DPRK refers to North Korean state-sponsored cyber threat actors collectively associated with the Democratic People’s Republic of Korea. This umbrella includes multiple government-linked operations and sub-clusters engaged in financially motivated cybercrime, espionage, and covert access operations that support state priorities and sanctions evasion. North Korean cyber activity is especially prominent in cryptocurrency theft, software supply-chain compromise, fraudulent remote IT worker schemes, and social-engineering-driven intrusions. North Korean operators have been tied to large-scale cryptocurrency theft from exchanges, services, and individual wallets, including record-setting heists in 2025. Their tradecraft includes compromise of private keys, social engineering of executives and technical staff, infiltration of cryptocurrency and technology firms through fraudulent hiring, and laundering through bridges, mixers, liquidity services, OTC facilitators, and Chinese-language guarantee or laundering ecosystems. Reporting also describes an evolution from theft and laundering toward more durable blockchain-enabled operational infrastructure, including embedding malware payloads and command-and-control data directly into blockchain transactions and adopting techniques such as EtherHiding. DPRK actors also run a sophisticated remote worker and insider-access program. Operatives use stolen or borrowed identities, deepfake-enhanced interviews, proxy chains, residential-device relays, and laptop farms to obtain remote employment at Western companies, particularly in technology-related roles. These operations generate revenue for the regime and can also provide espionage, sabotage, and persistent enterprise access opportunities. Related activity includes fake front companies and malicious coding-test or job-interview lures designed to compromise developers and job candidates. Observed intrusion capabilities associated with DPRK actors include credential theft, session and wallet compromise, malware delivery, persistence, post-exploitation, exfiltration, reconnaissance, defense evasion, and supply-chain compromise. They have used malicious open-source packages, recruiter impersonation, phishing, and blockchain-hosted malware infrastructure. North Korean operators have also been linked to rapid weaponization of newly disclosed vulnerabilities and to attacks targeting developers and software ecosystems. North Korean cyber operations target organizations involved in cryptocurrency, financial services, technology, software development, and government- or defense-adjacent environments. In Europe, DPRK activity has been reported against defense, diplomatic, and financial entities. The dominant strategic driver is financial: generating hard currency, stealing digital assets, and circumventing sanctions in support of state objectives, while some operations also enable espionage and covert access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
70 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
617 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses fake job interview coding tests to trick targets into cloning and running attacker-controlled repositories.
Linked to the spear-phishing compromise of a Humanity Protocol director's laptop, leading to theft of private keys, malicious contract upgrades, bridge draining, and unauthorized token minting.
Using deepfake job candidates and synthetic identities to infiltrate enterprise technology teams and gain insider access to production systems.
Suspected state-linked actor attributed in the content to the Axios npm supply chain compromise, involving takeover of a maintainer account and publication of malicious package versions that deployed cross-platform malware via a phantom dependency.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.