Amazon has identified and blocked over 1,800 suspected North Korean operatives attempting to secure remote IT jobs within the company since April 2024. These individuals, often using fake or stolen identities and leveraging AI tools or deepfakes, seek employment to funnel wages back to the North Korean regime, which uses the funds to support weapons programs. The company has observed a 27% quarter-over-quarter increase in such applications, highlighting the growing scale and sophistication of these operations. In one notable case, a North Korean imposter working as a sysadmin was detected due to a suspicious 110ms keystroke input lag, which raised red flags about the worker's true location.
The U.S. government and security researchers warn that this tactic is widespread, with most Fortune 500 companies believed to have been targeted or infiltrated, resulting in tens of millions of dollars in losses. Beyond financial gain, some North Korean operatives have used their access to steal proprietary data and extort employers. Additionally, DPRK-linked threat actors have developed advanced malware, such as a new variant of BeaverTail, to further support their cyber operations. Amazon's proactive detection and response efforts underscore the ongoing threat posed by North Korean state-sponsored cyber actors to major Western technology firms.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Amazon Chief Security Officer Stephen Schmidt said the company had blocked more than 1,800 suspected North Korean-linked applicants since April 2024. He also said the volume of such attempts had risen 27% quarter over quarter, underscoring a growing industry-wide threat.
Amazon uncovered a North Korean operative working through a contractor after security staff noticed keystroke input lag of more than 110 milliseconds, inconsistent with a U.S.-based remote worker. Investigation showed the employee laptop in Arizona was being remotely controlled from abroad.
U.S. law enforcement pursued a case against Arizona woman Christina Marie Chapman for helping North Korean operatives obtain remote jobs by hosting and managing dozens of company laptops in the United States. Reports say she was later sentenced to about eight and a half years in prison for her role in a fraud ring tied to roughly $1.7 million.
Amazon said it has been detecting and blocking suspected North Korean-linked job applications since April 2024, marking the start of a sustained campaign targeting the company’s hiring pipeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcedarkreading.com
Open sourcecsoonline.com
Open sourcetomshardware.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourcego.theregister.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.