Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actioninsider-threat-incidentstate-sponsored-espionagetrade-export-control

North Korean Fake IT Worker Network Infiltrates Western Firms and Funds Pyongyang

Updated 21h agoFirst seen Mar 18, 202639 sources

U.S. authorities and multiple security firms detailed a large North Korean scheme in which operatives use stolen or fabricated identities to win remote IT jobs at Western companies, then send the earnings back to Pyongyang in violation of sanctions. Research from IBM X-Force, Flare, Microsoft, LevelBlue, and others described a mature ecosystem of recruiters, facilitators, brokers, laptop-farm operators, and Western collaborators that helps workers pass interviews, receive corporate devices, mask their locations with VPNs, and clear payroll and compliance checks. Estimates cited across the reporting say more than 100,000 workers operating across dozens of countries may be generating roughly $500 million annually, while some cases also involved data theft, source-code exfiltration, extortion, and malware activity after hiring.

The U.S. Treasury's Office of Foreign Assets Control sanctioned six individuals and two entities tied to the operation, while U.S. courts sentenced three Americans, including a former Army soldier, for helping North Korean workers use false identities and laptop farms to obtain jobs at U.S. companies. Investigations also exposed operational tradecraft including use of Astrill VPN, NetKey/OConnect, IP Messenger, freelance platforms, AI-generated resumes and headshots, and U.S.-based hardware relays such as PiKVM-enabled laptop farms; one hired worker was removed within 10 days after suspicious logins from China and Missouri triggered detection. Researchers and federal advisories warned that remote hiring has become an insider-threat and sanctions-compliance risk, urging tighter identity verification, live skills testing, device and geolocation controls, least-privilege access, and joint oversight by HR, recruiters, and security teams.

Share:
North Korean Fake IT Worker Network Infiltrates Western Firms and Funds Pyongyang
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

18 events from the most recent confirmed update back to the earliest known activity.

18 EVENTS
Jun 16, 20268d ago

Nisos exposes DPRK cell behind 170,000 fraudulent job applications

On 2026-06-16, Nisos published research assessing with high confidence that a DPRK state-sponsored cell ran an industrial-scale employment fraud operation targeting U.S. companies. The report said that between December 2024 and September 2025, 22 operatives submitted more than 170,000 applications and secured 76 job offers using stolen identities, AI-assisted interviews, U.S.-based facilitators, Astrill VPN, PiKVM devices, and cryptocurrency payments.

Exposing DPRK Employment Fraud Operations
Apr 10, 20263mo ago

Accidental infostealer infection exposes DPRK payment server data

Reporting on 2026-04-10 said a North Korean operator accidentally executed infostealing malware on their own computer, exposing data from an internal payment server including 390 accounts, chat logs, and cryptocurrency transaction records. Investigators said the leak revealed a scheme generating about $1 million per month and exposed weakly protected infrastructure tied to sanctioned DPRK-linked firms.

Hacker faux pas uncloaks North Korean IT worker scheme | brief | SC Media
Apr 8, 20263mo ago

ZachXBT publishes findings on DPRK IT worker payment infrastructure

On 2026-04-08, ZachXBT published findings about DPRK IT workers and their payment infrastructure after an infostealer compromise exposed internal communications through luckyguys[.]site. The leak provided visibility into a large-scale but relatively low-sophistication ecosystem supporting fraudulent remote IT work.

Inside the computers of DPRK IT workers - Infosec.Pub
Apr 7, 20263mo ago

North Korean facilitators begin recruiting Iranian IT workers

Flare researchers reported that much of the observed activity recruiting Iranian IT professionals into the DPRK remote IT worker fraud pipeline dated back to 2024. Internal documents showed recruiters targeting Iranians on LinkedIn and coaching them to obtain jobs under stolen or fabricated identities.

North Korea recruits Iranian workers for IT job fraud | news | SC Media
Mar 31, 20263mo ago

Researchers expose suspected DPRK applicant using AI-generated resume

Researchers reported that in June 2025 they exposed a suspected North Korean operative who tried to infiltrate a cybersecurity firm using a stolen identity and an AI-generated resume. Investigators linked the activity to a broader laptop farm operation using PiKVM and Tailscale for remote control.

New North Korean AI Hiring Scheme Targets US Companies
Mar 26, 20263mo ago

Researcher reports identity-rental offer from suspected DPRK hacker

By 2026-03-26, cybersecurity engineer Toufik Airane reported that a suspected North Korean hacker had approached him offering up to $70,000 per month to use his identity for remote job interviews in exchange for a share of the salary. Airane said he captured screenshots from a video call and linked the individual to prior security-firm identification.

North Korean hackers offer $70,000 per month to be their front - Radio Free Asia
Mar 23, 20263mo ago

Federal court sentences three Americans for aiding DPRK IT worker scheme

A federal court in the Southern District of Georgia sentenced Alexander Paul Travis, Jason Salazar, and Audricus Phagnasay for helping North Korean IT workers secure remote jobs at U.S. companies using false identities and laptop farms. The sentencing was announced in a DOJ press release on Friday and included prison, probation, and forfeiture orders.

US soldier, two accomplices sentenced for aiding North Korean IT schemes | NK News

Three Americans plead guilty in DPRK IT worker fraud case

According to DOJ information cited in reporting, Alexander Paul Travis, Jason Salazar, and Audricus Phagnasay pleaded guilty in November to wire fraud conspiracy for helping North Korean IT workers obtain remote jobs at U.S. companies using false identities.

US soldier, two accomplices sentenced for aiding North Korean IT schemes | NK News
Mar 18, 20263mo ago

Suspected DPRK worker hired for Salesforce role at Western company

In August 2025, a suspected North Korean operative obtained a remote IT job at a Western company and was given access to sensitive Salesforce data after passing standard hiring checks. The case was later cited by LevelBlue as part of the broader DPRK remote worker scheme.

OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs

Flare and IBM X-Force publish DPRK infiltrator threat research

On 2026-03-18, Flare Research and IBM X-Force published findings describing a mature, multi-tiered North Korean fake IT worker ecosystem using false identities, collaborators, and DPRK-linked infrastructure such as RB Site, NetkeyRegister, NetKey/OConnect, and IP Messenger. The research detailed how the scheme places workers into Western companies to generate revenue and sometimes enable theft or extortion.

North Korean's 100k fake IT workers net $500M a year for Kim • The Register
Mar 17, 20263mo ago

OFAC sanctions six people and two entities tied to DPRK IT worker scheme

In March 2026, the U.S. Treasury Department's Office of Foreign Assets Control sanctioned six individuals and two entities linked to North Korea's remote IT worker operation. The sanctions targeted a scheme using stolen identities, fake personas, and fraudulent documents to obtain jobs and funnel earnings back to the DPRK.

Your company's Slack chat is the new DMZ - The Korea Times
Aug 25, 202510mo ago

Company revokes suspected DPRK worker's access after anomaly detection

On 2025-08-25, the company terminated the suspected North Korean worker's access by revoking the employee's EntraID account after detecting suspicious login activity tied to China and an unmanaged device in St. Louis. The action ended the worker's access within 10 days of hiring.

North Korean Hacker Lands Remote IT Job, Caught After VPN Slip
Jan 23, 20251y ago

FBI warns DPRK IT workers are conducting data extortion

On 2025-01-23, the FBI issued updated guidance stating that North Korean IT workers were increasingly stealing proprietary information, exfiltrating code, and conducting data extortion against U.S.-based businesses. The notice also warned of AI and face-swapping use during interviews and urged stronger monitoring and hiring controls.

Internet Crime Complaint Center (IC3) | North Korean IT Workers Conducting Data Extortion
Nov 19, 20242y ago

FBI posts wanted notice for 14 DPRK IT worker suspects

On 2024-11-19, the FBI published a wanted notice naming 14 individuals allegedly involved in a DPRK IT worker conspiracy that generated and laundered revenue for North Korea. The notice said the State Department's Rewards for Justice program was offering up to $5 million for information disrupting related financial mechanisms and solicited public tips.

DPRK IT WORKERS - FBI
May 16, 20242y ago

FBI warns DPRK uses US-based facilitators in remote job fraud

On 2024-05-16, the FBI warned that North Korean IT workers were fraudulently obtaining remote jobs at U.S. companies with help from U.S.-based facilitators who handled laptops, internet access, financial accounts, and interviews. The notice recommended stronger identity verification and monitoring for unauthorized remote access.

Internet Crime Complaint Center (IC3) | Democratic People's Republic of Korea Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue
Oct 18, 20233y ago

US and South Korea issue updated DPRK IT worker advisory

On 2023-10-18, the United States and the Republic of Korea issued updated guidance on DPRK IT workers, adding new red flags such as suspicious interview behavior, mismatched online identities, and freight-forwarding addresses. The advisory warned of sanctions, theft, and reputational risks and recommended stronger due diligence and monitoring.

Internet Crime Complaint Center (IC3) | Additional Guidance on the Democratic People's Republic of Korea Information Technology Workers
May 8, 20233y ago

Investigation finds DPRK laptop farm using Raspberry Pi KVM devices

An investigation reported on 2023-05-08 found evidence that DPRK IT workers used Raspberry Pi-based KVM devices and mesh VPN technology to remotely access desktop systems in a laptop farm setup.

Our investigation of the laptop farm identified that DPRK IT workers leverage Raspberry Pi-based KVM (Keyboard-Video-Mouse) devices to remotely access desktops and mesh VPN - Infosec.Pub
May 16, 20224y ago

US agencies publish advisory on DPRK IT workers

On 2022-05-16, the U.S. Departments of State and Treasury, together with the FBI, published an advisory warning that DPRK IT workers were posing as non-DPRK nationals to obtain employment and evade sanctions. The advisory also outlined red flags and released related guidance for companies and platforms.

Publication of North Korea Information Technology Workers Advisory | Office of Foreign Assets Control
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

91 LINKEDOpen in app
Malware
2 linked
Affected products
17 linked
GithubLinkedinDiscordChatgptTailscaleTeamviewerMullvad VpnAnydeskZoomMicrosoft Entra IdVmware WorkstationJiraChatgptGoogle SearchGoogleGmailSharepoint
Organizations
66 linked
Amazon Web ServicesSentinelOneEnergy SolutionsFoundryEnergySolutionsInternational Business MachinesFlareGoogleLinkedinGitHubDiscordOpenaiAstrill VPNUpworkSalesforceC Digital LLCLevelBlueMicrosoft CorporationFlare ResearchAstrillTechSmith CorporationTailscaleThe RegisterAtlassianTeam CymruCybereasonDICEStarlinkDTEXCybernewsIndeedMullvadZoom CommunicationsToptalShopifyInformation Security Media GroupAppleBroadcomSC MediaAnyDesk Software GmbHHackread.comSlack TechnologiesProtonTeamviewerFiverreSecurityPlanetDjinniRadio Free AsiaFreelancerAmnokgang Technology Development CompanyQuangvietdnbg International Services Company LimitedWorkanaCybersecurity DiveJoobleBig Orange PlanetSmartRecruitersGuruBambooHRGlassdoorRemoteBaseCardinal StaffingSimplyHiredSaenalSobaeksuSongkwangNoxHunt
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

North Korean Fake IT Worker Network Infiltrates Western Firms and Funds Pyongyang | Mallory