lang icon En
March 6, 2025, 3:05 p.m.
1538

Fraudulent North Korean IT Workers Creating Fake GitHub Personas

Brief news summary

A North Korean fraud network is exploiting GitHub to create fake identities for remote IT jobs in the US and Japan, according to threat monitoring firm Nisos. This group hijacks legitimate GitHub accounts, falsely asserting to operate from Asia while fabricating links to small companies. Their tactics are reminiscent of past North Korean cyber activities, involving inflated claims of technical skills, multiple fabricated job profiles, and manipulated images. Nisos has identified six people connected to this scheme; two are currently employed while the others are seeking remote roles. Warning signs include exaggerated credentials in application and blockchain development, as well as profiles lacking authentic social media footprints. Notably, individuals impersonating Huy Diep of Tenpct Inc. and Naoyuki Tanaka from Enver Studio share the same Telegram handle, suggesting a coordinated effort. Nisos warns that these operatives are creating false identities on GitHub, potentially generating substantial financial gains for the North Korean regime.

A network of fraudulent North Korean IT workers has been generating fictitious personas on GitHub to secure remote engineering and full-stack blockchain developer roles in the United States and Japan, according to a report by threat monitoring firm Nisos. These GitHub personas utilize established accounts and portfolio content, claiming to be located in Asia, with some appearing to hold positions at small companies. The network adopts the same tactics, techniques, and procedures (TTPs) historically associated with North Korean fake IT operatives, which include fabricating experience claims, creating accounts on various job platforms, digitally altered photographs, and using identical email addresses across multiple personas. Investigations into the shared GitHub and contact information uncovered six personas affiliated with this network, comprising two who seem to be currently employed and four seeking remote positions in Japan and the US, as detailed in Nisos's recent report (PDF). Indicators of suspicious activity linked to these personas include exaggerated experience in application development and blockchain technology, proficiency in numerous programming languages, and the presence of accounts on job, software, messaging, and freelance platforms, but none on social media. Among the identified personas, Nisos highlights Huy Diep (HuiGia Diep), seemingly a software engineer at the Japanese consulting firm Tenpct Inc since September 2023, and Naoyuki Tanaka, reportedly a full-stack and blockchain engineer at the video game developer Enver Studio since November 2021. These two individuals are connected by the Telegram username 'superbluestar', which appears on both their resumes. This same username, along with the GitHub account 'superbluestar', was also found in the resume of a third persona, Shaorun Zhang. Shaorun Zhang's GitHub repository was shared with another persona, Kamaal Sultan, which used an email address also linked to the 'superbluestar' account, and which was at one time modified by a third GitHub account, 'superredstar'. Nisos also associates Huy Diep with a username tied to another persona, Alvaro Morales, and Naoyuki Tanaka with the Karl Chong persona, as both listed work with Enver Studio in their portfolios. Additionally, multiple GitHub users involved with the Karl Chong persona also contributed to another persona, Yoshiro Morino. "Nisos assesses that DPRK-affiliated IT workers likely utilize GitHub to create new identities and support them with established content.

GitHub activity has shown various accounts importing, altering, and generating new persona resumes, " the threat monitoring firm states. It is believed that North Korea has dispatched thousands of IT workers across various nations globally, potentially generating tens of millions of dollars for the Pyongyang regime. Related: Freelance Software Developers in North Korean Malware Crosshairs Related: North Korean Fake IT Workers More Aggressively Extorting Enterprises Related: US Charges Five Individuals Over North Korean IT Worker Scheme


Watch video about

Fraudulent North Korean IT Workers Creating Fake GitHub Personas

Try our premium solution and start getting clients — at no cost to you

Content creator image

I'm your Content Creator.
Let’s make a post or video and publish it on any social media — ready?

Language

Hot news

April 4, 2026, 6:28 a.m.

Z.ai Goes Public on Hong Kong Stock Exchange

Z.ai, previously known as Zhipu AI, has reached a major milestone by becoming the first prominent large language model (LLM) company from China to be publicly listed on the Hong Kong Stock Exchange.

April 4, 2026, 6:15 a.m.

Gartner Predicts AI-Driven Sales Enablement Will …

A recent study by Gartner, Inc., a leading business and technology insights firm, reveals that sales organizations adopting AI-driven enablement functions are set to significantly speed up their sales processes.

April 4, 2026, 6:15 a.m.

Google Tests AI-Generated Headline Rewrites in Se…

Google has recently confirmed it is conducting a limited experimental test using artificial intelligence (AI) to generate rewritten headlines for traditional Search results.

April 4, 2026, 6:14 a.m.

Smmwiz.com Named the Cheapest SMM Panel for YouTu…

By 2026, demand for YouTube growth services has soared to unprecedented levels, with creators, influencers, agencies, and brands all actively seeking affordable and dependable solutions.

April 4, 2026, 6:11 a.m.

MKTNT | AI Marketing Intelligence Dashboard

MKTNT is an innovative AI marketing intelligence dashboard designed to deliver comprehensive real-time insights into the rapidly evolving fields of artificial intelligence and marketing.

April 3, 2026, 2:24 p.m.

Starcloud Raises $170 Million Series A to Build D…

Starcloud has raised $170 million in a Series A funding round, marking a major milestone in developing innovative space-based data infrastructure.

April 3, 2026, 2:19 p.m.

Results Driven Marketing Highlights AI Search Tre…

Results Driven Marketing® has published a comprehensive new overview examining the rapidly evolving artificial intelligence (AI) search trends poised to transform how clients discover local and service-based businesses by 2026.

All news

AI Company

Launch your AI-powered team to automate Marketing, Sales & Growth

AI Company welcome image

and get clients on autopilot — from social media and search engines. No ads needed

Begin getting your first leads today