Close Menu
NCIJ Network NCIJ Network
    What's Hot

    At least one dead after car crashes into crowd in northern France

    August 27, 2026

    Apple sets its iPhone 18 event for September: A new foldable and CEO could steal the show

    August 27, 2026

    Red Flags That Expose Fake North Korean IT Workers

    August 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • At least one dead after car crashes into crowd in northern France
    • Apple sets its iPhone 18 event for September: A new foldable and CEO could steal the show
    • Red Flags That Expose Fake North Korean IT Workers
    • Forget The Trump Bump, Bitcoin Would Be Fine Under Democrats: VanEck
    • One asteroid strike may explain two mysteries of Mars’ moon Deimos
    • Nepal flash flood live updates: more than 500 missing in Tibet, reports China, amid search for hundreds of tourists | Nepal
    • Das neue Machtzentrum der Koalition – POLITICO
    • Dating, delinquents and the power of second chances
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Red Flags That Expose Fake North Korean IT Workers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 27, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.

    A new blog post from Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating “suspicions that they’ve hired North Korean nationals posing as legitimate workers.”

    In recent years, operatives from the Democratic People’s Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government’s needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents “have significantly improved and increased their activity over the past few years.”

    Related:Ransomware Negotiator Pleads Guilty to BlackCat Scheme

    Moreover, these workers are skillful at their jobs and would otherwise fit into an enterprise IT environment.

    The trend is alarming on multiple levels, as it involves an insider threat orchestrated by a well-resourced foreign government. And because these remote workers are hired like any other employee, they’re not conducting traditional data breaches or compromising accounts. Between this and the employees’ use of VPNs and proxy services to mask location, it can be challenging to detect this kind of fraud.

    Huntress divided its blog across three sets of investigations: one in February involving the healthcare sector and two in August involving organizations in the financial services sector.

    Three Investigations into DPRK IT Worker Fraud

    In February, an Australian firm in the healthcare industry contacted Huntress under suspicions that three employees were North Korean workers impersonating Chinese individuals. The suspicion arose from the employees’ use of certain infrastructure, such as Astrill VPN, which has been tied to DPRK worker fraud in the past.

    The security firm analyzed relevant logs, authentication efforts, and activity over the previous six months and discovered that the employees were also utilizing IPRoyal Proxy, an otherwise legitimate commercial proxy service provider, and the bulletproof hosting service WorkTitans B.V., “that appears to have been raided by the Fiscal Information and Investigation Service of the Netherlands (FIOD).”

    One VPN or proxy service found on one user’s device would not be so anomalous in itself, due to the legitimate use cases for both, but as Minton and Maclachlan explained, “extensive VPN and proxy infrastructure usage across all three accounts deviated from typical end-user behavior, suggesting attempts to hide each individual’s real geolocations.”

    Huntress also observed similarities between two of the employees’ passports suggesting they may have fraudulently been created by the same person, and Chinese electricity bills that had errors in the same exact places, including links to Arizona Public Service websites.

    “Due to the various breadcrumbs potentially tying these accounts to DPRK-linked activity, we reported our findings to the partner organization and strongly recommended that they engage incident response services,” the blog post read.

    In the first of two detailed August investigations, Huntress was alerted by a partner of a possible North Korean worker in the partner’s environment thanks to an alert from a third-party security vendor.

    Upon analysis, Huntress discovered that the employee utilized a PiKVM device, which allows remote hardware-level control of a computer; these devices are uncommon in enterprise environments and have been tied to DPRK schemes in the past. The firm also identified the use of a profile photo that had been stolen and altered from a legitimate GitHub account.

    “We provided our assessment to the impacted organization that the identity of this individual was questionable,” Minton and Maclachlan wrote. “Following our investigation, the partner confirmed their suspicions about the employee, citing their refusal to show the room they were in, and their reluctance to appear on camera.”

    After that incident, Huntress Detection Engineering and Threat Hunting (DE&TH) proactively hunted DPRK worker fraud indicators and found another likely case at a separate partner. In this case, it was a sales and marketing employee onboarded two weeks prior.

    Like the second instance, this employee was found to have connected PiKVM and Guermok USB devices, and Huntress further identified evidence that legitimate identity documents had been digitally altered to replace a real individual’s photograph with another person’s image. The company also found Chrome extensions used for translating English, recording audio and video, and assisting with English pronunciation; microphone and audio testing websites (commonly used by DPRK IT workers); and the public posting of Zoom meeting links to a code-sharing website.

    Spotting Fake IT Workers

    Huntress made a number of recommendations for organizations wary of IT worker fraud, or those suspicious an employee may be tied to a North Korean operation.

    The vendor suggests setting alerts for PiKVM and Guermok devices, especially when both are used by a user account. Huntress also recommended looking out for Web services and browser extensions associated with screen, audio, and video recording, microphone testing, translation, and file sharing; employees sharing recurring meetings to public text-sharing websites; VPN and proxy infrastructure combined with unusual geography; the presence of anomalous identity-related activity, particularly outside regular working hours for sustained periods; and anomalous details surrounding identity documents.

    “While fake identification documents can be very challenging to detect with the naked eye, looking at their metadata and giving extra attention to any which have been recently issued can surface anomalies that raise questions on how and where the photos were taken and if they were altered,” Minton and Maclachlan wrote. “Consider also requiring any identification documents for new employees to be notarized.”

    The blog concluded by stressing that weeding out fraudulent workers begins at the interview stage and continues with rigorous background checks prior to onboarding. “When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”

    Expose Fake flags Korean North Red Workers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

    INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

    Critical Avada WordPress theme flaw enables zero-click RCE

    Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

    UK launches mini solar scheme … into a thicket of red tape – POLITICO

    Chrome 152 Patches Over 300 Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    At least one dead after car crashes into crowd in northern France

    August 27, 2026

    Apple sets its iPhone 18 event for September: A new foldable and CEO could steal the show

    August 27, 2026

    Red Flags That Expose Fake North Korean IT Workers

    August 27, 2026

    Forget The Trump Bump, Bitcoin Would Be Fine Under Democrats: VanEck

    August 27, 2026
    Latest Posts

    Andy Burnham wants to fix social care. It’s personal for him and for a lot of us too | John Crace

    July 29, 2026

    France orders Russian journalist Xenia Fedorova to leave country over alleged Kremlin propaganda

    July 29, 2026

    Russia-Ukraine War: The Wildberries Theory of Moscow’s Defeat

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    At least one dead after car crashes into crowd in northern France

    August 27, 2026

    Apple sets its iPhone 18 event for September: A new foldable and CEO could steal the show

    August 27, 2026

    Red Flags That Expose Fake North Korean IT Workers

    August 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.