Executive Summary
DPRK reporting last week connected fraudulent employment, developer compromise, and cryptocurrency theft more tightly than before. Investigations into Beejern and THORSwap traced suspected IT worker activity through front companies, developer identities, repository access, and merged wallet-integration changes. A separate account-rental approach showed how remote access to a local laptop can defeat hiring-platform controls.