Active network of North Korean IT front companies exposed

Share:

An analysis of the websites belonging to companies that served as a front for getting North Korean IT workers remote jobs with businesses worldwide has revealed an active network of such companies originating in China.

Unearthing North Korean IT front companies

US authorities have been warning about North Korean IT workers’ tactics to bypass sanctions for a number of years, and have repeatedly seized website domains that looked like they belong to legitimate IT services companies and were used to help North Korean IT workers to hide their true identities and location when applying for jobs.

They’ve also disrupted US-based schemes aimed at facilitating their employment and perpetrating the deception.

SentinelOne researchers have analyzed the websites of four recently identified front companies (whose domains have been seized), and have uncovered multiple leads that point to an active network of North Korean IT front companies originating in China.

They have also discovered another company, domain – huguotechltd[.]com – and website that they believe to be “closely associated with the (…) four reviewed DPRK IT Worker front companies”. That and several other companies are still active.

Advice for organizations

“Front companies, often based in China, Russia, Southeast Asia, and Africa, play a key role in masking the workers’ true origins and managing payments,” researchers Tom Heger and Dakota Cary explained.

“Notable examples include China-based Yanbian Silverstar Network Technology Co. Ltd., disrupted in October 2023, and Russia-based Volasys Silver Star, sanctioned by the U.S. Department of the Treasury in 2018, for their roles in facilitating fraudulent IT operations. These entities helped DPRK workers launder earnings through online payment services and Chinese bank accounts. The payments, often routed through cryptocurrencies or shadow banking systems, ultimately support state programs, including weapons development, circumventing international sanctions.”

Aiding North Korea evade sanctions – even inadvertently – can land companies into legal hot water, but they also risk getting their intellectual property and data stolen, held for ransom, and their systems compromised.

“Organizations are urged to implement robust vetting processes, including careful scrutiny of potential contractors and suppliers, to mitigate risks and prevent inadvertent support of such illicit operations,” Heger and Cary concluded.

The content and look of the websites they analyzed, for example, was copied from legitimate software and consulting firms headquartered in the United States and India – but not perfectly, so the sites sometimes retained a reference to the legitimate company.

Palo Alto Networks’ Unit 42 has recently also shared helpful advice for avoiding putting North Korean IT workers – or worse, hackers – on their payroll.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:03 pm, Feb 3, 2025
weather icon 6°C
L: 4° | H: 7°
few clouds
Humidity: 93 %
Pressure: 1024 mb
Wind: 5 mph WSW
Wind Gust: 10 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 22%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
4° | 7°°C 0.36 mm 36% 14 mph 94 % 1026 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 92 % 1043 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 9 mph 85 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 12 mph 93 % 1041 mb 0 mm/h
Sat Feb 08 9:00 pm
weather icon
1° | 3°°C 0.3 mm 30% 10 mph 94 % 1029 mb 0.22 mm/h
Tomorrow 12:00 am
weather icon
5° | 6°°C 0 mm 0% 6 mph 94 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 6°°C 0 mm 0% 7 mph 90 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 93 % 1023 mb 0 mm/h
Tomorrow 9:00 am
weather icon
7° | 7°°C 0 mm 0% 10 mph 92 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 12 mph 78 % 1022 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
9° | 9°°C 0 mm 0% 14 mph 78 % 1021 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
10° | 10°°C 0 mm 0% 13 mph 79 % 1022 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
8° | 8°°C 0.36 mm 36% 8 mph 72 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,631.99
5.09%
Ethereum(ETH)
€2,728.47
-4.53%
XRP(XRP)
€2.64
3.92%
Tether(USDT)
€0.98
0.11%
Solana(SOL)
€212.30
6.54%
USDC(USDC)
€0.98
0.00%
Dogecoin(DOGE)
€0.278917
6.06%
Shiba Inu(SHIB)
€0.000017
6.37%
Pepe(PEPE)
€0.000011
3.44%
Scroll to Top