UNC5267

2024-09-23 • MandiantStaying a Step Ahead: Mitigating the DPRK IT Work…

UNC5267 is Mandiant’s designation for North Korean government-directed IT-worker operations observed across victim environments. Mandiant has tracked the activity since 2022, while some reporting places its origins around 2018. UNC5267 is not a centralized intrusion group but a dispersed workforce based primarily in China and Russia, with smaller populations elsewhere, whose members use stolen or fabricated identities to obtain remote employment at Western companies. Operators apply for multiple jobs, reuse resumes and personas, rely on facilitators and laptop farms, and remotely control corporate devices through KVM hardware, virtual-private networks, and commercial administration tools. Their primary objective is illicit salary generation for the North Korean regime, but their legitimate workplace access creates opportunities for source-code theft, espionage, extortion, and future intrusion. The activity combines identity fraud, sanctions evasion, insider access, remote infrastructure, and long-term presence inside technology-sector organizations.

Related Actors

Related Reports in This Cluster

Top Authors

View UNC5267 reports only

View UNC5267 reports only