North Korean-linked IT worker operations have expanded in scale and geography, using fabricated identities, false references, and multiple online personas to secure remote jobs in the United States and Europe, including roles tied to government and the defense industrial base. Google threat intelligence reported that some operators managed a dozen personas at once, recruited through platforms such as Upwork, Telegram, and Freelancer, while facilitators helped bypass identity checks and move payments through cryptocurrency, TransferWise, and Payoneer. The activity has also evolved beyond revenue generation: since late 2024, recently fired workers have increasingly threatened to leak sensitive data and source code, and investigators observed cases in which company-issued devices were redirected across borders and false-resume infrastructure supported the scheme.
The campaign reflects a broader breakdown in trust around digital identity verification as deepfakes and voice cloning become more convincing. U.S. agencies including NSA, FBI, and CISA have warned that synthetic media can be used to deceive organizations and critical infrastructure operators, while recent incidents showed the operational impact: an employee at Arup was reportedly tricked by AI-generated executive impersonations into sending about $25 million across 15 transfers, and KnowBe4 disclosed hiring a fake employee later identified as a North Korean operative who attempted to deploy malware. Security guidance increasingly recommends layered, low-tech controls such as out-of-band verification, hardware-backed MFA, dual approval for sensitive transactions, and role-specific authentication procedures rather than relying on video, voice, or automated deepfake detection alone.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
By January 2025, DPRK IT workers were conducting operations against employers using BYOD and virtual workspace access models, which the report says can reduce monitoring and hinder detection.
Since late October 2024, Google Threat Intelligence Group assessed that DPRK IT workers increased extortion attempts, threatening to leak former employers' sensitive data and source code and targeting larger organizations.
In late 2024, one DPRK IT worker operated at least 12 personas across Europe and the United States while seeking jobs, including roles tied to European defense industrial base and government organizations.
In 2024, KnowBe4 hired an individual who passed interviews and screening before being identified as a North Korean operative; after receiving a workstation, the person attempted to introduce malware into the company's systems.
In January 2024, an Arup employee joined a video call with AI-generated clones posing as company executives and was induced to make 15 transfers totaling about $25 million to third-party accounts.
On September 12, 2023, the NSA, FBI, and CISA jointly released the Cybersecurity Information Sheet "Contextualizing Deepfake Threats to Organizations" covering synthetic media threats, techniques, trends, and defensive recommendations.
The ZDNet article says Google Threat Intelligence Group has investigated fake-employee incidents linked to North Korean operators since 2022.
The CISA alert states that U.S. Government organizations collaborated between 2021 and 2022 to establish employable best practices for preparing for and responding to synthetic media threats.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcecloud.google.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.