The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses traditional security perimeters. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders.
Recent investigations highlight that this scheme is no longer limited to the private sector, posing a direct threat to government agencies.
Here’s how organizations can defend against this threat effectively.
The Escalating Risk of the DPRK Remote Worker Threat

The primary objective of the DPRK IT worker scheme operated by the Lazarus APT has historically been revenue generation, collectively earning hundreds of millions of dollars annually for the DPRK. However, the threat has escalated from financial fraud to a direct national security concern as these operatives penetrate the U.S. public sector.
The FBI is currently investigating a recent case where an unidentified U.S. federal agency unknowingly hired a North Korean remote IT worker. Last year, an individual who facilitated a North Korean national’s work on software development contracts for the Federal Aviation Administration (FAA) received a prison sentence. Such breaches grant unauthorized actors access to sensitive government systems and proprietary data.
The full lifecycle, tools, and operational methods of these infiltrators were exposed in a comprehensive two-part joint investigation conducted by BCA LTD, NorthScan, and ANY.RUN.
- In Part 1, researchers gained unprecedented access by posing as facilitators, deploying custom ANY.RUN sandbox environments disguised as developer laptops to record every click, command, and network connection executed by the operatives in real time.
- In Part 2, the team went a step further by establishing a simulated Web3 startup, tracking how Famous Chollima operatives collaborate, manage candidate pipelines, share infrastructure, and attempt to embed whole networks of “ghost developers” into target companies.
How DPRK IT worker scheme Operatives Hijack the Personnel Supply Chain
As demonstrated in the investigations, threat actors combine stolen identities and artificial intelligence to infiltrate organizations.
Watch the video on YouTube and read the full investigation
Security experts describe this phenomenon as a critical risk within the personnel supply chain. While companies traditionally focus on defending against external attackers, the North Korean IT worker fraud flips this model by getting hired.
A DPRK IT worker functions as a “Trojan horse,” obtaining legitimate credentials, access to internal networks, and corporate resources. This creates a unique insider threat:
- Persistent Access to Critical Infrastructure: Unlike traditional cyberattacks that are brief and noisy, an employee is expected to remain in the system, allowing months or years of continuous access to source code and intellectual property.
- Malicious Influence on Decision-Making: Once embedded, operatives can influence critical engineering decisions, review code, and approve pull requests, potentially introducing intentional vulnerabilities.
- Legitimate Cover: By maintaining a facade of productivity, operatives generate legitimate salaries while gathering intelligence and staging future cyberattacks.
Actionable Steps for SOCs to Detect North Korea Remote IT Workers Infiltration Early
Standard background checks, especially automated ones, are insufficient to ensure DPRK IT worker detection.
Defending against this requires SOC and recruitment teams to adopt a technical vetting model that treats hiring as an attack vector.
Spot Mass Outreach and GitHub Exploitation Tactics
The initial stage of the North Korean scheme often begins with wide-scale recruitment efforts targeting developers on platforms like Telegram and GitHub.

A highly specific tactic involves recruiters spamming GitHub repositories with fraudulent job offers. These messages are often delivered as pull requests directly on a developer’s own repositories, making them difficult to ignore.
Recruiters seek individuals who appear to have experience working with US companies, offering them “partnerships” where they can increase their income by attending interviews on behalf of the operative.
Eliminate Rogue Team Leads from the Hiring Process
Famous Chollima operations often rely on a key team lead (a “horse trader” or agency manager) who acts as the primary point of contact to build trust and scale their footprint inside targeted organizations:
- Beware of “Bring Your Own Team” Offers: A single lead will apply for or land a role, establish rapport with hiring managers, and then offer to recruit, manage, or refer additional developers. Under the guise of a turnkey contracting team, this facilitator brings in multiple North Korean operatives using fake or stolen identities.
- Enforce Direct, Individual Vetting: Never permit a single contractor, agency manager, or team lead to bypass individual KYC/background checks for their referred developers. Every individual applicant must undergo separate, direct identity verification and technical assessment.
Safely Triage Applicant Files and Links with a Sandbox
Your Security Operations Center (SOC) must actively participate in the vetting process by validating suspicious candidate deliverables before finalizing a hire.

