How To Detect North Korean Remote Workers Hiding Inside Your Company

2026-08-10 Kravensecurity

https://kravensecurity.com/north-korean-remote-workers

Thumbnail for How To Detect North Korean Remote Workers Hiding Inside Your Company

North Korean remote IT workers use stolen identities, fabricated GitHub histories, interview stand-ins, deepfake tools, domestic laptop farms, and hardware KVM devices to obtain trusted access to foreign companies. Microsoft and Secureworks track overlapping parts of the operation as Jasper Sleet and Nickel Tapestry, respectively, while OFAC assesses that the program raises substantial foreign currency for the DPRK regime. Some operators have escalated from collecting salaries to stealing proprietary data and demanding cryptocurrency ransoms. Recommended detections include repository-history analysis, applicant resume clustering, interview consistency checks, hardware-display telemetry, VPN and activity-faker monitoring, and correlation of device, login, and payroll geography.

Related Actors

Related Reports

« Back