Fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.
A new blog post from Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating “suspicions that they’ve hired North Korean nationals posing as legitimate workers.”
In recent years, operatives from the Democratic People’s Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government’s needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents “have significantly improved and increased their activity over the past few years.”
Moreover, these workers are skillful at their jobs and would otherwise fit into an enterprise IT environment.
The trend is alarming on multiple levels, as it involves an insider threat orchestrated by a well-resourced foreign government. And because these remote workers are hired like any other employee, they’re not conducting traditional data breaches or compromising accounts. Between this and the employees’ use of VPNs and proxy services to mask location, it can be challenging to detect this kind of fraud.
Huntress divided its blog across three sets of investigations: one in February involving the healthcare sector and two in August involving organizations in the financial services sector.
Three Investigations into DPRK IT Worker Fraud
In February, an Australian firm in the healthcare industry contacted Huntress under suspicions that three employees were North Korean workers impersonating Chinese individuals. The suspicion arose from the employees’ use of certain infrastructure, such as Astrill VPN, which has been tied to DPRK worker fraud in the past.
The security firm analyzed relevant logs, authentication efforts, and activity over the previous six months and discovered that the employees were also utilizing IPRoyal Proxy, an otherwise legitimate commercial proxy service provider, and the bulletproof hosting service WorkTitans B.V., “that appears to have been raided by the Fiscal Information and Investigation Service of the Netherlands (FIOD).”
One VPN or proxy service found on one user’s device would not be so anomalous in itself, due to the legitimate use cases for both, but as Minton and Maclachlan explained, “extensive VPN and proxy infrastructure usage across all three accounts deviated from typical end-user behavior, suggesting attempts to hide each individual’s real geolocations.”
Huntress also observed similarities between two of the employees’ passports suggesting they may have fraudulently been created by the same person, and Chinese electricity bills that had errors in the same exact places, including links to Arizona Public Service websites.
“Due to the various breadcrumbs potentially tying these accounts to DPRK-linked activity, we reported our findings to the partner organization and strongly recommended that they engage incident response services,” the blog post read.
In the first of two detailed August investigations, Huntress was alerted by a partner of a possible North Korean worker in the partner’s environment thanks to an alert from a third-party security vendor.
Upon analysis, Huntress discovered that the employee utilized a PiKVM device, which allows remote hardware-level control of a computer; these devices are uncommon in enterprise environments and have been tied to DPRK schemes in the past. The firm also identified the use of a profile photo that had been stolen and altered from a legitimate GitHub account.
“We provided our assessment to the impacted organization that the identity of this individual was questionable,” Minton and Maclachlan wrote. “Following our investigation, the partner confirmed their suspicions about the employee, citing their refusal to show the room they were in, and their reluctance to appear on camera.”
After that incident, Huntress Detection Engineering and Threat Hunting (DE&TH) proactively hunted DPRK worker fraud indicators and found another likely case at a separate partner. In this case, it was a sales and marketing employee onboarded two weeks prior.
Like the second instance, this employee was found to have connected PiKVM and Guermok USB devices, and Huntress further identified evidence that legitimate identity documents had been digitally altered to replace a real individual’s photograph with another person’s image. The company also found Chrome extensions used for translating English, recording audio and video, and assisting with English pronunciation; microphone and audio testing websites (commonly used by DPRK IT workers); and the public posting of Zoom meeting links to a code-sharing website.
Spotting Fake IT Workers
Huntress made a number of recommendations for organizations wary of IT worker fraud, or those suspicious an employee may be tied to a North Korean operation.
The vendor suggests setting alerts for PiKVM and Guermok devices, especially when both are used by a user account. Huntress also recommended looking out for Web services and browser extensions associated with screen, audio, and video recording, microphone testing, translation, and file sharing; employees sharing recurring meetings to public text-sharing websites; VPN and proxy infrastructure combined with unusual geography; the presence of anomalous identity-related activity, particularly outside regular working hours for sustained periods; and anomalous details surrounding identity documents.
“While fake identification documents can be very challenging to detect with the naked eye, looking at their metadata and giving extra attention to any which have been recently issued can surface anomalies that raise questions on how and where the photos were taken and if they were altered,” Minton and Maclachlan wrote. “Consider also requiring any identification documents for new employees to be notarized.”
The blog concluded by stressing that weeding out fraudulent workers begins at the interview stage and continues with rigorous background checks prior to onboarding. “When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”


