DPRK operations
State-aligned activity targeting digital asset businesses — social engineering campaigns, tooling and delivery methods, and the laundering routes that follow.
Independent threat intelligence practice · Singapore
Pangolin Intelligence produces intelligence on the cyber threat actors operating in crypto — DPRK operations, organised cybercrime and large-scale fraud networks — covering how they operate, the infrastructure and tooling they use, and how stolen funds move.
We don't build tooling.
We produce the intelligence that goes into it.
Our work is used by threat intelligence platforms, security firms, exchanges, analytics providers and law enforcement. We also publish independent public-interest research.
State-aligned activity targeting digital asset businesses — social engineering campaigns, tooling and delivery methods, and the laundering routes that follow.
Social engineering at scale — support-desk impersonation, SIM swaps and account takeover — and the criminal service economy that supports them.
Industrialised investment and social engineering fraud, the infrastructure that sustains it, and the movement of proceeds through the wider ecosystem.
These are our principal areas of focus, not the limit of our coverage.
Research subscriptions and attribution datasets, licensed to threat intelligence platforms, analytics providers, exchanges and security teams.
Technical analysis and advisory for organisations, security firms and law firms.
Practical upskilling delivered directly to in-house analyst, security and compliance functions.
Pangolin works with organisations, security firms, platforms and law firms. We do not take instructions directly from private individuals and do not provide private investigation services.
We prioritise auditability: transparent assumptions, reproducible analysis, and reporting structured for internal governance, counsel review and external compliance needs.
We do not operate a cryptocurrency exchange or trading platform, provide custody or manage client assets, issue tokens/NFTs, operate DeFi protocols, or provide remittance/payment services. We also do not perform licensable cybersecurity services such as penetration testing or managed SOC monitoring. All services are technical, analytical and advisory in nature, focused on blockchain data analysis and threat intelligence.