Active network of North Korean IT front companies exposed

Share:

An analysis of the websites belonging to companies that served as a front for getting North Korean IT workers remote jobs with businesses worldwide has revealed an active network of such companies originating in China.

Unearthing North Korean IT front companies

US authorities have been warning about North Korean IT workers’ tactics to bypass sanctions for a number of years, and have repeatedly seized website domains that looked like they belong to legitimate IT services companies and were used to help North Korean IT workers to hide their true identities and location when applying for jobs.

They’ve also disrupted US-based schemes aimed at facilitating their employment and perpetrating the deception.

SentinelOne researchers have analyzed the websites of four recently identified front companies (whose domains have been seized), and have uncovered multiple leads that point to an active network of North Korean IT front companies originating in China.

They have also discovered another company, domain – huguotechltd[.]com – and website that they believe to be “closely associated with the (…) four reviewed DPRK IT Worker front companies”. That and several other companies are still active.

Advice for organizations

“Front companies, often based in China, Russia, Southeast Asia, and Africa, play a key role in masking the workers’ true origins and managing payments,” researchers Tom Heger and Dakota Cary explained.

“Notable examples include China-based Yanbian Silverstar Network Technology Co. Ltd., disrupted in October 2023, and Russia-based Volasys Silver Star, sanctioned by the U.S. Department of the Treasury in 2018, for their roles in facilitating fraudulent IT operations. These entities helped DPRK workers launder earnings through online payment services and Chinese bank accounts. The payments, often routed through cryptocurrencies or shadow banking systems, ultimately support state programs, including weapons development, circumventing international sanctions.”

Aiding North Korea evade sanctions – even inadvertently – can land companies into legal hot water, but they also risk getting their intellectual property and data stolen, held for ransom, and their systems compromised.

“Organizations are urged to implement robust vetting processes, including careful scrutiny of potential contractors and suppliers, to mitigate risks and prevent inadvertent support of such illicit operations,” Heger and Cary concluded.

The content and look of the websites they analyzed, for example, was copied from legitimate software and consulting firms headquartered in the United States and India – but not perfectly, so the sites sometimes retained a reference to the legitimate company.

Palo Alto Networks’ Unit 42 has recently also shared helpful advice for avoiding putting North Korean IT workers – or worse, hackers – on their payroll.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:13 pm, Jul 2, 2025
weather icon 18°C
L: 17° | H: 19°
overcast clouds
Humidity: 87 %
Pressure: 1017 mb
Wind: 6 mph NNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 0.2 mm 20% 11 mph 87 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 11 mph 57 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
16° | 18°°C 1 mm 100% 13 mph 97 % 1021 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 12 mph 93 % 1007 mb 0 mm/h
Today 1:00 pm
weather icon
18° | 19°°C 0.2 mm 20% 6 mph 87 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
19° | 21°°C 0.2 mm 20% 8 mph 77 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 23°°C 0 mm 0% 11 mph 46 % 1018 mb 0 mm/h
Today 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 11 mph 32 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 7 mph 43 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
14° | 14°°C 0 mm 0% 5 mph 56 % 1026 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0 mm 0% 5 mph 57 % 1028 mb 0 mm/h
Tomorrow 10:00 am
weather icon
20° | 20°°C 0 mm 0% 5 mph 39 % 1028 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,356.73
1.20%
Ethereum(ETH)
€2,080.58
-0.02%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.86
-0.46%
Solana(SOL)
€126.63
0.33%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.137196
0.26%
Shiba Inu(SHIB)
€0.000009
1.12%
Pepe(PEPE)
€0.000008
0.45%
Scroll to Top