U.S. authorities and multiple security firms detailed a large North Korean scheme in which operatives use stolen or fabricated identities to win remote IT jobs at Western companies, then send the earnings back to Pyongyang in violation of sanctions. Research from IBM X-Force, Flare, Microsoft, LevelBlue, and others described a mature ecosystem of recruiters, facilitators, brokers, laptop-farm operators, and Western collaborators that helps workers pass interviews, receive corporate devices, mask their locations with VPNs, and clear payroll and compliance checks. Estimates cited across the reporting say more than 100,000 workers operating across dozens of countries may be generating roughly $500 million annually, while some cases also involved data theft, source-code exfiltration, extortion, and malware activity after hiring.
The U.S. Treasury's Office of Foreign Assets Control sanctioned six individuals and two entities tied to the operation, while U.S. courts sentenced three Americans, including a former Army soldier, for helping North Korean workers use false identities and laptop farms to obtain jobs at U.S. companies. Investigations also exposed operational tradecraft including use of Astrill VPN, NetKey/OConnect, IP Messenger, freelance platforms, AI-generated resumes and headshots, and U.S.-based hardware relays such as PiKVM-enabled laptop farms; one hired worker was removed within 10 days after suspicious logins from China and Missouri triggered detection. Researchers and federal advisories warned that remote hiring has become an insider-threat and sanctions-compliance risk, urging tighter identity verification, live skills testing, device and geolocation controls, least-privilege access, and joint oversight by HR, recruiters, and security teams.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, Nisos published research assessing with high confidence that a DPRK state-sponsored cell ran an industrial-scale employment fraud operation targeting U.S. companies. The report said that between December 2024 and September 2025, 22 operatives submitted more than 170,000 applications and secured 76 job offers using stolen identities, AI-assisted interviews, U.S.-based facilitators, Astrill VPN, PiKVM devices, and cryptocurrency payments.
Reporting on 2026-04-10 said a North Korean operator accidentally executed infostealing malware on their own computer, exposing data from an internal payment server including 390 accounts, chat logs, and cryptocurrency transaction records. Investigators said the leak revealed a scheme generating about $1 million per month and exposed weakly protected infrastructure tied to sanctioned DPRK-linked firms.
On 2026-04-08, ZachXBT published findings about DPRK IT workers and their payment infrastructure after an infostealer compromise exposed internal communications through luckyguys[.]site. The leak provided visibility into a large-scale but relatively low-sophistication ecosystem supporting fraudulent remote IT work.
Flare researchers reported that much of the observed activity recruiting Iranian IT professionals into the DPRK remote IT worker fraud pipeline dated back to 2024. Internal documents showed recruiters targeting Iranians on LinkedIn and coaching them to obtain jobs under stolen or fabricated identities.
Researchers reported that in June 2025 they exposed a suspected North Korean operative who tried to infiltrate a cybersecurity firm using a stolen identity and an AI-generated resume. Investigators linked the activity to a broader laptop farm operation using PiKVM and Tailscale for remote control.
By 2026-03-26, cybersecurity engineer Toufik Airane reported that a suspected North Korean hacker had approached him offering up to $70,000 per month to use his identity for remote job interviews in exchange for a share of the salary. Airane said he captured screenshots from a video call and linked the individual to prior security-firm identification.
A federal court in the Southern District of Georgia sentenced Alexander Paul Travis, Jason Salazar, and Audricus Phagnasay for helping North Korean IT workers secure remote jobs at U.S. companies using false identities and laptop farms. The sentencing was announced in a DOJ press release on Friday and included prison, probation, and forfeiture orders.
According to DOJ information cited in reporting, Alexander Paul Travis, Jason Salazar, and Audricus Phagnasay pleaded guilty in November to wire fraud conspiracy for helping North Korean IT workers obtain remote jobs at U.S. companies using false identities.
In August 2025, a suspected North Korean operative obtained a remote IT job at a Western company and was given access to sensitive Salesforce data after passing standard hiring checks. The case was later cited by LevelBlue as part of the broader DPRK remote worker scheme.
On 2026-03-18, Flare Research and IBM X-Force published findings describing a mature, multi-tiered North Korean fake IT worker ecosystem using false identities, collaborators, and DPRK-linked infrastructure such as RB Site, NetkeyRegister, NetKey/OConnect, and IP Messenger. The research detailed how the scheme places workers into Western companies to generate revenue and sometimes enable theft or extortion.
In March 2026, the U.S. Treasury Department's Office of Foreign Assets Control sanctioned six individuals and two entities linked to North Korea's remote IT worker operation. The sanctions targeted a scheme using stolen identities, fake personas, and fraudulent documents to obtain jobs and funnel earnings back to the DPRK.
On 2026-01-23, a threat-hunting investigation published findings on a cluster of suspicious GitHub profiles assessed as linked to North Korean fake IT worker activity. The report described coordinated starring and following behavior, AI-generated or low-quality profile images, crypto-themed repositories, and links to X accounts used for engagement farming and possible developer recruitment.
On 2025-11-29, a follow-up investigation into the DPRK-linked Wagemole operation identified newer fake front companies including MetaMint Studio and JSoft Labs, alongside tradecraft overlaps with earlier DredSoftLabs activity. The report said the broader repository web included 116 malicious GitHub repositories, 9 hostnames used to deliver malicious code, 3 command-and-control IPs, and published related indicators and obfuscation details.
On 2025-08-25, the company terminated the suspected North Korean worker's access by revoking the employee's EntraID account after detecting suspicious login activity tied to China and an unmanaged device in St. Louis. The action ended the worker's access within 10 days of hiring.
On 2025-01-23, the FBI issued updated guidance stating that North Korean IT workers were increasingly stealing proprietary information, exfiltrating code, and conducting data extortion against U.S.-based businesses. The notice also warned of AI and face-swapping use during interviews and urged stronger monitoring and hiring controls.
On 2024-11-19, the FBI published a wanted notice naming 14 individuals allegedly involved in a DPRK IT worker conspiracy that generated and laundered revenue for North Korea. The notice said the State Department's Rewards for Justice program was offering up to $5 million for information disrupting related financial mechanisms and solicited public tips.
On 2024-05-16, the FBI warned that North Korean IT workers were fraudulently obtaining remote jobs at U.S. companies with help from U.S.-based facilitators who handled laptops, internet access, financial accounts, and interviews. The notice recommended stronger identity verification and monitoring for unauthorized remote access.
On 2023-10-18, the United States and the Republic of Korea issued updated guidance on DPRK IT workers, adding new red flags such as suspicious interview behavior, mismatched online identities, and freight-forwarding addresses. The advisory warned of sanctions, theft, and reputational risks and recommended stronger due diligence and monitoring.
An investigation reported on 2023-05-08 found evidence that DPRK IT workers used Raspberry Pi-based KVM devices and mesh VPN technology to remotely access desktop systems in a laptop farm setup.
On 2022-05-16, the U.S. Departments of State and Treasury, together with the FBI, published an advisory warning that DPRK IT workers were posing as non-DPRK nationals to obtain employment and evade sanctions. The advisory also outlined red flags and released related guidance for companies and platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
42 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcenknews.org
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceic3.gov
Open sourceic3.gov
Open sourceinfosec.pub
Open sourceofac.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.