North Korean remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. “DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations’ environments, they’re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do,” Huntress said. “Furthermore, DPRK workers often use stolen identity documents, VPNs, and proxy services to mask their true identity and location, meaning other methods must be used to help verify if an employee is who they say they are,” they added.
In an Australian healthcare case, Huntress analyzed six months of login records for three accounts. The users consistently connected through Astrill VPN and IPRoyal Proxy. Less than 50% of their activity happened during normal business hours, and their busiest period lined up with 9 a.m. in North Korea.
Two workers uploaded resident ID cards and passports to verify their identity. The documents shared disturbing similarities. Passports were issued in the same city within a single day. The ID cards shared the same validity dates and issuing police station. The photos were taken at similar angles using the same phone model within minutes of each other. The researchers noted visible damage consistent across both photos, leading to a theory that both individuals accidentally used the same rear-facing card photo.
Related: AI security gains on a shoestring budget
Electricity bills submitted as proof of residence contained identical typos. Huntress suggested these errors might stem from optical character recognition software turning an image into a template, though the documents could also contain legitimate information stolen from other people.
Hardware and identity swaps
A second incident at a financial services firm highlighted the use of specialized hardware. Investigators found a PiKVM connected to a new hire’s laptop within hours of the device reaching a residential address. This open-source device, based on a Raspberry Pi, allows a user to operate a computer remotely.
Windows logs showed the laptop moving from a managed service provider’s network to a travel router, then to a home Wi-Fi network named “Pickle_Rick,” before settling on a fixed Ethernet connection. The researchers described this sequence as potentially indicative of a laptop farm setup. The device was paired with a Guermok USB capture card, which registered as a webcam on the machine to stream video into web conferencing apps like Zoom. While the card itself is not definitive proof of DPRK involvement, its co-occurrence with the PiKVM raised significant red flags.
Related: Coding agents can be evaluated by assessing their work
At a partner organization, a sales and marketing hire who had been onboarded 13 days earlier appeared to have used a swapped photo. Investigators found a police mugshot of a person whose name, date of birth, and location matched the provided identity documents. The identification numbers passed validation checks, suggesting the documents contained a real person’s data that had been digitally altered.
When the company requested a video call to see the employee’s workspace, the individual refused and was reluctant to appear on camera, leaving the investigation’s findings about their true identity questionable.
