Наталя ХандусенкоHot News
13 August 2026, 15:48
2026-08-13
Trojan Horse in the Staff: How to Expose North Korean Spies in an IT Company Before Hiring
Hackers are traditionally thought of as external attackers. But North Korean IT professionals are changing that model: they are interviewed, given official access, and infiltrate systems that cost millions to protect.
This is no longer a theory — the FBI is already investigating a case where a North Korean operative worked for a US government agency.
Hackers are traditionally thought of as external attackers. But North Korean IT professionals are changing that model: they are interviewed, given official access, and infiltrate systems that cost millions to protect.
This is no longer a theory — the FBI is already investigating a case where a North Korean operative worked for a US government agency.
A joint study by Mauro Eldritch (BCA LTD), Heiner García (NorthScan), and ANY.RUN revealed the mechanics of the scheme. The researchers knowingly hired developers from the DPRK (affiliated with the Lazarus Group) and provided them with test workstations. In fact, these were ANY.RUN's controlled interactive sandboxes that recorded every action, The Hacker News reports .
The research uncovered the use of fake identities, remote access tools, artificial intelligence prompts, and dedicated VPN/VPS infrastructure.
"Red flags" for hiring
Suspicious signals are usually not found in one thing, but in a combination of small discrepancies:
data inconsistency: discrepancies between addresses, documents and bank details;
traces of ID manipulation: unusual metadata, visual flaws, or traces of document generation/editing via AI;
strange behavior during the interview: the candidate constantly looks away, has delays in answering, uses translators or real-time AI prompts;
Network anomalies: the actual IP location does not match the declared place of residence.
4 steps for CISOs
1. Deep identity verification
A simple passport review is not enough. For critical roles (access to source code, cloud, production or finance), the verification must be comprehensive: documents, geolocation, interview behavior and banking data must form a single picture.
2. Securely check for suspicious activity
Use interactive sandboxes (e.g. ANY.RUN). If a new employee runs strange scripts, tools, or files, analyze them in an isolated environment to assess the risks before they affect critical systems.
3. Checking the infrastructure in the logs
Compare network data (EDR, Proxy, DNS) with known indicators of DPRK activity.
A coincidence is not 100% proof of guilt, but it is a direct reason for a detailed investigation.
4. Continuous monitoring
Researchers identified the infrastructure used by suspected North Korean operatives, including IP addresses, VPN endpoints, and VPS providers.
For CISOs, the next step is to ensure that such findings are not just a one-off check for a check mark. They should become part of an ongoing threat detection process so that security teams can spot this or related infrastructure in time if it appears elsewhere in the system.
ANY.RUN Threat Intelligence Feeds help with this by continuously delivering fresh indicators from real-world investigations into your existing security tools. This turns cyber intelligence from similar incidents into early warning signals to detect future suspicious activity.
So hiring remote workers is no longer just an HR task — it’s a cybersecurity issue. Deep verification of individuals and integration of Threat Intelligence before the date of access is granted is the only way to prevent an insider from entering the company.
Hackers from North Korea rent profiles of foreigners on LinkedIn, Fiverr and Upwork and apply for vacancies at IT companies on their behalf. A cyber specialist conducted an experiment - his rented profile received an offer for $80,000