Register and share your invite link to earn from video plays and referrals.

NorthScan
@north_scan
Investigating North Korean IT Worker Infiltration Driven by OSINT & HUMINT | Founded by @0xfigo
59 Following    238 Followers
Found a project on Giveth that you really believe in? Stick with them. 💜 Set up a recurring donation and keep supporting their work every month.
The DAO is back again! Participate and check out the proposals currently under consideration
Onchain security is everyone’s problem and nobody’s job. ETHSecurity Initiatives is how we are changing that. Propose the work. Fund the work. Build the work.
Show more
⚠️ Giveth community, please be careful. We’ve been made aware of a phishing email pretending to be from Giveth. The email says your “donation wallet needs attention” and prompts you to confirm your wallet. This message is not from Giveth. If you receive an email like this, do not click the button, connect your wallet, or sign any transactions. Please stay alert, and if a Giveth email ever looks suspicious, reach out to us through our official channels before interacting with it.
Show more
North Korea fired an unidentified projectile toward the East Sea on Saturday, South Korea's military said. It marks the North's fourth test since early last month, a day after the US, South Korea and Japan wrapped up the Freedom Edge exercise.
Show more
An interview into our research, an remember to do a good background check🎉
What happens after a company hires a North Korean operative? Two researchers built a fake company to find out, hired three of them and published it all. #cybersecurity# #northkorea#
Show more
Long before the world knew him as Kim Jong Il, the former North Korean leader had a Russian name
🎬 "Are you living two lives, Mr. Anderson?"    Time to meet Mr. Benito and watch the Famous Chollima team fall apart — in the video he confronts Mr. Anderson directly about forged documents. ⚠️ Read the full investigation →
Show more
If you want to check our talk here is a great shortcut to watch it on youtube 👀!!
this wild defcon talk is finally out researchers created a fake defi startup, hired lazarus it workers, put them into a sandbox and recorded their tooling, workflows, and faces from inside the operation starts at 5:46:09
Show more
In June, Cointelegraph was invited by @0xfigo, @MauroEldritch and @anyrun_app to take part in an investigation into suspected North Korean IT workers operating inside a fake crypto startup created by the researchers. Our reporter posed as a VC, discussed funding and even offered them a shot at Cointelegraph coverage. They didn’t know who they were pitching to.
Show more
🚨 Fake crypto startup hires three suspected North Korean IT workers. Researchers created Ballena Azul, interviewed the candidates, signed them as employees, and gave them work VMs. No exploit was needed. The access came through the hiring process. See how they got hired:
Show more
🎉 Last week at DEF CON 34, our friends @MauroEldritch and @0xfigo presented the 2nd episode of "Smile, You're on camera" investigation, exposing DPRK IT workers scheme. 🔥 And #ANYRUN# is the part of it. 📖 Read the full undercover investigation:
Show more
North Korean IT workers thought they had landed a lucrative crypto job. Instead, they walked into a sting that exposed their evolving playbook.
"Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup" published by @anyrun_app. #ITWorker#, #FamousChollima#
🔥 New investigation out We went undercover to investigate the Famous Chollima / DPRK IT worker scheme by creating a fake startup and hiring remote workers connected to the operation Working with @BirminghamCyber and @ANYRUN_app, we were able to observe their activity firsthand and capture weeks of real-world activity inside the environment Full story 👇
Show more
🔥 We “hired” Lazarus APT remote workers — and uncovered their toolkit. @BirminghamCyber & @north_scan used #ANYRUN# Sandbox to capture weeks of Famous Chollima activity inside a fake startup. 👀 How not to let a spy in? See full story and videos:
Show more
First time at @defcon and glad to share a new fresh article coming soon...
First time at @defcon and glad to have this beauty in my hands 🔥
First time at @defcon and glad to have this beauty in my hands 🔥
Ethereum security is one of the highest ROI investments the ecosystem can make.
NorthScan is growing 🔎 With support from the Ethereum Security QF round hosted through @Giveth, NorthScan received community donations and matching funds to strengthen our research A special thank you to @TheDAOfund @Quantstamp and @wintermute_t for their major contributions, and to everyone who supported us The funding is helping us improve our GitHub intelligence, making it faster to cross-reference profiles, identify connections, flag suspicious patterns, and analyze the aliases, and behavior associated with suspected DPRK IT worker operations As part of this work, we recently launched “The GitHub Diaries of DPRK IT Workers,” a monthly series documenting cases involving people, projects, and hiring networks that have interacted with suspected DPRK IT worker accounts on GitHub The first investigation is already live: Thanks to this support, we can publish more independent investigations and expand our public threat intelligence resources!
Show more