Active network of North Korean IT front companies exposed

Share:

An analysis of the websites belonging to companies that served as a front for getting North Korean IT workers remote jobs with businesses worldwide has revealed an active network of such companies originating in China.

Unearthing North Korean IT front companies

US authorities have been warning about North Korean IT workers’ tactics to bypass sanctions for a number of years, and have repeatedly seized website domains that looked like they belong to legitimate IT services companies and were used to help North Korean IT workers to hide their true identities and location when applying for jobs.

They’ve also disrupted US-based schemes aimed at facilitating their employment and perpetrating the deception.

SentinelOne researchers have analyzed the websites of four recently identified front companies (whose domains have been seized), and have uncovered multiple leads that point to an active network of North Korean IT front companies originating in China.

They have also discovered another company, domain – huguotechltd[.]com – and website that they believe to be “closely associated with the (…) four reviewed DPRK IT Worker front companies”. That and several other companies are still active.

Advice for organizations

“Front companies, often based in China, Russia, Southeast Asia, and Africa, play a key role in masking the workers’ true origins and managing payments,” researchers Tom Heger and Dakota Cary explained.

“Notable examples include China-based Yanbian Silverstar Network Technology Co. Ltd., disrupted in October 2023, and Russia-based Volasys Silver Star, sanctioned by the U.S. Department of the Treasury in 2018, for their roles in facilitating fraudulent IT operations. These entities helped DPRK workers launder earnings through online payment services and Chinese bank accounts. The payments, often routed through cryptocurrencies or shadow banking systems, ultimately support state programs, including weapons development, circumventing international sanctions.”

Aiding North Korea evade sanctions – even inadvertently – can land companies into legal hot water, but they also risk getting their intellectual property and data stolen, held for ransom, and their systems compromised.

“Organizations are urged to implement robust vetting processes, including careful scrutiny of potential contractors and suppliers, to mitigate risks and prevent inadvertent support of such illicit operations,” Heger and Cary concluded.

The content and look of the websites they analyzed, for example, was copied from legitimate software and consulting firms headquartered in the United States and India – but not perfectly, so the sites sometimes retained a reference to the legitimate company.

Palo Alto Networks’ Unit 42 has recently also shared helpful advice for avoiding putting North Korean IT workers – or worse, hackers – on their payroll.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:28 pm, Feb 3, 2025
weather icon 8°C
L: 7° | H: 9°
overcast clouds
Humidity: 81 %
Pressure: 1024 mb
Wind: 9 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 9°°C 0 mm 0% 8 mph 97 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0.2 mm 20% 14 mph 98 % 1027 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 89 % 1044 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 10 mph 86 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
3° | 6°°C 0 mm 0% 14 mph 91 % 1039 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 8°°C 0 mm 0% 8 mph 86 % 1025 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 7°°C 0 mm 0% 5 mph 91 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 97 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 5 mph 98 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 0 mm 0% 7 mph 91 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 95 % 1022 mb 0 mm/h
Tomorrow 9:00 am
weather icon
7° | 7°°C 0 mm 0% 11 mph 90 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 13 mph 79 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,756.24
-3.76%
Ethereum(ETH)
€2,518.10
-16.10%
Tether(USDT)
€0.98
0.15%
XRP(XRP)
€2.32
-14.72%
Solana(SOL)
€190.98
-7.19%
USDC(USDC)
€0.98
0.00%
Dogecoin(DOGE)
€0.246701
-14.10%
Shiba Inu(SHIB)
€0.000015
-14.85%
Pepe(PEPE)
€0.000010
-21.08%
Scroll to Top