Home ANY.RUN How to Hunt DPRK IT Worker Activity: Behavioral Clues, Infrastructure, and IOCs 

How to Hunt DPRK IT Worker Activity: Behavioral Clues, Infrastructure, and IOCs 

0

DPRK IT worker operations do not always start with malware, exploitation, or an obvious intrusion. 

The activity may come from a legitimate employee account, an approved device, or a developer who has already passed onboarding.

For security analysts, that changes the investigation: the challenge is not simply finding malicious code but identifying when seemingly normal employee activity begins to reveal a larger operation. 

A joint investigation by  ANY.RUN, Mauro Eldritch, Heiner García, and provided a rare look at those signals from inside a suspected Famous Chollima operation. 

Researchers hired suspected DPRK developers and observed their activity inside specially configured ANY.RUN Sandbox environments, revealing behaviors and infrastructure analysts can use when investigating similar cases. 

Inside the Fake Company 

The researchers created Ballena Azul LTD, a fake DeFi startup complete with a professional website, branding, documentation, and a convincing online presence. 

Screenshot of the Ballena Azul LTD website 

The company became the controlled setting for the next stage of the operation. Once the suspected DPRK developers started working, researchers were able to document the tools, infrastructure, and workflows they relied on in day-to-day activity. 

The investigation exposed remote-access software, system reconnaissance, AI-assisted workflows, shared 2FA services, crypto wallet activity, and supporting VPN and VPS infrastructure, giving analysts a much clearer picture of the operational patterns behind the scheme. 

See the full investigation on the ANY.RUN blog for the recorded interviews, live operator activity, infrastructure findings, and complete toolset breakdown. Check Details Now 

Validate Suspicious Activity in a Safe Environment 

During the investigation, researchers used specially configured ANY.RUN Sandbox environments to observe the operatives without exposing real corporate systems.

That gave them visibility into the files they opened, tools they launched, browser activity, network connections, and other actions as they happened. 

Suspicious activities caught inside ANY.RUN sandbox 

For analysts, the same approach is useful when suspicious files, links, scripts, or tools appear around an employee account.

Inside the sandbox, they can check process activity, outbound connections, redirects, dropped files, command execution, browser behavior, and other indicators instead of relying on a single alert. 

This makes it easier to answer practical questions: What did the artifact actually do? Which infrastructure did it contact? Did it launch remote-access tooling? Did it create additional files or processes? 

That extra behavioral evidence can help analysts reach a stronger verdict faster and decide whether the case should be escalated or contained. 

Trace the Infrastructure Behind the Activity 

The investigation exposed a set of VPS hosts, AstrillVPN exit nodes, and crypto wallets used by the suspected operatives. These indicators can serve as starting points for finding related activity across the environment: 

  • IPv4: 62[.]33[.]223[.]165 // INVESTSTROY-NET (InvestStroyTrest) 
  • IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS 
  • IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS 
  • IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS 
  • IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node 
  • IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node 
  • IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node 
  • IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node 
  • IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node 
  • 0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd 
  • 0xA3D6938f152C47A411263573Bb3AF324C25A8eba 
  • 0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0 

If one of these indicators appears, look at the surrounding activity rather than treating the match as a verdict.

Check which user or process made the connection, what happened before and after it, and whether remote-access, reconnaissance, or unusual account activity appears nearby. 

With ANY.RUN Threat Intelligence Lookup, analysts can also pivot on suspicious indicators to review related sandbox sessions and threat context, helping them understand whether a single connection points to a broader pattern. 

ANY.RUN’s TI Lookup showing all the relevant sandbox sessions for deeper investigations and more context 

Turn Findings into Detection Coverage 

Once suspicious infrastructure or behavior is confirmed, the findings should not stay inside a single case. 

The IPs, VPN endpoints, VPS hosts, and other indicators uncovered in the operation can be added to existing detection workflows so related activity is easier to surface if it appears again. 

ANY.RUN Threat Intelligence Feeds continuously supplies fresh indicators from real-world investigations to SIEM, EDR, and other security tools, helping teams expand coverage beyond the indicators already known from this case. 

Actionable IOCs to your existing security stack 

That makes it easier to spot related infrastructure earlier and avoid rebuilding the same investigation from scratch. 

Catch the Signals Before They Become Business Impact 

DPRK remote-worker activity can be difficult to spot because it often starts with legitimate access, familiar developer tools, and behavior that looks normal in isolation. 

The advantage comes from connecting the signals early: suspicious files and tools, remote-access activity, unusual infrastructure, account behavior, and known IOCs.

The faster teams can validate those clues and understand how they fit together, the less time a malicious insider has to reach source code, cloud environments, financial assets, or other critical systems. 

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN 

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version