The Threat of North Korean IT Workers

Gerard Chukwu, CTI AI Technologist
TLP Clear // CS-SA-26-0801

The DPRK's fraudulent IT-worker scheme has evolved from salary fraud into a demonstrated insider-access threat — and organizations that engage remote IT talent should treat identity verification as a security control, not solely an HR function.

Executive Summary

The CRITICALSTART® Cyber Research Unit (CRU) is tracking the continued expansion of the Democratic People's Republic of Korea (DPRK) remote information technology (IT) worker scheme, in which operatives use fraudulent identities to secure remote employment at organizations worldwide and remit their earnings to fund the regime's weapons programs. On July 31, 2026, the Federal Bureau of Investigation (FBI), the U.S. Department of State, and partner agencies from more than a dozen countries issued a joint advisory describing the scheme's continued growth and its increasing reliance on artificial intelligence (AI) to forge documents and pass interviews. [1], [2]

The FBI separately disclosed that a DPRK operative had performed remote contract work inside a U.S. federal agency, and independent researchers have since documented the full operational cycle from inside a controlled company, showing that these operatives are not merely a hiring nuisance but a genuine insider threat with access to source code, credentials, and corporate infrastructure once placed. [3], [4], [6] Organizations that engage remote IT talent should treat identity verification and onboarding controls as a security control, not solely an HR function.

Introduction

The DPRK has dispatched skilled IT workers abroad for years, with the United States and international partners issuing the first public advisories on the scheme in 2022 and 2023. [1] The Internet Crime Complaint Center (IC3) updated its guidance in January 2025 after observing operatives escalate from simple salary fraud to data extortion, in which discovered workers held stolen proprietary code and data hostage until victim companies paid a ransom. [5] The scheme's scale prompted the July 31, 2026 joint alert from the FBI, State Department, and international partners, which described operatives increasingly using AI throughout the application and employment lifecycle, from polishing resumes to real-time interview assistance. [1], [2]

At a July 28, 2026 conference in Washington, D.C., Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, disclosed that the FBI had identified a DPRK operative performing remote contract work inside an unnamed U.S. federal agency, indicating the scheme has reached beyond the private sector. [3], [4] Separately, independent researchers from BCA LTD, NorthScan, and ANY.RUN spent months posing as a fabricated decentralized finance (DeFi) startup to recruit and hire suspected operatives linked to Famous Chollima, a subgroup of the Lazarus Group. The engagement, published in August 2026, is assessed to be one of the most detailed public records of how these operatives behave once granted legitimate system access. [6]

Tactics and Techniques

The North Korean IT-worker threat relies on a combination of identity fraud, human facilitators, AI-enabled deception, remote-access infrastructure, and malware delivery. These thematic techniques illustrate how operatives combine social engineering with technical tradecraft across the employment lifecycle to obtain access, maintain a presence within victim environments, and conceal their true identity and location.

Identity Fraud and Facilitator Networks

Operatives apply for positions using forged or stolen identity documents, often altered with AI image tools. In one documented case, a submitted driver's license carried metadata showing it had been processed with Google Gemini and carried a SynthID watermark, while a separate applicant submitted an authentic but stolen photograph of a real individual's license. [6]

U.S.-based facilitators knowingly or unknowingly support operatives by sitting for interviews, lending bank accounts to receive salary payments, and hosting company-issued laptops in "laptop farms" so the actual worker can log in remotely and appear to be working from a trusted jurisdiction. [1], [3], [4]

AI-Enabled Operations

Operatives use live translation tools during video interviews, visible in documented cases as a slight lag or off-screen glances toward a second monitor, and browser-based AI assistants to complete technical assignments and interview questions in real time. [6] FBI officials have confirmed that AI is now used across the entire operative lifecycle, from resume generation through employment. [3], [4]

Remote Access and Supporting Infrastructure

Once hired, operatives rely on commercial remote-desktop tools, including AnyDesk and Google Remote Desktop, and consistently route traffic through AstrillVPN to obscure their true location. Silent Push has tracked dozens of AstrillVPN exit nodes tied to Lazarus Group infrastructure since at least 2024, and the pattern persisted in the August 2026 investigation. [6], [8] Operatives commonly provision virtual private servers through providers such as Vultr and Gorilla Servers to stage tooling and proxy connections into victim environments. [6]

Malware Delivery Through Fraudulent Recruitment

A related and inverse vector uses fake recruitment to target legitimate job seekers rather than to place operatives. In a campaign identified after a July 2026 compromise, a fabricated Web3 recruitment process led a candidate through a signed Microsoft ClickOnce installer that ultimately deployed a Rust-based information stealer and a Go-based remote access trojan with hidden virtual network computing (hVNC) capability, resulting in the theft of cryptocurrency and credentials across multiple platforms within about an hour of execution. [7] This confirms that recruitment-themed social engineering, in both directions, remains a reliable technique against organizations and individuals in the technology and cryptocurrency sectors.

