Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-impersonation-fraudstate-sponsored-espionageinsider-threat-incidentcritical-infrastructure-threat

North Korean Fraudulent Remote Employment Schemes Targeting US Architecture and Engineering Sectors

Updated 3mo agoFirst seen Oct 10, 20252 sources

North Korean operatives have expanded their fraudulent remote employment schemes beyond traditional IT and software development roles to include architectural and civil engineering positions within US companies. According to research by cybersecurity firm Kela, North Korean workers have been creating fake profiles, résumés, and even using stolen Social Security numbers to secure freelance jobs in architecture and structural engineering. These operatives have produced 2D architectural drawings and 3D CAD files for properties located in the United States, indicating direct involvement in sensitive infrastructure projects. The workers have also been observed advertising a wide range of architectural services and, in some cases, creating or using architectural stamps or seals to falsely certify that their designs comply with local building regulations. This activity represents a significant evolution in North Korea’s strategy to generate revenue for its regime, moving beyond IT and cryptocurrency projects to infiltrate new sectors. The scale of these operations is believed to be extensive, with thousands of North Korean digital laborers having previously earned billions for the regime through similar schemes in the tech industry. The new focus on architecture and civil engineering raises concerns about the potential exposure of sensitive infrastructure information and the risk of compromised building designs. US companies are being targeted through freelance platforms and remote work arrangements, making it difficult to verify the true identities and locations of these workers. The use of stolen or fabricated documentation further complicates detection and prevention efforts. Cybersecurity experts warn that these schemes not only provide financial support to North Korea’s authoritarian government but also pose risks to national security and critical infrastructure. The operatives’ ability to access and potentially manipulate architectural plans could have far-reaching consequences if exploited for malicious purposes. Organizations are advised to strengthen their vetting processes for remote workers, particularly in fields related to infrastructure and design. Enhanced background checks, verification of credentials, and monitoring for suspicious activity are recommended to mitigate the threat. The expansion of North Korea’s remote employment schemes into new professional domains underscores the regime’s adaptability and the ongoing need for vigilance among US businesses. This development highlights the intersection of cyber-enabled fraud, insider threats, and geopolitical risk in the modern workforce. The findings serve as a warning to companies across multiple sectors to remain alert to sophisticated social engineering and employment fraud tactics originating from state-sponsored actors.

Share:
North Korean Fraudulent Remote Employment Schemes Targeting US Architecture and Engineering Sectors
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Oct 10, 20259mo ago

Kela reports findings to the FBI and other law enforcement bodies

Cybersecurity firm Kela said it shared its findings on the suspected North Korean architecture and engineering fraud operation with the FBI and other law enforcement agencies. This marked an official escalation from research discovery to law enforcement notification.

Exposed files reveal US construction-related work tied to the network

Investigators identified exposed files linked to the suspected network that reportedly contained architectural drawings for US properties, persona materials, email spreadsheets, and communications with prospective customers. Researchers and outside experts said the activity may have led to real-world construction work and raised concerns about altered architect seals, fraud, safety, and possible access to critical infrastructure projects.

North Korean IT worker scheme expands into architecture and engineering fraud

Research reported by WIRED and Kela found that suspected North Korean digital laborers moved beyond remote software work and began posing as licensed architects and structural engineers to target US clients on freelance platforms. The operation allegedly used fake profiles, fabricated or stolen identities, false résumés, and Social Security numbers to offer services including CAD drawings, permit plans, structural analysis reports, and stamped construction documents.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
1 linked
Affected products
7 linked
GithubIosIphoneMicrosoft Entra IdGoogle DriveNeonIos
Organizations
8 linked
Warner Bros. DiscoveryAmazon Web ServicesKELADTEXWIREDMicrosoft CorporationGoogleCBC/Radio-Canada
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.