Applicants routinely submit portfolios, code archives, or external links during technical assessments. Opening these directly on internal corporate workstations exposes the network to staging malware (such as OtterCookie, InvisibleFerret, and PyLangGhost RAT).
Integrating ANY.RUN’s Interactive Sandbox into the technical vetting and SOC triage and response workflows provides critical security value and operational efficiency:
- Uncover Evasive Phishing & Malware in under 60 seconds: Automated tools often miss stealthy malware that requires human interaction. ANY.RUN allows analysts to actively interact with the candidate’s files and URLs in real time, clicking links and triggering behaviors that reveal hidden payloads.
- Ensure Early-Stage Attack Vector Neutralization: Proactive analysis of suspicious objects sent by candidates enables SOC teams to identify malicious intent early and prevent threat actors from ever obtaining legitimate corporate credentials, company laptops, or access to sensitive infrastructure.
Inspect Applicant Documents for AI Artifacts and Forensic Inconsistencies
North Korean operatives frequently submit manipulated identity documents containing digital creation fingerprints.

Investigations show forged licenses often contain metadata proving processing via AI tools like Google Gemini, or feature embedded SynthID watermarks.

Analyze candidate data for geographic discrepancies (e.g., claiming residence in Texas while presenting a California driver’s license and a New York bank account). Forensic analysis often reveals stolen authentic photos re-used across multiple applications.
Monitor for AI-Assisted and Suspicious Live Behavior
Apart from North Korean IT worker AI-generated personas, operatives rely heavily on live translation and dynamic AI prompt generators.
Watch the video on YouTube and read the full investigation
Watch for off-screen glances, unusual delays before answering technical queries, or physical distractions. In recorded instances, operatives faked medical emergencies or prolonged coughing fits to avoid speaking when translation tools failed.
Trace Mule Accounts and Cryptocurrency Infrastructure
Salary exfiltration relies on complex networks of mule accounts, payment intermediaries, and digital wallets designed to route funds back to the DPRK.
Always verify that the account holder’s name on banking or crypto payment details matches the verified candidate’s identity. Operatives frequently request payroll transfers to third-party accounts, domestic facilitators, or mule accounts tied to stolen Social Security Numbers (SSNs) and completely different names.
To bypass traditional banking compliance and international sanctions, operatives push to receive compensation or transfer funds through non-custodial wallets or exchange wallets on platforms.
Analyze Network Markers: Proxies, VPNs, and Jump Boxes
To maintain the illusion of being local U.S. residents, North Korean IT worker tactics involve multi-layered networking designed to hide their origin.
During the BCA LTD, NorthScan, and ANY.RUN investigation, researchers successfully exposed operatives’ true locations by asking candidates to scan a QR code during a live interview to access a coding test. Embedded Canary Tokens silently recorded the candidates’ actual IP addresses, User-Agents, and geolocation data, completely bypassing active VPNs like AstrillVPN.
SOC and recruiting teams should closely monitor candidate connectivity and verify real network locations wherever possible:
- Track network telemetry, User-Agent strings, and IP locations during video calls, technical assignments, or onboarding tasks to flag proxies and VPN exit nodes.
- Enforce strict policies against commercial VPN services (e.g., AstrillVPN) commonly used by Famous Chollima operatives to spoof major U.S. exit nodes.
DPRK IT Worker IOCs
- IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS
- IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS
- IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS
- IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node
- IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node
- IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node
- IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node
- IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node
- 0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd
- 0xA3D6938f152C47A411263573Bb3AF324C25A8eba
- 0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0
Keep Defenses Updated with Fresh Threat Intelligence
While North Korean IT worker schemes primarily rely on identity fraud and social engineering, their operations heavily overlap with broader state-sponsored campaigns run by North Korean APT groups (such as Lazarus / Famous Chollima).
Threat actors routinely reuse command-and-control (C2) infrastructure, staging servers, malware delivery domains, and phishing URLs across both cyber espionage and remote worker infiltration schemes.
SOC analysts can collect context on indicators from alerts like URLs, file hashes, mutexes, or proactively gather actionable intel on active threats using ANY.RUN’s Threat Intelligence Lookup.
Powered by real-time telemetry contributed by over 16,000 organizations and 700,000 security professionals worldwide, TI Lookup instantly cross-references indicators against known Lazarus/Famous Chollima malware samples (such as BeaverTail or InvisibleFerret), phishing infrastructure, and active C2 servers.

