home.social

#unc5267 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #unc5267, aggregated by home.social.

fetched live
  1. 🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.

    None of them knew it at the time.

    In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.

    → Stolen US identity + AI-generated profile
    → Live #AI assisted interview manipulation
    → Domestic facilitator handling onboarding
    → Corporate laptop sent to a US “laptop farm”
    → KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
    → Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regime

    More than 300 companies impacted. Estimated revenue stream: ~$600M/year.

    Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.

    $17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.

    This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.

    The future of #CTI and insider-threat detection is already here.

    cidu.io/articles/dprk-it-worke

    #NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500

  2. 🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.

    None of them knew it at the time.

    In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.

    → Stolen US identity + AI-generated profile
    → Live #AI assisted interview manipulation
    → Domestic facilitator handling onboarding
    → Corporate laptop sent to a US “laptop farm”
    → KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
    → Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regime

    More than 300 companies impacted. Estimated revenue stream: ~$600M/year.

    Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.

    $17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.

    This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.

    The future of #CTI and insider-threat detection is already here.

    cidu.io/articles/dprk-it-worke

    #NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500