The Invisible Army: Inside North Korea’s Organised IT Worker Scam
What if the freelance developer you hired wasn’t who they claimed to be—but part of a state-backed scheme stealing millions? This isn’t dystopian fiction. Recently leaked documents reveal how North Korean IT workers operate a sophisticated, corporate-like fraud network targeting global companies. Security researchers analyzed spreadsheets detailing job scams, worker inventories, and financial tracking for operations generating revenue for Pyongyang. With experts confirming the data’s authenticity, this exposure unveils an industrial-scale threat exploiting remote work—and demanding urgent cybersecurity attention.
The Anatomy of Deception: Inside the Leaked Spreadsheets
Target Acquisition: Job Hunting as Warfare
The spreadsheets resemble a sales CRM but track fraudulent job applications. One sheet, updated daily, lists:
- Job descriptions like “need a new React and Web3 developer”
- Companies and locations targeted
- Links to freelance platform vacancies or direct contact details
- Application status (e.g., “waiting” or “contact made”)
This systematized approach mirrors legitimate recruitment but fuels identity theft. Workers pose as non-North Korean freelancers, often using stolen identities, to infiltrate companies and siphon funds or steal data.
Resource Inventory: The IT Worker Arsenal
A chilling spreadsheet catalogs worker assets down to granular details:
- Real names of IT operatives
- Makes/models of computers and monitors
- Hard drive capacities and device serial numbers
Notably, the “master boss” used a 34-inch monitor with dual 500GB hard drives—highlighting the operation’s resources. This inventory enables workload allocation and minimizes digital footprints by matching tools to tasks, evading device-based red flags.
Table: Data Categories in Leaked North Korean Spreadsheets
| Spreadsheet Type | Key Data Points | Purpose |
|———————-|———————|————-|
| Job Targeting | Company names, job links, status updates | Identify/fraudulent applications |
| Worker Inventory | Operative names, device specs, serial numbers | Resource management, opsec |
| Financial Analysis | Project types, budgets, payment methods | Revenue optimization |
The Business of Fraud: Operations and Profit Tracking
One “analysis” sheet meticulously categorizes illicit work and revenue streams, revealing a diversified criminal portfolio:
Revenue-Generating Activities
- Blockchain development: Exploiting crypto’s anonymity
- Web scraping: Harvesting data for blackmail or resale
- Bot development: Deploying social media manipulation
- AI and trading tools: Creating malicious algorithms
- App development (mobile/web): Embedding backdoors
Each category listed potential budgets and “total paid” sums, treating fraud like quarterly business targets.
Performance Metrics: Data-Driven Crime
A dozen graphs tracked:
- Lucrative regions (North America/Europe prioritized)
- Payment models (fixed fees vs. recurring contracts)
- Income by project type
- Quota attainment rates
“Everything needs to be jotted down. Everyone has to make their quotas,” says Michael Barnhart of DTEX Systems, noting parallels with elite North Korean hacking units like the Lazarus Group (PDF source: UN Security Council Report). This corporatization of crime maximizes efficiency—and sanctions-busting revenue.
Expert Analysis: “Professionally Run” and State-Linked
Evan Gordenker (Palo Alto Networks Unit 42) confirms the data’s legitimacy: “I do think this is very real.” His team tracked accounts from the leak, including GitHub profiles accidentally exposing operational files. Barnhart corroborates ties to Pyongyang, though clarifies these IT schemes operate separately from hacking collectives stealing billion-dollar crypto heists.
Disturbing similarities exist between this operation and North Korea’s playbook:
- Quota systems pressuring workers to meet financial targets
- Centralized reporting ensuring Pyongyang’s oversight
- Compartmentalization separating IT fraud from cyber-theft units
Silencing the Threat: Big Tech Responds
When WIRED shared findings:
- GitHub suspended 3 accounts tied to the operation, citing “spam and inauthentic activity.”
- Google refused to comment on specifics but noted policies to detect fraud and assist law enforcement.
Raj Laud (GitHub’s security head) admitted the challenge: “The prevalence of nation-state threat activity is an industry-wide issue.” Meanwhile, Google’s Mike Sinno emphasized partnerships with agencies to “share threat intelligence.” Despite takedowns, experts warn porous freelance platforms remain easy prey for fake profiles.
The Broader Menace: Funding a Pariah State
These scams feed North Korea’s economy amid sanctions:
- The UN estimates 40% of Pyongyang’s missile funding comes from cyber operations (Reuters report).
- FBI alerts confirm IT worker fraud exceeds $100M+ in stolen wages alone (FBI Advisory).
Unlike ransomware attacks, this slow-burn scam avoids immediate detection. Workers deliver real code while exfiltrating data or skimming funds over months. For hiring managers, the red flags are subtle:
- Geographic discrepancies (e.g., IPs mismatched with claimed location)
- Overqualification for routine gigs
- Refusal to video-call or verify identity
Conclusion: An Invisible War Demands Vigilance
North Korea’s IT worker scheme is borderless, data-driven, and alarmingly corporate. By weaponizing remote work infrastructure, it evades sanctions while compromising global businesses. Tech firms’ reactive suspensions won’t suffocate this hydra; proactive verification—AI-powered identity checks, stricter freelance platform vetting, cross-industry intelligence sharing—is essential.
What’s your organization’s defense against invisible threat actors? Have you encountered suspicious freelance activity? Share your insights in the comments.
Sources & Further Reading:
Original article at www.wired.com


