Researchers from 38 North, with assistance from Mandiant, reported that a misconfigured cloud server tied to a North Korean IP address exposed thousands of production files indicating North Korean workers may have contributed to international animation projects despite sanctions. The openly accessible server reportedly contained animation cells, videos, workflow documents, and editing notes translated from Chinese into Korean, suggesting a subcontracting chain that obscured the workers’ origin from major studios and distributors.
The leaked materials were linked to projects including Amazon Prime Video’s Invincible season 3, Max and Cartoon Network’s Iyanu: Child of Wonder, and additional Japanese animation work. According to the reporting, the server remained accessible without authentication and appeared to stop being actively used at the end of February, highlighting how North Korea may be generating revenue through skilled IT and creative labor embedded deep within global outsourcing networks.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
The Stimson Center's 38 North Project published findings, with assistance from Mandiant, linking files on the exposed server to international animation projects including Invincible season 3, Iyanu: Child of Wonder, and Japanese anime work. The report said the evidence suggested North Korean workers were contributing to outsourced animation production, likely without the knowledge of the major production companies.
The exposed server reportedly ceased being used at the end of February, although it remained live and accessible. Researchers said its contents were still exposed despite the apparent halt in activity.
In December, researcher Nick Roy found a misconfigured cloud server on a North Korean IP address that exposed thousands of animation-related files without authentication. The server was reportedly being updated daily at the time and appeared to be used to transfer work to and from North Korean animators.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
38north.org
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.