216.73.217.22

Unmasking DPRK Cyber Threat Actors: Fake IT Worker Infrastructure

· Published 23/04/2026 05:27 · Modified 27/04/2026 14:32

Export JSON

Essential information

Published
23/04/2026 05:27
Modified
27/04/2026 14:32
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
astrill vpn cryptocurrency fraud dprk fake it workers freelance platforms residential proxies sanctions evasion vpn infrastructure
Tags
2026-04-23 astrill vpn cryptocurrency fraud dprk fake it workers freelance platforms residential proxies sanctions evasion vpn infrastructure
Related entities
3 indicators, 3 observables, 1 intrusion sets (apt), 16 techniques (mitre), 5 others

Description

Investigation of -linked fake IT worker infrastructure began after cryptocurrency researcher ZachXBT identified domain luckyguys[.]site connected to illicit payments. Analysis of 30 days of network activity associated with IP 163.245.219[.]19 revealed concentrated VPN usage patterns, with (37.5%), Mullvad (32.25%), and Proton VPN (6.25%) being prominent. American and Latvian residential IPs communicated with the infrastructure, showing frequent usage and connectivity to Gmail, ChatGPT, and Workana freelance platform. A second IP, 216.158.225[.]144, was discovered through X509 certificate analysis. Traffic dropped sharply following public exposure, consistent with adversary behavior of abandoning attributed infrastructure. The activity suggests a distributed network of remote IT workers participating in workflows, leveraging AI tools and to obtain employment under false identities.

External references