Ex-Unit 350: Elite cookie ops. Perfect bake temp. No ties to Unit 8200.
Jul 24 • 8 tweets • 2 min read
Whats this... real DPRK ITW names and related emails/profiles?! 🇰🇵🍪🇰🇵🍪🇰🇵🍪
Enjoyyy and enrich with your data in the thread below ~> ❤️❤️🔥🔥
(will post raw for easier searching in 🧵🧵)
@Narcass3 @aptwhatnow @KawaiiJongUwUn @KeyboardTrial2 @eastside_nci #NorthKorea #DPRK
@Narcass3 @aptwhatnow @KawaiiJongUwUn @KeyboardTrial2 @eastside_nci Black Man
github[.]com/Lunggo123
calanderin0130@gmail[.]com
Ri Min Hyok
Mister Black
github[.]com/business-developer-alpha business.developer.alpha@gmail[.]com
Jon Son Chol
goodlife26918@gmail[.]com
trello[.]com/u/goodlife169
github[.]com/good-life-26918
Jun 30 • 7 tweets • 4 min read
Other ✨interesting ✨North Korean threat actor Google searches and/or communications. 🧵
(1) Researching drones, radar trucks, etc. Lots of activity
#DPRK #NorthKorea roboflow.com
Looks like they wanted someone to believe they were a citizen of Ukraine! Had to take the day off due to "mass shelling". Needed funds moved outside of @Upwork .
#DPRK #NorthKorea
May 29 • 4 tweets • 1 min read
DPRK.
"David" also has a zillion other identities he leverages (see thread 🧵). A few interesting ones are several emails under the Korean named app "Haru Hana" (below)
Did you know DPRK "remote workers" are heavily involved in work outside of IT? Some ITW have transitioned into to Civil Engineers! This has been going on for quite some time...
THIS INCLUDES stamping engineering drawings for construction in the U.S. as purported "Structural Engineers". They are also electrical engineers, construction engineering, etc. they will create CAD drawings for you on your next construction project.
Apr 21 • 5 tweets • 2 min read
Hello! I come bearing ("suspected") DPRK gifts. Including public Google Drive links they left open containing 🧁goodies. Copies have been made, don't worry!
His name may be Bobby Lee Ray, but don't be fooled! Although it sounds like he might own a BBQ shop in Tennessee..... he's actually a ✨DPRK IT worker✨
This is a DPRK IT worker, Nikos Amofa! You might find him on other sites too, if you look!
Apr 18 • 23 tweets • 4 min read
How do you catch a DPRK actor you ask? Here are a few things to think about;
1. They love to use a VPN when applying for jobs. Check your HR system.
2. They love certain email schemas, including emails ending in "dev", "eng", "soft", using periods to separate names (e.g., , corly.devguru. They most commonly use gmail. They also have numbers at the end such as "benton.franklin.0710" "dev84".luke.ford.dev
Apr 18 • 30 tweets • 12 min read
Meet Faraz, he's a North Korean IT worker.
#dprk #cybersecurity #northkorea @Mandiant
@Mandiant Meet Jason Rostro, he's a North Korean IT worker.