A sophisticated network orchestrated by the Democratic People’s Republic of Korea (DPRK) has been uncovered, targeting remote tech job opportunities with Western organizations.
These operatives are masquerading as Polish and US nationals, infiltrating high-level positions such as blockchain developers and engineers. By securing these roles, they gain unauthorized access to critical Western corporate systems and financial infrastructures.
The network relies on meticulously crafted digital identities, featuring fake profile pictures, highly detailed portfolios, and well-maintained online presences across various platforms. The scope of the operation is not limited to independent contractors; it also includes a seemingly credible international software development company, “Inspiration With Digital Living” (IWDL).
This marks a notable shift in DPRK’s approach to employment fraud, as it represents the first instance of DPRK-linked workers establishing counterfeit companies with professional-grade websites to secure freelance contracts.
The operatives behind this scam carefully design their digital personas, often reusing the same profile across multiple accounts or superimposing faces onto stock images to create a convincing illusion.
Researchers at NISOS uncovered this scheme by analyzing patterns across interconnected GitHub accounts and portfolio sites. Their investigation revealed specific trends, such as consistent use of certain profile elements and the false portrayal of technical skills, which exposed the fraudulent network.
These tactics reflect an alarming rise in the sophistication of DPRK’s efforts to infiltrate Western tech firms. The fake developers primarily target remote positions, where in-person verification is minimal, allowing them to remain undetected for longer periods.
The financial impact of these scams is significant, as these high-paying roles often fund DPRK state initiatives. Furthermore, the access these positions provide to sensitive corporate systems presents serious cybersecurity risks that extend far beyond financial fraud.
This scheme is part of a broader DPRK strategy to exploit cyber channels for generating revenue and evading international sanctions, blending economic espionage with sanctions-busting activities.

The Saja GitHub network has been traced through multiple connections, revealing distinct patterns in its structure (Source – NISOS).
Among the network’s accounts, several prominently featured lion-themed avatars, with three of the eight most interconnected accounts specifically using lion imagery.
A recurring feature across numerous accounts and portfolio websites was the inclusion of the term “century” within email addresses, likely serving as an internal marker for network identification.
The design and content of the portfolio websites exhibited striking uniformity. Active sites hosted on platforms like GitHub.io and Vercel.app shared nearly identical “about” sections, each claiming over 10 years of experience, referencing a project called “Assistant for Freelancer,” and showcasing fake client testimonials.
Interestingly, these portfolios often featured work on a supposedly groundbreaking “Anti-Game-Cheat engine with a focus on AI,” yet no verifiable evidence of such a project’s existence could be found.

Impersonated Developer Profiles (Source – NISOS)
Analyzing the digital footprints left by these threat actors reveals key patterns that are critical for identification.
A telltale sign of their deception lies in the testimonial sections, where language inconsistencies are evident—often resembling the writing of non-native English speakers trying to replicate Western business communication norms. These irregularities serve as strong indicators of the profiles’ fraudulent origins.




