Future Tech Group is a DPRK-linked technology company associated with a broader sanctions-evasion and procurement network tied to North Korean front companies involved in defense-related trade. It has been publicly linked to North Korea and appears in the same operational cluster as Glocom, a front company identified by a United Nations Panel of Experts as being managed by Pan Systems Pyongyang Branch and affiliated with the Reconnaissance General Bureau. The cluster has been associated with the marketing and sale of military communications equipment and other advanced technology products, and with efforts to sustain commercial access despite international sanctions. Future Tech Group has been connected through shared infrastructure and overlapping operational artifacts with entities assessed to function as supplier-facing intermediaries for electronics and communications-related procurement. Reporting has linked the company to facial recognition technology sales, indicating activity beyond traditional military radio systems and suggesting a broader technology-trading role. The surrounding network has shown characteristics consistent with covert procurement and sanctions evasion, including the use of front-company branding, questionable corporate identities, overlapping online personas, and cross-border commercial representations spanning East Asia and Russia. At high confidence, Future Tech Group should be understood as part of a DPRK-linked commercial and procurement ecosystem supporting North Korean state interests. Given its association with entities tied to the Reconnaissance General Bureau and defense-related equipment sales, its dominant role is best characterized as enabling acquisition, brokerage, and outward-facing commercial cover rather than conducting publicly documented disruptive cyber intrusions. Known associated entities in this cluster include Glocom and Hato Tsusin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.