Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

Trojan Horse in the Staff: How to Expose North Korean Spies in an IT Company Before Hiring

Hackers are traditionally thought of as external attackers. But North Korean IT professionals are changing that model: they are interviewed, given official access, and infiltrate systems that cost millions to protect.

This is no longer a theory — the FBI is already investigating a case where a North Korean operative worked for a US government agency.

Leave a comment
Trojan Horse in the Staff: How to Expose North Korean Spies in an IT Company Before Hiring

Hackers are traditionally thought of as external attackers. But North Korean IT professionals are changing that model: they are interviewed, given official access, and infiltrate systems that cost millions to protect.

This is no longer a theory — the FBI is already investigating a case where a North Korean operative worked for a US government agency.

A joint study by Mauro Eldritch (BCA LTD), Heiner García (NorthScan), and ANY.RUN revealed the mechanics of the scheme. The researchers knowingly hired developers from the DPRK (affiliated with the Lazarus Group) and provided them with test workstations. In fact, these were ANY.RUN's controlled interactive sandboxes that recorded every action, The Hacker News reports .

The research uncovered the use of fake identities, remote access tools, artificial intelligence prompts, and dedicated VPN/VPS infrastructure.

"Red flags" for hiring

Suspicious signals are usually not found in one thing, but in a combination of small discrepancies:

  • data inconsistency: discrepancies between addresses, documents and bank details;

  • traces of ID manipulation: unusual metadata, visual flaws, or traces of document generation/editing via AI;

  • strange behavior during the interview: the candidate constantly looks away, has delays in answering, uses translators or real-time AI prompts;

  • Network anomalies: the actual IP location does not match the declared place of residence.

4 steps for CISOs

1. Deep identity verification

A simple passport review is not enough. For critical roles (access to source code, cloud, production or finance), the verification must be comprehensive: documents, geolocation, interview behavior and banking data must form a single picture.

2. Securely check for suspicious activity

Use interactive sandboxes (e.g. ANY.RUN). If a new employee runs strange scripts, tools, or files, analyze them in an isolated environment to assess the risks before they affect critical systems.

3. Checking the infrastructure in the logs

Compare network data (EDR, Proxy, DNS) with known indicators of DPRK activity.

A coincidence is not 100% proof of guilt, but it is a direct reason for a detailed investigation.

4. Continuous monitoring

Researchers identified the infrastructure used by suspected North Korean operatives, including IP addresses, VPN endpoints, and VPS providers.

For CISOs, the next step is to ensure that such findings are not just a one-off check for a check mark. They should become part of an ongoing threat detection process so that security teams can spot this or related infrastructure in time if it appears elsewhere in the system.

ANY.RUN Threat Intelligence Feeds help with this by continuously delivering fresh indicators from real-world investigations into your existing security tools. This turns cyber intelligence from similar incidents into early warning signals to detect future suspicious activity.

So hiring remote workers is no longer just an HR task — it’s a cybersecurity issue. Deep verification of individuals and integration of Threat Intelligence before the date of access is granted is the only way to prevent an insider from entering the company.

Ukrainian man gets 5 years in prison for participating in scheme with North Korean IT workers
Ukrainian man gets 5 years in prison for participating in scheme with North Korean IT workers
On the topic
Ukrainian man gets 5 years in prison for participating in scheme with North Korean IT workers
A video of an interview with a North Korean IT guy went viral on X. He "cut himself off" when asked to call Kim Jong-un a pig
A video of an interview with a North Korean IT professional went viral on X. He "cut himself off" when asked to call Kim Jong-un a pig
On the topic
A video of an interview with a North Korean IT professional went viral on X. He "cut himself off" when asked to call Kim Jong-un a pig
A hacker from North Korea "exploded" a virus on his own PC, exposing a scheme of fake IT workers with an income of $1 million per month
A hacker from North Korea "exploded" a virus on his own PC, exposing a scheme of fake IT workers with an income of $1 million per month
On the topic
A hacker from North Korea "exploded" a virus on his own PC, exposing a scheme of fake IT workers with an income of $1 million per month
Hackers from North Korea rent profiles of foreigners on LinkedIn, Fiverr and Upwork and apply for vacancies at IT companies on their behalf. A cyber specialist conducted an experiment - his rented profile received an offer for $80,000
Hackers from North Korea rent profiles of foreigners on LinkedIn, Fiverr and Upwork and apply for vacancies at IT companies on their behalf. A cyber specialist conducted an experiment - his rented profile received an offer for $80,000
On the topic
Hackers from North Korea rent profiles of foreigners on LinkedIn, Fiverr and Upwork and apply for vacancies at IT companies on their behalf. A cyber specialist conducted an experiment - his rented profile received an offer for $80,000
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.