North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring The Hacker News Aug 13, 2026 Cyber Espionage / Threat Intelligence Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access. When the Threat Gets Hired A recent joint investigation by Mauro Eldritch ( BCA LTD ), Heiner García ( NorthScan ), and ANY.RUN showed what this looks like from inside the operation. Researchers deliberately hired suspected DPRK developers linked to Lazarus Group and gave them what looked like ordinary virtual desktops. In reality, they were controlled ANY.RUN Sandboxes, capturing their activity in real time. The operation exposed forged identities, remote-access tools, AI-assisted workflows, and VPN and VPS infrastructure. See the full investigation on the ANY.RUN blog for the recorded interviews, live operator activity, infrastructure findings, and complete toolset breakdown. Check Investigation Details The Red Flags Start Before Day One The investigation showed that the strongest warning signs were often small inconsistencies across the hiring process rather than one obvious giveaway. Security and hiring teams should pay closer attention to: Identity details that don’t line up: addresses, states, documents, or banking information that contradict each other. Signs of document manipulation: unusual metadata, visual inconsistencies, or evidence that an ID has been altered with AI. Interview behavior that feels assisted: repeated off-screen glances, delayed responses, or dependence on live translation and AI tools. Location mismatches: network activity that does not match where the candidate claims to live or work. None of these signals proves malicious intent on its own. But when several appear together, they should trigger deeper verification before the candidate receives company access. How CISOs Can Keep a DPRK Operative Off the Payroll The Famous Chollima investigation showed that there is rarely one obvious sign that gives a fraudulent worker away. Instead, the clues appear across identity documents, interviews, location data, infrastructure, and activity after onboarding. Based on what researchers observed, here are several steps security leaders can take to make it much harder for a spy to get onto the company payroll. 1. Fully Verify the Person Behind the Documents A convincing identity document should not be the end of verification. The researchers encountered manipulated IDs, stolen identities, conflicting personal information, and financial details that did not always match the person being hired. For sensitive remote roles, CISOs should make sure identity checks use several independent signals. The candidate’s documents, location, interview behavior, employment history, and financial details should tell a consistent story before access is approved. Roles with access to source code, cloud infrastructure, production systems, or financial assets should receive a higher level of scrutiny from the start. 2. Give Security Teams a Safe Way to Validate Suspicious Activity The researchers used specially configured ANY.RUN Sandbox environments to observe the operatives' activity without exposing real corporate systems. This gave them visibility into the files they opened, tools they used, network connections they made, and other behavior that would have been difficult to assess from identity checks alone. CISOs can apply the same principle by making sure security teams have access to interactive sandboxes like ANY.RUN when suspicious files, links, scripts, or tools appear around employee activity. Instead of relying only on alerts or isolated indicators, teams can safely examine how the activity behaves and gather stronger evidence before deciding whether escalation or containment is necessary. This can help reduce uncertainty, speed up response, and lower the risk of suspicious activity reaching critical systems. 3. Check Whether the Same Infrastructure Appears in Your Environment The investigation uncovered specific infrastructure used by the suspected DPRK operatives. Security teams can cross-check these indicators against historical logs, EDR telemetry, proxy records, DNS data, and other security sources to see whether the same infrastructure has already appeared inside the organization. Examples from the investigation include: IPv4: 62[.]33[.]223[.]165 // INVESTSTROY-NET (InvestStroyTrest) IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node 0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd 0xA3D6938f152C47A411263573Bb3AF324C25A8eba 0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0 A match should not be treated as proof of DPRK activity on its own, but it can be a strong reason to look deeper when combined with other suspicious signals. With ANY.RUN’s Threat Intelligence Lookup , security teams can investigate indicators in more context, including related sandbox sessions, associated threats, and targeting patterns across countries and industries. This helps teams determine whether an unusual connection is isolated or part of a broader malicious pattern and prioritize the cases that need attention first. 4. Turn Investigation Findings into Ongoing Detection The researchers identified infrastructure used by the suspected DPRK operatives, including IP addresses, VPN endpoints, and VPS providers. For CISOs, the next step is making sure findings like these are not checked once and forgotten. They should become part of ongoing detection, so security teams can spot the same or related infrastructure if it appears elsewhere in the environment. ANY.RUN’s Threat Intelligence Feeds can support this by continuously supplying fresh indicators from real-world investigations to existing security tools. That turns intelligence from cases like this into earlier warning signs for future activity. Don’t Let a Fraudulent Hire Become a Trusted Insider North Korean remote-worker schemes show why hiring can no longer sit outside the security conversation. A candidate may pass interviews, present convincing documents, and receive legitimate access long before traditional security controls see anything suspicious. For CISOs, the priority is to reduce that gap: verify identity more deeply, give security teams the right solutions to validate suspicious activity, check known infrastructure against the environment, and turn confirmed findings into ongoing detection. Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE artificial intelligence , cyber espionage , endpoint security , Fraud , Identity Security , insider threat , Nation-State , network security , Remote Access , Threat Intelligence ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources See How to Stop the Browser-Based Attacks Your Existing Stack Misses [Book a Live Demo] [Webinar] See Where Claude Fits in the