Threat Actor ๐Ÿ‡ฐ๐Ÿ‡ต North Korea

WageMole

Also known as: Famous Chollima ยท UNC5267 ยท Wagemole ยท Nickel Tapestry ยท Storm-1877 ยท Void Dokkaebi ยท WaterPlum ยท PurpleBravo

WageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in Western countries, leveraging stolen personal data from the Contagious Interview campaign. Threat actors create fake identities, including passports and driver's licenses, and prepare study guides for interviews, often utilizing generative AI for well-structured responses. They target small to mid-sized businesses and utilize job platforms like Upwork and Indeed, while employing automation scripts for account creation. WageMole's activities include sharing code within their group and requesting payments through platforms like PayPal to conceal their identity.

Indicators of Compromise 37

Domain bitbucket[.]org Domain trustidcard[.]com Filename Guermok Filename PiKVM Filename raw.js Filename test.list GitHub Repo 7span/react-list GitHub Repo Artiffusion-Inc/mirofish GitHub Repo SendGB GitHub Repo Xpos587/git2md GitHub Repo Xpos587/markfetch GitHub User 7span GitHub User Xpos587 SHA-256 0904eff1edeff4b6eb27f03e0ccc759d6aa8d4e1317a1e6f6586cdb84db4a731 SHA-256 51ddd8f6ff30d76de45e06902c45c55163ddbec7d114ad89b21811ffedb71974 SHA-256 6a9b4e8537bb97e337627b4dd1390bdb03dc66646704bd4b68739d499bd53063 SHA-256 72ebfe69c69d2dd173bb92013ab44d895a3367f91f09e3f8d18acab44e37b26d SHA-256 77aec48003beeceb88e70bed138f535e1536f4bbbdff580528068ad6d184f379 SHA-256 83c145aedfdf61feb02292a6eb5091ea78d8d0ffaebf41585c614723f36641d8 SHA-256 8efa928aa896a5bb3715b8b0ed20881029b0a165a296334f6533fa9169b4463b SHA-256 9e65de386b40f185bf7c1d9b1380395e5ff606c2f8373c63204a52f8ddc01982 SHA-256 a6914ded72bdd21e2f76acde46bf92b385f9ec6f7e6b7fdb873f21438dfbff1d SHA-256 caad2f3d85e467629aa535e0081865d329c4cd7e6ff20a000ea07e62bf2e4394 SHA-256 d27c9f75c3f1665ee19642381a4dd6f2e4038540442cf50948b43f418730fd0a SHA-256 d89c45d65a825971d250d12bc7a449321e1977f194e52e4ca541e8a908712e47 SHA-256 dff2a0fb344a0ad4b2c129712b2273fda46b5ea75713d23d65d5b03d0057f6dd SHA-256 f08e3ee84714cc5faefb7ac300485c879356922003d667587c58d594d875294e IP 135[.]181[.]123[.]177 IP 138[.]201[.]50[.]5 IP 144[.]172[.]112[.]50 IP 144[.]172[.]96[.]35 IP 172[.]86[.]113[.]12 IP 172[.]86[.]73[.]46 IP 172[.]86[.]88[.]188 IP 23[.]227[.]202[.]244 Package node-nvm-ssh Package sevenspan

MITRE ATT&CK TTPs 21

Source Articles

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
North Korean threat actors, operating under multiple aliases including PurpleDelta, Jasper Sleet, and Wagemole, are conducting a large-scale job fraud campaign to infiltrate global companies in IT, healthcare, sales, and other sectors. These actors use forged identities, AI-generated profiles, and synthetic personas to gain remote employment, often using laptop farms equipped with PiKVM and Guermok USB devices to maintain control. They leverage tools like AnyDesk, Telegram, and Slack for coordination, and abuse legitimate platforms such as Workday, Zoom, and Microsoft Teams during recruitment and employment, posing significant insider threat and sanctions compliance risks.
hacker-news ยท2d ago
BeaverTail and OtterCookie evolve with a new Javascript module
Cisco Talos identified a new attack campaign linked to the DPRK-aligned threat group Famous Chollima, which uses social engineering through fake job offers to distribute trojanized Node.js applications. The campaign leverages malicious npm packages like 'node-nvm-ssh' and combines the BeaverTail and OtterCookie malware tools to steal credentials, cryptocurrency wallets, and system information. Recent evolution includes merged functionality between BeaverTail and OtterCookie, with new capabilities such as keylogging, screenshot capture, and clipboard monitoring delivered via a modular JavaScript-based framework.
talos
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
PolinRider is a North Korea-linked supply chain campaign targeting developer ecosystems, including npm, Packagist, Go modules, and Chrome extensions. The threat actors compromise maintainer accounts, modify legitimate repositories with obfuscated JavaScript loaders, and use Git history rewriting to conceal malicious changes. These loaders retrieve encrypted second-stage payloads from blockchain infrastructure, execute them via eval(), and have delivered malware such as DEV#POPPER and OmniStealer. The campaign remains active, with ongoing compromises across multiple open source platforms.
socket-dev