.png)
The DPRK's fraudulent IT-worker scheme has evolved from salary fraud into a demonstrated insider-access threat — and organizations that engage remote IT talent should treat identity verification as a security control, not solely an HR function.
The CRITICALSTART® Cyber Research Unit (CRU) is tracking the continued expansion of the Democratic People's Republic of Korea (DPRK) remote information technology (IT) worker scheme, in which operatives use fraudulent identities to secure remote employment at organizations worldwide and remit their earnings to fund the regime's weapons programs. On July 31, 2026, the Federal Bureau of Investigation (FBI), the U.S. Department of State, and partner agencies from more than a dozen countries issued a joint advisory describing the scheme's continued growth and its increasing reliance on artificial intelligence (AI) to forge documents and pass interviews. [1], [2]
The FBI separately disclosed that a DPRK operative had performed remote contract work inside a U.S. federal agency, and independent researchers have since documented the full operational cycle from inside a controlled company, showing that these operatives are not merely a hiring nuisance but a genuine insider threat with access to source code, credentials, and corporate infrastructure once placed. [3], [4], [6] Organizations that engage remote IT talent should treat identity verification and onboarding controls as a security control, not solely an HR function.
The DPRK has dispatched skilled IT workers abroad for years, with the United States and international partners issuing the first public advisories on the scheme in 2022 and 2023. [1] The Internet Crime Complaint Center (IC3) updated its guidance in January 2025 after observing operatives escalate from simple salary fraud to data extortion, in which discovered workers held stolen proprietary code and data hostage until victim companies paid a ransom. [5] The scheme's scale prompted the July 31, 2026 joint alert from the FBI, State Department, and international partners, which described operatives increasingly using AI throughout the application and employment lifecycle, from polishing resumes to real-time interview assistance. [1], [2]
At a July 28, 2026 conference in Washington, D.C., Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, disclosed that the FBI had identified a DPRK operative performing remote contract work inside an unnamed U.S. federal agency, indicating the scheme has reached beyond the private sector. [3], [4] Separately, independent researchers from BCA LTD, NorthScan, and ANY.RUN spent months posing as a fabricated decentralized finance (DeFi) startup to recruit and hire suspected operatives linked to Famous Chollima, a subgroup of the Lazarus Group. The engagement, published in August 2026, is assessed to be one of the most detailed public records of how these operatives behave once granted legitimate system access. [6]
The North Korean IT-worker threat relies on a combination of identity fraud, human facilitators, AI-enabled deception, remote-access infrastructure, and malware delivery. These thematic techniques illustrate how operatives combine social engineering with technical tradecraft across the employment lifecycle to obtain access, maintain a presence within victim environments, and conceal their true identity and location.
Operatives apply for positions using forged or stolen identity documents, often altered with AI image tools. In one documented case, a submitted driver's license carried metadata showing it had been processed with Google Gemini and carried a SynthID watermark, while a separate applicant submitted an authentic but stolen photograph of a real individual's license. [6]
U.S.-based facilitators knowingly or unknowingly support operatives by sitting for interviews, lending bank accounts to receive salary payments, and hosting company-issued laptops in "laptop farms" so the actual worker can log in remotely and appear to be working from a trusted jurisdiction. [1], [3], [4]
Operatives use live translation tools during video interviews, visible in documented cases as a slight lag or off-screen glances toward a second monitor, and browser-based AI assistants to complete technical assignments and interview questions in real time. [6] FBI officials have confirmed that AI is now used across the entire operative lifecycle, from resume generation through employment. [3], [4]
Once hired, operatives rely on commercial remote-desktop tools, including AnyDesk and Google Remote Desktop, and consistently route traffic through AstrillVPN to obscure their true location. Silent Push has tracked dozens of AstrillVPN exit nodes tied to Lazarus Group infrastructure since at least 2024, and the pattern persisted in the August 2026 investigation. [6], [8] Operatives commonly provision virtual private servers through providers such as Vultr and Gorilla Servers to stage tooling and proxy connections into victim environments. [6]
A related and inverse vector uses fake recruitment to target legitimate job seekers rather than to place operatives. In a campaign identified after a July 2026 compromise, a fabricated Web3 recruitment process led a candidate through a signed Microsoft ClickOnce installer that ultimately deployed a Rust-based information stealer and a Go-based remote access trojan with hidden virtual network computing (hVNC) capability, resulting in the theft of cryptocurrency and credentials across multiple platforms within about an hour of execution. [7] This confirms that recruitment-themed social engineering, in both directions, remains a reliable technique against organizations and individuals in the technology and cryptocurrency sectors.
