ctipilot.ch

Bismarck

actor · actor:bismarck-dprk-cybercrime single-source

Kudelski Security's designation for a North Korea-linked actor connected via infrastructure reuse to a DPRK gambling-platform operation and the FakeCalls Android banking trojan; distinct from the registry's already-tracked PurpleDelta North Korean IT-worker cluster (Kudelski Security, 2026-08-12).

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1585.001Establish Accounts: Social Media Accounts×1

Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used to build a persona to further operations. Persona development consists of the development of public information, presence, history and appropriate affiliations.

Evidence: 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap · ATT&CK page ↗

T1586Compromise Accounts×1

Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating accounts (i.e. Establish Accounts), adversaries may compromise existing accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona.

Evidence: 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap · ATT&CK page ↗

Story timeline

  1. 2026-08-28Kudelski Security: North Korean IT-worker infrastructure overlaps a Bismarck-linked gambling-platform operation and the FakeCalls Android banking trojan
    active-threatsA Swiss research lab traces a stealer-log leak into DPRK gambling infrastructure and the fake-IT-worker university pipelines behind it

Where this entity is cited

  • active-threats1

Source distribution

  • kudelskisecurity.com1 (100%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Bismarck (1)

2026-08-28 · view entry permalink →

NOTABLENATOB2

Kudelski Security: North Korean IT-worker infrastructure overlaps a Bismarck-linked gambling-platform operation and the FakeCalls Android banking trojan

Kudelski Security, a Swiss research lab headquartered in Cheseaux-sur-Lausanne, reconstructs connections between North Korean state-linked cybercrime and fake-IT-worker operations via a stealer-log leak. An actor the researchers designate "Bismarck," linked to DPRK-run gambling platforms, reused infrastructure that overlaps with the FakeCalls Android banking trojan (previously documented by Check Point targeting South Korean banking customers via voice-phishing app impersonation): "we recently observed a stealer log leak involving an actor linked to the DPRK, nicknamed 'Bismarck.' The actor used two IP addresses that overlap with indicators of compromise (IOCs) documented by Check Point Research in its analysis of FakeCalls, an Android banking trojan targeting South Korea" (Kudelski Security, 2026-08-12). Kudelski assesses the infrastructure reuse most plausibly reflects that the gambling-operation domains were purchased by DPRK associates rather than by Bismarck directly.

Separately, a DPRK-affiliated manager's own WinSCP credential vault — stolen in a 2021 leak — held access to historical Emotet botnet loader infrastructure, and cross-referencing that infrastructure's later reuse ties it into a loader role for subsequent campaigns. The investigation names operational bases and identifies university-affiliated IT-worker pipelines at named North Korean technical universities, plus organisational entities supporting fake IT-worker placement across multiple countries — directly relevant tradecraft for this constituency's HR and identity-vetting teams screening remote-hire pipelines, where a DPRK IT worker's fabricated identity and credentials are the initial-access vector rather than a technical exploit.

Both actor:bismarck-dprk-cybercrime (new) and the already-tracked actor:purpledelta North Korean IT-worker cluster are referenced here; Kudelski's own article treats Bismarck as distinct from PurpleDelta rather than as an alias. actions[] is empty: this is a research/awareness finding for HR and identity-vetting process design rather than a technical exposure with a specific patch, hunt or block action; the transferable lesson belongs in the body's defender-facing framing rather than a do-now task list.

We recently observed a stealer log leak involving an actor linked to the DPRK, nicknamed "Bismarck." The actor used two IP addresses that overlap with indicators of compromise (IOCs) documented by Check Point Research in its analysis of FakeCalls, an Android banking trojan targeting South Korea.

We assess that DPRK actors may have reused IP addresses from the gambling operation because the domains were purchased by the associates rather than by [Bismarck directly].

Kudelski Security 2026-08-12
threat28 Aug 06:32Zsingle-sourceOpen finding ↗