software engineering experience and proficiency in numerous programming languages.<\/p>\n<p>A technical review of his GitHub contribution history revealed suspicious patterns consistent with other identified DPRK actors.<\/p>\n<p>The report provides evidence of digital manipulation used by the persona, with multiple instances where the individual\u2019s face was digitally superimposed onto stock photographs to create the appearance of the person working in professional environments.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjfjuRbGHjOS-ChXxKFmo6cBtNdK7a7mFmB9BNIsgykdym-2x9O5LFSOBF8a1UyqRnCmvtYFB-lPxkq2PmLS2EibTDB_Ez097O9pKdf31MUB9u47SjmHuIFpOqU5_MaaUJXM1NAmDSsUaRGTLWsuFFys8LRK-o5IUqI0IN8lybHOrKXvP2CXIuphkVV4J0\/s16000\/Digital%2520Photo%2520Manipulation%2520%28Source%2520-%2520NISOS%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Digital Photo Manipulation (Source \u2013 NISOS)<\/figcaption><\/figure>\n<\/div>\n<p>The exact same stock photos were identified with different heads inserted. This technique appears common across the network of fake personas, providing a technical indicator for identifying potential DPRK-affiliated accounts.<\/p>\n<p>The research suggests this activity represents not just isolated fraud but a systematic effort by North Korea to place IT workers in legitimate companies, potentially creating <a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEicq2aX-kBzpD1SbHRyJ1lj6AW6bWQSPWy47x1q5VXUX65mvZUQAFP-Nr1_F_qnjQO1kx8vn9SAmiotI8gIQ6suE6fzWE_uwz6xMmizHOfSDnF4KQuKnGT1BKTKLAZ86H_oSZu9xRihCY8zL8vSdXJfvugZlHQjRA8u5iUCWy4xZ_RbHBKyslL7Z9mzvQ\/s16000\/EEEEEEE.webp\" target=\"_blank\" rel=\"noreferrer noopener\">security risks<\/a> beyond the financial implications.<\/p>\n<p>Companies are advised to enhance their hiring verification processes, particularly when considering remote technical workers with profiles matching these patterns.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><strong><code>Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new-stegocampaign-attack&amp;utm_content=intelligence.any.run&amp;utm_term=040325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for free<\/a><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/north-korean-it-workers-using-github\/\">North Korean IT Workers Using GitHub To Attack Organization Globally<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/north-korean-it-workers-using-github\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean IT Workers Using GitHub To Attack Organization Globally Cybersecurity research firm NISOS has uncovered a network of suspected North Korean IT workers who are leveraging GitHub to create elaborate fake personas aimed at securing employment with companies in Japan and the United States. These individuals pose as Vietnamese, Japanese, and Singaporean nationals while [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-2433","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2433"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2433"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2433\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}