Amazon has detected and prevented over 1,800 suspected North Korean operatives from infiltrating its workforce by posing as remote IT workers. The company’s Chief Security Officer, Stephen Schmidt, revealed that one operative was caught after investigators noticed unusual keystroke delays inconsistent with a US-based employee, leading to the discovery that the individual was operating from North Korea. This detection was part of a broader effort by Amazon to scrutinize remote work applications and identify fraudulent activity linked to the Democratic People’s Republic of Korea (DPRK).
The scheme highlights ongoing attempts by North Korean actors to bypass international sanctions and generate revenue through illicit employment in Western technology companies. Amazon’s security team has reported a 27% increase in DPRK-affiliated job applications quarter over quarter in 2025, underscoring the scale and persistence of the threat. The company’s actions demonstrate the importance of behavioral analysis and vigilance in remote hiring processes to counter sophisticated nation-state tactics targeting the tech sector.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced plans to finally disable RC4 encryption by mid-2026. The move followed years of criticism over the legacy cipher's continued availability despite repeated security concerns.
A new managed security service provider initiative was launched to help defend small U.S. water utilities. The program was introduced in response to persistent targeting of the sector by Chinese and Iranian threat actors.
The FBI, working with Estonian law enforcement, seized a phishing domain used to steal bank credentials from U.S. victims. Authorities said the operation was linked to $14.6 million in losses.
Interpol carried out an enforcement action targeting ransomware actors operating in Africa. The operation was reported as part of broader international efforts to disrupt cybercriminal groups.
The U.S. Department of Justice announced charges against suspects accused of involvement in ATM jackpotting activity. The case was one of several law-enforcement actions against financially motivated cybercrime reported that week.
Reporting indicated that data stolen in the 2022 LastPass breach is still being exploited, with password vaults being cracked and then used to steal cryptocurrency. This marked a continuing escalation in the long-term impact of the original breach.
France's La Poste suffered a cyberattack that was claimed by the Russian DDoS group NoName057. The event added to a series of disruptive attacks attributed to pro-Russian hacktivist actors.
French privacy regulator CNIL imposed fines on Mobius and Nexpublica in connection with major data breaches. The enforcement action was reported as part of the week's notable cyber developments in France.
A supply chain compromise involving EmEditor led to users receiving an infostealer through a modified installer. The incident represented a software distribution channel being abused to spread malware.
Romania's water agency ANAR was reported as suffering operational disruption following a ransomware attack. The incident was cited as a significant cyber event affecting public-sector infrastructure.
The UK's Foreign Office confirmed it was hit by a cyberattack, and reporting said the intrusion was suspected to be tied to a Chinese threat actor tracked as Storm-1849. The incident was highlighted as one of the week's major state-linked breaches.
Amazon said it detected and stopped more than 1,800 attempts by North Korean operatives to obtain jobs at the company using identity fraud and remote-work tactics. The activity was identified in part through signals such as keystroke lag.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.