The techniques below map common tactics observed in these operations, from obtaining valid accounts and conducting information gathering to concealing operator activity and masking the origin of network connections.
| ID | Name | Description |
|---|---|---|
| T1078 | Valid Accounts | Operatives obtain legitimate credentials and system access through fraudulently secured employment. |
| T1598 | Phishing for Information | Fraudulent recruiter and candidate personas are used to gather information or deliver payloads through the interview process. |
| T1219 | Remote Access Software | Commercial tools such as AnyDesk and Google Remote Desktop provide persistent access to victim environments. |
| T1090.002 | Proxy: External Proxy | AstrillVPN and leased virtual private servers obscure the true origin of operative connections. |
| T1564.006 | Hide Artifacts: Run Virtual Instance | Hidden VNC sessions allow operators to act on a compromised host without visible activity. |
The following indicators can help organizations identify potential North Korean IT-worker activity during recruitment, onboarding, and employment. Individual indicators may have legitimate explanations, but multiple inconsistencies should prompt additional verification.
A successful placement gives an operative legitimate, trusted access to source code, intellectual property, and internal decision-making processes for as long as the employment continues, which the August 2026 field investigation showed can include participation in code review and deployment workflows. [6] This creates exposure beyond salary fraud: discovered operatives have extorted employers by withholding proprietary code and data, and employers that unknowingly pay a sanctioned entity face potential regulatory exposure independent of any technical compromise. [5] Because the access is granted rather than exploited, conventional perimeter and vulnerability-focused defenses do not address this risk. Controls belong primarily in hiring, identity verification, and endpoint monitoring rather than in patching.
Organizations can reduce North Korean IT-worker risk by applying controls at three points in the hiring process: before the interview, during the interview, and after the interview. The objective is to establish that the candidate is who they claim to be, prevent third-party facilitation, and limit enterprise exposure if a fraudulent candidate progresses through the hiring process. To mitigate risks associated with North Korean IT workers, we recommend the following prioritized strategies:
These controls should be limited to identity assurance, fraud prevention, and protection of company systems, rather than becoming a general employee-surveillance program. Organizations should collect only the information necessary for these purposes and avoid unnecessary GPS tracking, webcam or microphone monitoring, inspection of personal devices, access to personal communications, or investigation of unrelated personal activity. Deepfake detection, biometric analysis, identity discrepancies, and unusual network activity should be treated as risk indicators requiring corroboration, not definitive evidence of fraud. Where automated identity or media-analysis tools are used, organizations should incorporate human review and account for privacy risks, false positives, and limitations in detection technology.
The DPRK remote IT worker scheme has moved from a salary-fraud concern to a demonstrated insider access risk, confirmed both by federal disclosure of a compromised government contract and by independent researchers who documented the full operational cycle from inside a controlled company. Organizations that engage remote IT talent should treat identity verification with the same rigor applied to technical vetting and should review the red flag indicators and recommended actions in this advisory against their current hiring and onboarding process.
Visit Critical Start's Resources page for threat research articles, advisories, and to download the Critical Start H2 Threat Landscape Report. Also, sign up for our upcoming webinar on the H1 2026 Threat Landscape and get early access to the report.
This advisory was written using the best intelligence available at the time and is subject to change as additional information becomes available.
