Monday, March 3, 2025
Homecyber securityNorth Korean IT Workers Hide Their IPs Using Astrill VPN

North Korean IT Workers Hide Their IPs Using Astrill VPN

Published on

SIEM as a Service

Follow Us on Google News

Security researchers have uncovered new evidence that North Korean threat actors, particularly the Lazarus Group, are actively using Astrill VPN to conceal their true IP addresses during cyberattacks and fraudulent IT worker schemes.

Silent Push, a cybersecurity firm, recently acquired infrastructure and logs from the Lazarus subgroup known as “Contagious Interview” or “Famous Chollima,” confirming the ongoing use of Astrill VPN in their operations.

The investigation revealed that the threat actors registered the domain “bybit-assessment[.]com” hours before the $1.4 billion ByBit cryptocurrency heist, using an email address previously linked to Lazarus Group activities.

Within the acquired logs, researchers identified 27 unique Astrill VPN IP addresses associated with test records created by Lazarus members during their infrastructure setup, further solidifying the group’s preference for this VPN service.

Sophisticated Obfuscation Techniques Uncovered

SecurityScorecard’s STRIKE team has mapped out the operational infrastructure used by the Lazarus Group, revealing a sophisticated network of Astrill VPN exit points and proxies designed to obscure traffic while managing command and control (C2) servers.

The team successfully traced connections through VPNs back to six distinct IP addresses in Pyongyang, North Korea.

The attackers employed a multi-layered obfuscation strategy, routing traffic from North Korean IP addresses through Astrill VPN endpoints, then through an intermediate proxy layer registered to a company in Russia, before finally reaching the C2 infrastructure hosted on servers attributed to Stark Industries.

According to Silent Push Report, this layered approach demonstrates the group’s advanced understanding of operational security and network management.

Ongoing Threat to Global Organizations

The use of Astrill VPN by North Korean IT workers posing as legitimate job candidates continues to pose a significant threat to organizations worldwide.

Google’s Mandiant reported in September 2024 that connections to remote management solutions used by these fake IT workers primarily originated from Astrill VPN IP addresses, likely from China or North Korea.

As the threat persists, cybersecurity firms are releasing updated lists of Astrill VPN IP addresses to help organizations enhance their security posture against this particular threat.

Spur.us, for instance, has made available a comprehensive list of approximately 2,400 IP addresses associated with Astrill VPN as of December 2024.

Organizations are advised to implement stringent background checks, including biometric verification, require on-camera interviews, and monitor for the use of AI-generated photos when hiring remote workers0978.

Additionally, security teams should remain vigilant for signs of remote access tools and connections originating from known VPN services, particularly those associated with high-risk regions.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...