DPRK refers collectively to North Korean state-sponsored and state-aligned cyber threat actors operating on behalf of, or in support of, the Democratic People’s Republic of Korea. This umbrella encompasses multiple intrusion sets and operational clusters commonly associated with North Korean intelligence and revenue-generation missions. North Korean cyber operations are notable for combining espionage, financially motivated theft, sanctions evasion, and covert workforce infiltration in support of state priorities. DPRK-linked actors are among the most significant threats to the cryptocurrency ecosystem. They have repeatedly conducted large-scale thefts from exchanges, platforms, and related services, and have also targeted individual wallets. Their operations commonly rely on social engineering, private-key compromise, credential theft, and post-compromise laundering workflows that use bridges, mixers, and Chinese-language facilitation networks to move stolen funds. Cryptocurrency theft is widely assessed as a major mechanism for generating revenue for the North Korean regime. A defining recent DPRK tradecraft area is the fraudulent remote IT worker program. Operatives use stolen or borrowed identities, deepfake-enhanced interviews, proxy infrastructure, and laptop farms to obtain employment at foreign companies, especially technology and cryptocurrency firms. Once embedded, they can generate revenue, gain insider access, steal intellectual property, establish persistence, and in some cases support espionage or sabotage objectives. Related activity also includes fake recruiters, front companies, and malicious coding tests or interview repositories designed to compromise developers and job candidates. DPRK actors are also active in software supply-chain compromise and developer-focused intrusion campaigns. Reported activity includes malicious package publication, compromise of software maintainers or publishing credentials, abuse of package ecosystems, and delivery of malware through developer tooling and open-source workflows. They have used blockchain-based concealment techniques such as EtherHiding and have been linked to malware families and campaigns including EtherRAT, BeaverTail, and OtterCookie. Their operations frequently emphasize stealth, social engineering, and trusted-channel abuse rather than noisy exploitation alone. North Korean operators have also been observed using artificial intelligence to improve phishing, reconnaissance, and deception, including deepfake personas for hiring fraud and synthetic media in social engineering. Across campaigns, DPRK tradecraft commonly includes initial access via phishing or recruiter lures, credential theft, persistence, exfiltration, defense evasion, and post-exploitation actions aligned either to espionage or financial theft. Known aliases in reporting include North Korea, DPRK actors, DPRK-affiliated actors, DPRK-linked hackers, and North Korean state-sponsored threat actors. As an umbrella designation, DPRK is broader than any single named cluster and may include multiple sub-groups and operational teams.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
537 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses fake job interview coding tests to trick targets into cloning and running attacker-controlled repositories.
Linked to the spear-phishing compromise of a Humanity Protocol director's laptop, leading to theft of private keys, malicious contract upgrades, bridge draining, and unauthorized token minting.
Using deepfake job candidates and synthetic identities to infiltrate enterprise technology teams and gain insider access to production systems.
Suspected state-linked actor attributed in the content to the Axios npm supply chain compromise, involving takeover of a maintainer account and publication of malicious package versions that deployed cross-platform malware via a phantom dependency.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.