🧵 New investigation: Beejern, an active Oklahoma LLC, appears linked to a suspected DPRK IT worker cluster first identified through GitHub activity
The case connects GitHub aliases, company records, Upwork activity, manipulated imagery, shared infrastructure, and external DPRK research corroboration
Using a security company as the example here. Yesterday:
*Lays off 80% of US based Sec staff*
*Replaces half with AI*
*Sends the other half of those jobs to India*
*DPRK IT Workers and fraudulent hires begin applying to the India roles*
Aaron Maupin of Augusta, my brother in christ you have to stop facilitating for DPRK. I used to live next to you, you're killing me, and you're also not good at this.
A Chinese woman just got arrested in Norway for allegedly setting up a secret satellite data receiver inside the Arctic Circle. The cover story was a legitimate Norwegian company. The target was polar orbit satellite data near one of Europe's most sensitive space facilities.
On May 7, 2026, Norway's domestic intelligence service PST arrested the suspect and searched two locations, one on Andøya island in northern Norway, home to Andøya Spaceport and a military weapons testing range, and one in Innlandet in southern Norway. A satellite receiver was seized and the operation shut down.
PST prosecutor Thomas Blom stated the operation was based on suspicion that a company registered in Norway was being used as a front for a Chinese state actor attempting to intercept downloads from polar orbit satellites. The data, he said, could "harm Norway's fundamental interests if it came into the hands of a foreign state." Several other people have also been charged in the same case.
Polar orbit satellites are particularly valuable for intelligence because they pass over Arctic and high-latitude regions repeatedly, capturing military, space, and infrastructure data that standard satellites miss. Andøya is not a random location. It sits inside the Arctic Circle and serves as a launch facility that is central to Europe's growing independent space ambitions.
Norway has consistently identified China as one of its primary espionage threats alongside Russia. The CCP's method here is consistent with its global pattern: register a legitimate local company, embed the operation inside it, and collect what would otherwise be inaccessible.
The receiver was seized. The network was not necessarily limited to one person.
#China #CCP #Espionage #Norway #Arctic #Satellite #NationalSecurity #Geopolitics #Space #Intelligence
🔎🇷🇺Inside Russia's elite Bauman University, a secret department trains the GRU's next-gen hackers, saboteurs & spies. Now, 2,000+ leaked docs expose how its graduates feed the units behind Russia's cyberattacks, election interference, and NATO sabotage. https://t.co/5TTRIaWZj7
Here's your Aaron and David. Per partner, David switched to recruitment schemes recently and told on himself to Fortune. We didnt start tracking him til 2023.
@browsercookies@Narcass3
https://t.co/NAkb2gfEY0
https://t.co/TAFCqxLFBc
@Mandiant PS, David Ye also goes by David Rose.
He uses a US facilitator in Minnesota to host his laptops.
He uses the identity of a college grad in Texas who also stands-in to complete identity checks on his behalf for money.
Enjoy!
@aptwhatnow#dprk
@tayvano_ Bunch of fucking losers in the comments on this post. North Korea is stealing money through crypto and ITW, conducting ransomware attacks against hospitals and schools, and exfiltrating defense industry data used in the wars in both Ukraine and Iran.
Not all ITW can be DPRK APT operators but all APT operators can or have been ITW.
It's a blended attrib nightmare so... I dunno keep that in mind or something *falls off soapbox*
1. This isn't new news this is the updates on the partial information from a while back. The more important thing here and an overlooked topic I feel across the board is ...
...some have privileges and they can even request to mgmt to hack an employer. Others are aligned to APTs and operate with them or provide access to them. Numerous times seeing an APT and wondering the initial threat vector then seeing an ITW nearby all...
I've created a Giveth project and applied for the Ethereum Security QF round - funding independent DPRK threat research, IT worker notifications, and public investigations. If you've found my work useful, consider donating or sharing. 🦝 https://t.co/CewN8WQ4i4