North Korean Operatives Pose as IT Workers, But Red Flags Can Expose Them
A growing trend of North Korean operatives posing as IT workers has been making headlines in recent years, with the latest reports suggesting that these agents have significantly improved and increased their activity. These fake workers infiltrate organizations by using stolen or fake identities, often through remote work arrangements, and can potentially plant malware or steal sensitive data on behalf of the North Korean regime.
The problem is alarming because it involves an insider threat orchestrated by a well-resourced foreign government. What’s more, these remote workers blend in seamlessly with their legitimate colleagues, making them difficult to detect. They use VPNs and proxy services to mask their location, just like any other employee working remotely. This makes it challenging for organizations to identify and expose the fake workers before they cause harm.
Researchers at Huntress have been investigating this trend and have identified several red flags that can help organizations spot these fake workers. In a recent blog post, the security firm shared three detailed investigations into DPRK IT worker fraud. One of the cases involved an Australian healthcare company that suspected three employees were North Korean workers impersonating Chinese individuals.
The investigation revealed that the employees used certain infrastructure, such as Astrill VPN and IPRoyal Proxy, which have been tied to DPRK worker fraud in the past. What’s more, they also utilized a bulletproof hosting service called WorkTitans B.V., which was previously raided by Dutch authorities. While using one VPN or proxy service might not be suspicious on its own, extensive use of these services across multiple accounts raised red flags.
Another investigation revealed similarities between two employees’ passports, suggesting that they may have been fraudulently created by the same person. Additionally, Chinese electricity bills with identical errors, including links to Arizona Public Service websites, were found on both employees’ devices. These findings strongly suggested that the individuals were not who they claimed to be.
In another case, Huntress was alerted to a possible North Korean worker in a partner organization’s environment thanks to an alert from a third-party security vendor. Upon analysis, it was discovered that the employee used a PiKVM device, which allows remote hardware-level control of a computer and has been tied to DPRK schemes in the past. The firm also identified a profile photo that had been stolen and altered from a legitimate GitHub account.
The cases highlighted by Huntress demonstrate that while these fake workers are becoming increasingly sophisticated, there are still ways to expose them. Organizations can take several steps to protect themselves against this type of threat, including:
* Monitoring employee activity closely, particularly when it comes to VPN and proxy service usage
* Verifying the authenticity of employee documents and credentials
* Implementing robust authentication and access control measures
* Conducting regular background checks on new employees
By being vigilant and aware of these red flags, organizations can reduce the risk of falling victim to this type of insider threat.
Source: Dark Reading — 2026-08-26