Are You Hiring a Hacker? The Rise of North Korean IT Workers in Corporate Networks
Imagine sifting through hundreds of applications for a senior engineering role, only to discover that many are fabricated, some even originating from state-sponsored actors. This isn’t a far-fetched scenario; it’s the reality facing many companies today as the number of fraudulent remote IT workers, particularly those linked to North Korea, continues to surge. The issue of these fraudulent IT workers represents a significant cybersecurity and national security threat, demanding immediate attention and proactive measures from businesses and governments alike.
The Growing Threat of Fraudulent IT Workers
The digital landscape has blurred borders, making it easier for malicious actors to infiltrate corporate networks. But the sophistication and scale of the current threat, particularly involving North Korean IT workers, are unprecedented.
AI-Powered Deception and the Breakdown of Traditional Recruitment
The rise of artificial intelligence (AI) is exacerbating the problem. As Gunter Ollman, CTO of Cobalt, highlights, AI can be used to craft incredibly convincing resumes tailored to specific job descriptions. This “AI-laundering” of resumes makes it nearly impossible for traditional keyword-based filtering systems to identify fraudulent applications.
- Problem: Keyword filtering, the cornerstone of initial resume screening, is rendered ineffective.
- Result: A deluge of applications, many of which are sophisticated forgeries.
- Further Complication: The use of deepfakes during video interviews, making it harder to detect imposters.
The widespread availability of deepfake technology means that even a basic home computer can produce a reasonably convincing video persona. Refusing to turn on a camera during a video call was once a red flag, but now that red flag has evolved into a seemingly real person generated by AI.
The North Korean Connection: Funding Weapons Programs Through Cybercrime
North Korea, facing severe international sanctions, has turned to cybercrime as a significant source of revenue. Employing fraudulent IT workers is a key component of this strategy. These individuals, operating under stolen or fabricated identities, secure remote positions and funnel their earnings back to Pyongyang.
- Magnitude: US authorities estimate that these schemes have generated at least $88 million for the North Korean regime by the end of last year.
- Growth: CrowdStrike reported a 220% year-on-year increase in these cases, logging over 320 incidents in the past year.
- Impact: This illicit income directly supports North Korea’s weapons programs, posing a threat to global security.
Beyond Financial Gain: Espionage and Sabotage
The motivation behind these schemes extends beyond mere financial gain. These fraudulent workers also provide opportunities to access sensitive corporate data, steal intellectual property, and potentially disrupt operations. CrowdStrike researchers warn that the aim is to create back doors into Western companies for theft and disruption, creating opportunities for espionage or sabotage. The consequences of such breaches can be devastating, ranging from financial losses and reputational damage to compromised national security.
Identifying “Worker Personas”: A New Approach to Threat Intelligence
Palo Alto Networks has taken a proactive approach by tracking “worker personas” – the fabricated identities used to bypass HR and compliance checks. Andy Piazza, Senior Director of Threat Intelligence, emphasizes the collaborative nature of this effort.
The “Worker Persona” Database
By sharing information about suspicious personas, companies can contribute to a growing database of known fraudulent identities. This intelligence exchange allows security teams to identify and prevent infiltration before it occurs.
Legal and Compliance Implications
The use of fabricated identities complicates matters for legal and compliance teams. Unlike traditional threat indicators like IP addresses, personas involve names, biographies, and other personal information. This requires closer collaboration between security departments and legal/compliance teams to ensure appropriate due diligence and legal compliance.
Government Warnings and Red Flags for Businesses
The severity of the threat has prompted governments to issue warnings and advisories to businesses.
Canada’s Advisory: Criminal Liability and Sanctions Violations
In July, Canadian authorities issued a public advisory highlighting the potential legal consequences of hiring North Korean IT workers. Employing such individuals could be considered a violation of international sanctions and could result in criminal liability.
Red Flags to Watch Out For
Both Canadian and UK authorities have outlined specific red flags that businesses should be aware of during the hiring process:
- Frequent money transfers, especially to unusual locations.
- Requests for payment in cryptocurrency.
- Inconsistencies in personal information across different documents.
- Reluctance to appear on camera or engage in live video interviews.
- Unusually low bids for work, potentially indicating a willingness to undercut legitimate competitors.
- Suspicious logins from multiple countries, suggesting the use of VPNs or proxy servers.
- Requests for prepayment before completing any substantial work.
- Failure to attend check-in meetings or provide regular updates.
- Offering free services initially to gain trust and establish a foothold.
These red flags, while not definitive proof of fraudulent activity, should raise suspicion and prompt further investigation.
Small Businesses and Start-Ups: Prime Targets
Small businesses and start-ups are particularly vulnerable due to their need for affordable talent and limited resources for thorough applicant screening. This makes them attractive targets for fraudulent IT workers.
Strategies for Mitigating the Risk
Combating the threat of fraudulent IT workers requires a multi-faceted approach involving enhanced due diligence, technological solutions, and employee training.
Enhanced Due Diligence and Background Checks
- Verify Credentials: Go beyond simple resume checks. Verify educational qualifications, work experience, and professional certifications with issuing institutions.
- Social Media Analysis: Conduct thorough social media analysis to identify inconsistencies or red flags in a candidate’s online presence.
- Independent Background Checks: Utilize reputable background check services to verify identity, criminal history, and credit history.
- Reference Checks: Conduct thorough reference checks, speaking directly to previous employers to verify employment history and job performance.
Technological Solutions
- AI-Powered Screening Tools: Deploy AI-powered screening tools that can detect fraudulent resumes and identify inconsistencies in application materials.
- Biometric Authentication: Implement biometric authentication for remote workers to verify identity and prevent unauthorized access to company systems.
- IP Address Monitoring: Monitor IP addresses for suspicious activity, such as logins from unusual locations or the use of proxy servers.
- Network Monitoring: Implement robust network monitoring systems to detect unusual traffic patterns or suspicious activity that could indicate unauthorized access.
Employee Training and Awareness Programs
- Educate Employees: Educate employees, especially HR and hiring managers, about the threat of fraudulent IT workers and the red flags to watch out for.
- Security Awareness Training: Provide regular security awareness training to all employees, emphasizing the importance of data security and reporting suspicious activity.
- Phishing Simulations: Conduct phishing simulations to test employees’ ability to identify and avoid phishing attacks, a common tactic used by fraudulent IT workers.
Conclusion: Vigilance is Key in the Fight Against Fraudulent IT Workers
The infiltration of corporate networks by fraudulent IT workers, particularly those linked to North Korea, represents a growing and evolving threat. The use of AI-powered deception, combined with the complex geopolitical landscape, makes this a challenging issue for businesses to address.
By implementing enhanced due diligence measures, leveraging technological solutions, and providing comprehensive employee training, organizations can significantly reduce their risk of falling victim to these schemes. It’s a constant game of cat and mouse, demanding continued vigilance and adaptation.
What measures is your company taking to combat the threat of fraudulent remote workers? Share your thoughts and strategies in the comments below!
Sources & Further Reading:
Original article at techinformed.com


