FILTERING BY: CLEAR FILTER

Mapping DPRK Infrastructure via Kudelski Security Stealer Log Analysis

North Korean state-sponsored actors are infiltrating Western corporate networks by posing as legitimate remote IT workers to generate illicit revenue. A critical vulnerability in their operational security has emerged: the actors themselves are being targeted by stealer malware. By analyzing the resulting stealer logs, which contain operator credentials and system metadata, researchers at Kudelski Security are reverse-mapping the regime's obfuscation infrastructure. This includes identifying specific proxy networks, IP ranges, and internal coordination tools used to mask the actors' true locations. This campaign directly facilitates the laundering of funds for the DPRK regime and provides critical financial support for Russian military procurement during the ongoing Ukraine conflict.


LINK COPIED TO CLIPBOARD