PULSE NAME
Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations
WHITE WageMole AlienVault 2025-04-24 Modified: 2025-05-24
8
IOCs
LOW VOLUME
North Korean cybercrime activities heavily rely on Russian IP ranges in Khasan and Khabarovsk, utilizing extensive anonymization networks. The Void Dokkaebi group, linked to North Korea, employs fictitious companies like BlockNovas to target IT professionals through fraudulent job interviews, aiming to steal cryptocurrency and potentially engage in espionage. Their tactics involve using VPNs, proxies, and RDP connections to obscure their origins. Instruction videos suggest the involvement of less-skilled foreign conspirators. The primary focus remains cryptocurrency theft, but there's potential for expanded espionage activities and possible cooperation between North Korean and Russian entities.
Indicators of Compromise (8)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain apply-blocknovas.site 2025-04-24
domain blocknovas.com 2025-04-24
domain easydriver.cloud 2025-04-24
domain lianxinxiao.com 2025-04-24
domain softglide.co 2025-04-24
domain worldenterprise-beta.com 2025-04-24
hostname bookings.blocknovas.com 2025-04-24
hostname gitlab.blocknovas.com 2025-04-24