TAG-120

2025-02-13 • Recorded FutureInside the Scam: North Korea’s IT Worker Threat

TAG-120 (Threat Activity Group 120) was Recorded Future Insikt Group's original name, later changed to PurpleBravo, for a North Korean-linked cluster documented in a February 2025 report on North Korean IT-worker fraud and related cyber operations. Insikt Group found the group overlaps with the "Contagious Interview" campaign, first documented in November 2023, which targets software developers, primarily in cryptocurrency, through fake recruiter personas and fraudulent job interviews that lead victims to download malicious "coding challenge" files. Its toolkit includes the BeaverTail JavaScript infostealer, the cross-platform Python backdoor InvisibleFerret, and the OtterCookie backdoor, first identified in December 2024. Between October and November 2024, Insikt Group observed the group targeting at least seven organizations, including a cryptocurrency market-making firm, an online casino, and a software-development company, using fabricated recruiter personas and front companies such as "AgencyHill99" advertised across LinkedIn, Telegram, Upwork, DoraHacks, and Intch, while managing command-and-control infrastructure through Astrill VPN.

Related Actors

Related Reports in This Cluster

Top Authors

View TAG-120 reports only

View TAG-120 reports only