MITRE ATT&CK Technique Mapping

The techniques below map common tactics observed in these operations, from obtaining valid accounts and conducting information gathering to concealing operator activity and masking the origin of network connections.

IDNameDescription
T1078Valid AccountsOperatives obtain legitimate credentials and system access through fraudulently secured employment.
T1598Phishing for InformationFraudulent recruiter and candidate personas are used to gather information or deliver payloads through the interview process.
T1219Remote Access SoftwareCommercial tools such as AnyDesk and Google Remote Desktop provide persistent access to victim environments.
T1090.002Proxy: External ProxyAstrillVPN and leased virtual private servers obscure the true origin of operative connections.
T1564.006Hide Artifacts: Run Virtual InstanceHidden VNC sessions allow operators to act on a compromised host without visible activity.

Red Flag Indicators

The following indicators can help organizations identify potential North Korean IT-worker activity during recruitment, onboarding, and employment. Individual indicators may have legitimate explanations, but multiple inconsistencies should prompt additional verification.

  • Payment preferences: Refusal of direct deposit; requests for cryptocurrency, money-transfer services, or payment to a third-party account.
  • Interview behavior: Video or audio lag consistent with live translation tools; reluctance to enable video; or an inconsistent match between voice and appearance.
  • Identity documents: Address, bank institution, and identification-issuing state do not align; or image metadata indicates AI editing tools.
  • Logistics requests: Requests to ship company equipment to an address other than the employee's stated residence.
  • Technical history: Sparse or inconsistent portfolio, GitHub, or professional history relative to the claimed experience level.

Implications for Organizations

A successful placement gives an operative legitimate, trusted access to source code, intellectual property, and internal decision-making processes for as long as the employment continues, which the August 2026 field investigation showed can include participation in code review and deployment workflows. [6] This creates exposure beyond salary fraud: discovered operatives have extorted employers by withholding proprietary code and data, and employers that unknowingly pay a sanctioned entity face potential regulatory exposure independent of any technical compromise. [5] Because the access is granted rather than exploited, conventional perimeter and vulnerability-focused defenses do not address this risk. Controls belong primarily in hiring, identity verification, and endpoint monitoring rather than in patching.

Passing a technical interview and producing working code does not confirm an applicant's identity. Identity verification and technical competence are separate controls and must both be satisfied before granting system access.

Phased Mitigation Strategies

Organizations can reduce North Korean IT-worker risk by applying controls at three points in the hiring process: before the interview, during the interview, and after the interview. The objective is to establish that the candidate is who they claim to be, prevent third-party facilitation, and limit enterprise exposure if a fraudulent candidate progresses through the hiring process. To mitigate risks associated with North Korean IT workers, we recommend the following prioritized strategies:

Before the Interview

  • Independently verify candidate information. Validate employment history, professional references, education where relevant, contact information, and other material identity attributes using sources independent of the information provided by the candidate.
  • Examine identity documents for inconsistencies. Check submitted identification for mismatched addresses, issuing authorities, photographs, formatting, or other anomalies. Where appropriate, examine document metadata and signs of digital manipulation, including evidence of AI-assisted editing.
  • Establish the expected interview process in advance. Use a standardized process that requires the candidate to appear on camera and prohibits substitution by another individual. Avoid relying exclusively on asynchronous video or written technical assessments.
  • Identify high-risk positions. Roles involving source code, production infrastructure, credentials, financial systems, or sensitive information should receive stronger identity-proofing and access controls before employment begins.

