North Korean Cyber Scams: From Crowdfunding Cons to IT Worker Infiltration

North Korean threat actors have evolved from crowdfunding scams to infiltrating IT companies under fake identities, as part of elaborate revenue-generating schemes. SecureWorks highlights infrastructure links between these fraudulent IT worker schemes and a past 2016 scam. Clearly, North Korea is not just a fan of K-pop but also of K-scams!

Pro Dashboard

Hot Take:

Looks like the North Korean cyber ninjas have been in the game longer than we thought! From crowdfunding cons to IT worker impersonations, they truly are the Swiss army knife of cybercrime. Someone call Hollywood, because this has blockbuster potential written all over it!

Key Points:

  • North Korean threat actors are connected to both IT worker fraud and a 2016 crowdfunding scam.
  • The IT worker fraud involves North Koreans posing as employees under fake identities globally.
  • Notable companies involved include Yanbian Silverstar and Volasys Silver Star, both sanctioned entities.
  • 17 internet domains impersonating IT service companies were seized by the U.S. government.
  • North Korean actors have been linked to cryptocurrency thefts totaling over $1.34 billion in 2024.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?