North Korea’s fraudulent remote IT worker operation is being used to infiltrate hiring pipelines and generate illicit revenue through front companies and intermediaries tied to the regime. Reporting on the scheme describes DPRK-linked personnel posing as remote developers and other technology workers, with the activity framed as a sustained effort to penetrate global hiring processes while concealing state involvement behind false identities and corporate cutouts.
New findings cited by DTEX indicate the proceeds flow far beyond individual fraud, feeding a broader state financing network that supports North Korea’s weapons programs, weapons manufacturing, and activity benefiting Russia’s war effort in Ukraine. Transaction data from a leaked North Korean payment server reportedly showed millions of dollars moving into sanctioned organizations including Sobaeksu, Saenal, Songkwang, and Korea Ryonbong General Corp, with SC Media highlighting $1.97 million routed through Korea Ryonbong between December 2025 and February 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
DTEX reported that $1.97 million in payments moved through the sanctioned Korea Ryonbong General Corp as part of North Korea's fraudulent IT worker scheme. The report explicitly dates these flows to between December 2025 and February 2026.
DTEX reported that North Korea's fake IT worker scheme channels millions of dollars through front companies and sanctioned entities, supporting not only DPRK weapons programs but also broader regime objectives that benefit Russia's war effort in Ukraine. CyberScoop and SC Media both described the report's findings, including flows through entities such as Sobaeksu, Saenal, Songkwang, and Korea Ryonbong General Corp.
Opsek published research describing how North Korean IT workers infiltrate remote hiring processes. A Bluesky post amplified the publication and framed it as DPRK-linked remote hiring activity.
Kudelski Security published research analyzing infrastructure used by DPRK-linked fake IT workers and related offensive teams. The report described Russian exit nodes, shared VPN infrastructure, Skyfreight-linked IP use, mapped parts of the actors’ internal networks, and identified a newly added offensive cluster labeled PUG.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcebsky.app
Open sourcekudelskisecurity.com
Open sourceteam-cymru.com
Open sourcespur.us
Open sourcemsmt.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.