During the Interview

  • Require a live, camera-on interaction. The interviewer should confirm that the person appearing on camera matches the submitted identity documentation and remains visible throughout the interaction. The FBI has specifically identified face-swapping and other identity deception techniques in North Korean IT-worker activity.
  • Use unpredictable liveness checks. Ask the candidate to perform a simple, spontaneous action, such as turning their head, moving a hand across their face, or holding a specified object next to their face while answering an unexpected question. These challenges can help expose prerecorded video, face-swapping, and other forms of manipulated media. NIST recommends randomized human-in-the-loop cues as part of remote identity proofing.
  • Watch for manipulation indicators. Interviewers should note unusual audio-video synchronization, facial movement, lighting, image quality, virtual-camera indicators, unexplained latency, or behavior suggesting the candidate is receiving assistance from another person or system. These observations should be treated as indicators for additional verification, not proof of deception.
  • Test claimed expertise interactively. Ask follow-up questions about the candidate's submitted work and require them to explain or modify technical concepts in real time. The goal is to establish that the person being interviewed has the claimed experience, rather than simply assessing whether they can produce a correct answer.
  • Compare across interactions. Where multiple interviews occur, compare the candidate's appearance, voice, background, technical history, and answers for material inconsistencies.

Post-Interview

  • Control equipment delivery. Ship company equipment only to a verified employee address or approved company location. Escalate requests involving third-party residences, mail-forwarding services, or another person receiving the equipment. U.S.-based facilitators have been documented receiving laptops for North Korean IT workers.
  • Restrict initial access. Apply least privilege until identity and onboarding requirements are complete. Newly hired personnel should not receive immediate, unrestricted access to production systems, sensitive repositories, credentials, or financial systems.
  • Monitor the company endpoint for third-party operation. Once a device is issued, monitor company-managed endpoints for unauthorized remote-access software, VNC, virtual cameras, remote desktop services, and other mechanisms that could allow someone other than the employee to operate the device.
  • Monitor enterprise authentication for anomalies. Alert on unusual combinations of account, device, network, and authentication activity, including simultaneous sessions from geographically inconsistent networks or unexpected VPN and proxy infrastructure. This should rely on existing enterprise security telemetry rather than continuous tracking of an employee's physical location.
  • Re-verify when circumstances change. Repeat identity verification when there are material changes to the employee's address, payment arrangements, equipment location, staffing relationship, or access requirements.

Privacy and Proportionality

These controls should be limited to identity assurance, fraud prevention, and protection of company systems, rather than becoming a general employee-surveillance program. Organizations should collect only the information necessary for these purposes and avoid unnecessary GPS tracking, webcam or microphone monitoring, inspection of personal devices, access to personal communications, or investigation of unrelated personal activity. Deepfake detection, biometric analysis, identity discrepancies, and unusual network activity should be treated as risk indicators requiring corroboration, not definitive evidence of fraud. Where automated identity or media-analysis tools are used, organizations should incorporate human review and account for privacy risks, false positives, and limitations in detection technology.

Conclusion

The DPRK remote IT worker scheme has moved from a salary-fraud concern to a demonstrated insider access risk, confirmed both by federal disclosure of a compromised government contract and by independent researchers who documented the full operational cycle from inside a controlled company. Organizations that engage remote IT talent should treat identity verification with the same rigor applied to technical vetting and should review the red flag indicators and recommended actions in this advisory against their current hiring and onboarding process.

Visit Critical Start's Resources page for threat research articles, advisories, and to download the Critical Start H2 Threat Landscape Report. Also, sign up for our upcoming webinar on the H1 2026 Threat Landscape and get early access to the report.

This advisory was written using the best intelligence available at the time and is subject to change as additional information becomes available.

Further Reading

  1. Federal Bureau of Investigation. "North Korean IT Worker Threats to U.S. Businesses." fbi.gov, updated January 27, 2026.
  2. U.S. Department of State. "Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers." state.gov, July 31, 2026.
  3. Federal News Network. "FBI investigating North Korean remote IT staffer working for US agency." federalnewsnetwork.com, August 2026.
  4. TheStreet. "FBI finds North Korean IT worker inside federal agency." thestreet.com, August 17, 2026.
  5. Internet Crime Complaint Center (IC3). "North Korean IT Workers Conducting Data Extortion." PSA250123, January 23, 2025.
  6. Eldritch, M., and García Pérez, H. "Smile, You're on Camera! Part 2: Lazarus IT Workers Exposed." ANY.RUN Cybersecurity Blog, August 10, 2026.
  7. Dutta, T. S. "Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT." Cyber Security News, August 17, 2026.
  8. Dutta, T. S. "North Korean IT Workers Using Astrill VPN To Hide Their IPs." Cyber Security News, March 3, 2025.