Close Menu
Mirror Brief

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ex-Arsenal midfielder Partey joins Villarreal despite his legal troubles

    August 8, 2025

    UK ministers push ahead with discount on bills for households near new pylons | Energy bills

    August 8, 2025

    As dark financial clouds gather, Labour has to heed its past: when it chooses austerity, it loses elections | Andy Beckett

    August 8, 2025
    Facebook X (Twitter) Instagram
    Mirror BriefMirror Brief
    Trending
    • Ex-Arsenal midfielder Partey joins Villarreal despite his legal troubles
    • UK ministers push ahead with discount on bills for households near new pylons | Energy bills
    • As dark financial clouds gather, Labour has to heed its past: when it chooses austerity, it loses elections | Andy Beckett
    • Instagram’s map feature spurs user backlash over privacy concerns
    • Mandalorian actress Gina Carano settles with Disney over firing
    • Benjamina Ebuehi’s recipe for peach and sumac Eton mess | Dessert
    • Gloucestershire support network helped us to breastfeed, say mums
    • Boxing: BBC to broadcast Boxxer fights on TV and iPlayer
    Friday, August 8
    • Home
    • Business
    • Health
    • Lifestyle
    • Politics
    • Science
    • Sports
    • World
    • Travel
    • Technology
    • Entertainment
    Mirror Brief
    Home»Technology»Leak Reveals the Workaday Lives of North Korean IT Scammers
    Technology

    Leak Reveals the Workaday Lives of North Korean IT Scammers

    By Emma ReynoldsAugust 8, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Leak Reveals the Workaday Lives of North Korean IT Scammers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The tables show the potential target jobs for IT workers. One sheet, which seemingly includes daily updates, lists job descriptions (“need a new react and web3 developer”), the companies advertising them, and their locations. It also links to the vacancies on freelance websites or contact details for those conducting the hiring. One “status” column says whether they are “waiting” or if there has been “contact.”

    Screenshots of one spreadsheet seen by WIRED appears to list the potential real-world names of the IT workers themselves. Alongside each name is a register of the make and model of computer they allegedly have, as well as monitors, hard drives, and serial numbers for each device. The “master boss,” who does not have a name listed, is apparently using a 34-inch monitor and two 500GB hard drives.

    One “analysis” page in the data seen by SttyK, the security researcher, shows a list of types of work the group of fraudsters are involved in: AI, blockchain, web scraping, bot development, mobile app and web development, trading, CMS development, desktop app development, and “others.” Each category has a potential budget listed and a “total paid” field. A dozen graphs in one spreadsheet claim to track how much they have been paid, the most lucrative regions to make money from, and whether getting paid weekly, monthly, or as a fixed sum is the most successful.

    “It’s professionally run,” says Michael “Barni” Barnhart, a leading North Korean hacking and threat researcher who works for insider threat security firm DTEX. “Everyone has to make their quotas. Everything needs to be jotted down. Everything needs to be noted,” he says. The researcher adds that he has seen similar levels of record keeping with North Korea’s sophisticated hacking groups, which have stolen billions in cryptocurrency in recent years, and are largely separate to IT worker schemes. Barnhart has viewed the data obtained by SttyK and says it overlaps with what he and other researchers were tracking.

    “I do think this data is very real,” says Evan Gordenker, a consulting senior manager at the Unit 42 threat intelligence team of cybersecurity company Palo Alto Networks, who has also seen the data SttyK obtained. Gordenker says the firm had been tracking multiple accounts in the data and that one of the prominent GitHub accounts was previously exposing the IT workers’ files publicly. None of the DPRK-linked email addresses responded to WIRED’s requests for comment.

    GitHub removed three developer accounts after WIRED got in touch, with Raj Laud, the company’s head of cybersecurity and online safety, saying they have been suspended in line with its “spam and inauthentic activity” rules. “The prevalence of such nation-state threat activity is an industry-wide challenge and a complex issue that we take seriously,” Laud says.

    Google declined to comment on specific accounts WIRED provided, citing policies around account privacy and security. “We have processes and policies in place to detect these operations and report them to law enforcement,” says Mike Sinno, director of detection and response at Google. “These processes include taking action against fraudulent activity, proactively notifying targeted organizations, and working with public and private partnerships to share threat intelligence that strengthens defenses against these campaigns.”

    Korean leak lives North reveals Scammers Workaday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWaterstones sorry after readers criticise event ‘overcrowding’
    Next Article Ghana : three days of national mourning
    Emma Reynolds
    • Website

    Emma Reynolds is a senior journalist at Mirror Brief, covering world affairs, politics, and cultural trends for over eight years. She is passionate about unbiased reporting and delivering in-depth stories that matter.

    Related Posts

    Technology

    Instagram’s map feature spurs user backlash over privacy concerns

    August 8, 2025
    Technology

    Trump announces Apple’s plan to invest $100bn in US manufacturing | Apple

    August 8, 2025
    Technology

    Trump calls for Intel boss Lip-Bu Tan to resign over alleged China ties

    August 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Medium Rectangle Ad
    Top Posts

    Revealed: Yorkshire Water boss was paid extra £1.3m via offshore parent firm | Water industry

    August 3, 202513 Views

    Eric Trump opens door to political dynasty

    June 27, 20257 Views

    How has Ryanair changed its cabin baggage rule – and will other airlines do it too? | Ryanair

    July 5, 20256 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Technology

    Meta Wins Blockbuster AI Copyright Case—but There’s a Catch

    Emma ReynoldsJune 25, 2025
    Business

    No phone signal on your train? There may be a fix

    Emma ReynoldsJune 25, 2025
    World

    US sanctions Mexican banks, alleging connections to cartel money laundering | Crime News

    Emma ReynoldsJune 25, 2025

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Medium Rectangle Ad
    Most Popular

    Revealed: Yorkshire Water boss was paid extra £1.3m via offshore parent firm | Water industry

    August 3, 202513 Views

    Eric Trump opens door to political dynasty

    June 27, 20257 Views

    How has Ryanair changed its cabin baggage rule – and will other airlines do it too? | Ryanair

    July 5, 20256 Views
    Our Picks

    Ex-Arsenal midfielder Partey joins Villarreal despite his legal troubles

    August 8, 2025

    UK ministers push ahead with discount on bills for households near new pylons | Energy bills

    August 8, 2025

    As dark financial clouds gather, Labour has to heed its past: when it chooses austerity, it loses elections | Andy Beckett

    August 8, 2025
    Recent Posts
    • Ex-Arsenal midfielder Partey joins Villarreal despite his legal troubles
    • UK ministers push ahead with discount on bills for households near new pylons | Energy bills
    • As dark financial clouds gather, Labour has to heed its past: when it chooses austerity, it loses elections | Andy Beckett
    • Instagram’s map feature spurs user backlash over privacy concerns
    • Mandalorian actress Gina Carano settles with Disney over firing
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 Mirror Brief. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.