A Growing Threat: North Korean Operatives Pose as IT Workers, Steal Sensitive Data
North Korean operatives are increasingly posing as IT workers to infiltrate organizations, steal sensitive data, and send funds back to the regime. According to a recent report from Huntress, these fake employees have improved their tactics, making it challenging for companies to detect them before they cause damage.
The threat is not new, but its sophistication has increased significantly over the past few years. Operatives from the Democratic People’s Republic of Korea (DPRK) use fake or stolen identities to get hired at various organizations, often through remote work arrangements. Once inside, they send their wages back to North Korea and may plant malware or steal sensitive data, depending on the government’s needs.
The trend is alarming because it involves an insider threat orchestrated by a well-resourced foreign government. These employees are skilled in their jobs and would fit seamlessly into an enterprise IT environment if not for their suspicious behavior. The fact that they use VPNs and proxy services to mask their location makes detection even more difficult.
Huntress conducted three investigations into this type of fraud, including one in February involving a healthcare sector organization and two in August involving companies in the financial services sector. In each case, the company suspected that some employees were North Korean workers impersonating Chinese individuals.
In one investigation, Huntress analyzed logs, authentication efforts, and activity over six months for three employees who used VPNs and proxy services extensively to hide their real geolocations. The security firm discovered that these employees also utilized a legitimate commercial proxy service provider and a bulletproof hosting service that had been linked to DPRK worker fraud in the past.
The investigation revealed several red flags, including similarities between two of the employees’ passports suggesting they may have been fraudulently created by the same person. Additionally, Chinese electricity bills with identical errors and links to Arizona Public Service websites raised suspicions about their authenticity.
Huntress also identified a pattern of behavior involving PiKVM devices, which allow remote hardware-level control of computers and are commonly used in DPRK schemes. In another investigation, the firm discovered that an employee’s profile photo had been stolen and altered from a legitimate GitHub account.
The investigations demonstrate that while these operatives have become more skilled at their jobs, there are still ways to detect them before they cause harm. Organizations can learn from these cases by paying attention to suspicious behavior, such as excessive use of VPNs or proxy services, and verifying the authenticity of employee documents and online profiles.
As remote work continues to grow, companies must remain vigilant about protecting themselves against insider threats like this one. By being aware of the tactics used by North Korean operatives and taking proactive measures to detect suspicious activity, organizations can reduce their risk of falling victim to these types of attacks.
Source: Dark Reading — 2026-08-26