A multinational government alert warns that North Korean IT workers are fraudulently securing remote jobs at companies worldwide using stolen or fabricated identities, forged documents, interview proxies, VPNs, remote-desktop tools, and overseas laptop farms. The activity generates revenue for Pyongyang's prohibited nuclear-weapons and ballistic-missile programs, while potentially exposing employers to sanctions violations and insider threats including data theft, cryptocurrency theft, and exfiltration of sensitive information.
Reporting indicates North Korea is also recruiting talent abroad to expand infiltration of U.S. companies and facilitate associated money-laundering activity. Employers, staffing firms, and online work platforms should strengthen identity and right-to-work verification and investigate anomalies in interviews, account activity, device locations, payment methods, and requests to route company laptops through third parties; UN Security Council Resolution 2397 generally requires states to repatriate North Korean nationals earning income in their jurisdictions.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
The Multilateral Sanctions Monitoring Team released a report concerning North Korean violations and evasion of UN sanctions through cyber activity and IT-worker operations.
Japan, the United States, and the Republic of Korea issued a joint statement addressing North Korean IT workers.
The United States, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom jointly issued an alert on North Korean IT workers fraudulently obtaining remote employment under false or stolen identities. The alert warned of insider risk, data theft, cryptocurrency theft, and potential sanctions or legal exposure for organizations that pay such workers.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.