Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware
2026-08-12 • Kudelski Security •
Kudelski Security linked a DPRK-associated operator known as Bismarck to gambling administration infrastructure and IP addresses that overlap earlier FakeCalls research. A separate fake IT worker manager held credentials for two systems later associated with Emotet delivery, which the researchers assess with moderate confidence were used to deploy the malware. The report also maps fake IT worker teams associated with North Korean universities and describes a five-location Base system used to provide internet access. Parts of the physical-site reconstruction remain low confidence, and the PYITC identity and possible student participation are unresolved.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | admin.loginxcasino.com | 2026-08-12 | 2026-08-12 |
| DOMAIN | adminv2.gitslotpark.com | 2026-08-12 | 2026-08-12 |
| DOMAIN | app-b.insvr.com | 2026-08-12 | 2026-08-12 |
| DOMAIN | prd-sdv2-api.slotsdiamond.com | 2026-08-12 | 2026-08-12 |
| DOMAIN | admin.moo-gadang.com | 2026-08-12 | 2026-08-12 |
| DOMAIN | zeu-000.com | 2026-08-12 | 2026-08-12 |
| DOMAIN | obdb.honorlink.org | 2026-08-12 | 2026-08-12 |
| DOMAIN | backoffice.honorlink.org | 2026-08-12 | 2026-08-12 |
| IPv4 | 185.254.241.135 | 2026-08-12 | 2026-08-12 |
| IPv4 | 160.16.218.63 | 2026-08-12 | 2026-08-12 |
| IPv4 | 160.16.143.191 | 2026-08-12 | 2026-08-12 |
| IPv4 | 182.16.42.18 | 2026-08-12 | 2026-08-12 |