For example, running a query like threatName:”lazarus” reveals numerous indicators belonging to the latest malware campaigns run by Lazarus like TigerRAT and others. SOC teams can use these indicators to enrich their defense systems to identify attacks early and prevent an incident.

Security teams can also ingest continuously updated Threat Intelligence Feeds directly into their SIEM, EDR, and perimeter firewalls. By feeding real-time network indicators (IPs, domains, URLs) gathered from global investigations directly into your security stack, your SOC can automatically block malicious connections and prevent unauthorized data exfiltration.
Conclusion
The North Korean IT worker scheme represents a unique hybrid threat, combining traditional human infiltration, social engineering, identity fraud, and software supply chain risk. Defensive strategies that focus strictly on traditional malware detection are insufficient when an attacker holds valid credentials, corporate devices, and a legitimate seat on your engineering team.
Protecting your organization requires aligning HR, recruiting, and SOC workflows. By enforcing strict identity verification, monitoring candidate connection telemetry, running interactive file/link sandboxing during technical assessments, and feeding real-time Threat Intelligence into your security stack, companies and government agencies can stop Famous Chollima operatives before they gain a permanent foothold.
About ANY.RUN
ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions, trusted by more than 16,000 organizations and over 700,000 security professionals worldwide.
Its Interactive Sandbox enables SOC teams, MSSPs, and threat researchers to analyze malware, suspicious files, URLs, and candidate deliverables in controlled, live virtual environments. By offering full behavioral visibility in under 60 seconds, ANY.RUN helps analysts observe execution chains, capture network traffic, and make fast, confident response decisions.
Additionally, ANY.RUN Threat Intelligence aggregates real-time indicators from global investigations. This allows security teams to enrich local SIEM/EDR alerts, uncover shared adversary infrastructure, and stay ahead of evolving APT tactics, phishing campaigns, and insider threat schemes.
Frequently Asked Questions (FAQ)
1. Why are North Korean IT workers targeting government agencies and corporate SOCs?
Beyond earning revenue for the DPRK, placing operatives inside corporate or public sector organizations grants long-term, persistent access to source code, intellectual property, and internal networks. Operatives can gather intelligence, manipulate software supply chains, and stage future cyberattacks without ever needing to exploit software vulnerabilities.
2. How do operatives bypass standard background checks and automated HR screening?
Operatives rely on stolen identities, rented Social Security Numbers (SSNs), synthetic personas created with AI tools like Google Gemini, and domestic facilitators who host “laptop farms”. Standard background checks confirm that the identity itself exists, but they often fail to verify whether the remote candidate behind the screen is actually the person named in the documents.
3. What is a “laptop farm” and how does it obscure the operative’s location?
A laptop farm is a physical setup managed by a domestic facilitator (often based in the U.S. or EU). Corporate equipment sent by the employer is delivered to the facilitator’s address. The facilitator connects the devices to local residential internet and grants the North Korean operative 24/7 remote desktop access (via AnyDesk, Google Remote Desktop, etc.). This makes all network connections appear to originate from a legitimate local residence.
4. How can a SOC safely inspect coding assignments, portfolios, or links sent by candidates?
Candidate deliverables should never be opened directly on corporate endpoints. Using an interactive environment like ANY.RUN Interactive Sandbox, SOC teams can open suspicious files, scripts, or URLs in a secure cloud container. Analysts can interactively test the submission, observe process trees, and monitor outbound network connections in real time without risking the internal network.
5. How does Threat Intelligence help detect North Korean operative schemes?
North Korean remote worker schemes heavily share infrastructure with state-sponsored APT groups like Lazarus (Famous Chollima). Operatives routinely reuse C2 servers, malware delivery domains, phishing links, and malicious code samples (such as BeaverTail or InvisibleFerret). Cross-referencing candidate links, domains, or infrastructure against ANY.RUN Threat Intelligence Lookup and Threat Intelligence Feeds allows SOC analysts to instantly spot overlaps with known DPRK cyber campaigns and block threats at the perimeter.