North Korean IT Worker Threat Center
North Korean IT workers use false or concealed identities to obtain remote jobs and contractor access. This resource tracks how the schemes operate, the signals organizations can use to detect them, current government guidance, and imper.ai research.
Last updated: August 2026
Start with the question you need to answer
Use the Threat Center as the overview. Go deeper into detection, insider risk, threat intelligence, or response when you need operational detail.
How to detect North Korean IT workers
Device, network and identity indicators observed in a 600-candidate hiring cohort.
View detection guidance → Insider riskWhy normal behavior can still be risky
Why a technically capable worker using legitimate access can evade traditional insider-risk controls.
Explore insider risk → Threat intelligenceDPRK IT worker TTPs and activity
Government guidance, researcher tracking names, infrastructure, tools and campaign patterns.
View threat intelligence → Incident responseThink you hired one?
What security, IT, HR, legal and finance teams should do when an employee or contractor is suspected.
View response guidance →What is a North Korean IT worker?
North Korean IT workers are technology workers associated with the DPRK’s overseas revenue-generation programs who obtain employment or contract work while concealing their nationality, location, identity, or who is actually operating the account.
Government agencies have documented stolen identities, U.S.-based facilitators, laptop farms, VPNs, remote-access software, AI-assisted applications and unusual payment arrangements. Once hired, the worker can receive legitimate credentials, corporate devices and authorized access to internal systems.
How the scheme works
The exact tactics vary, but government and private-sector investigations repeatedly show the same basic sequence.
Identity
Use a stolen, borrowed or fabricated identity and digital profile.
Hiring
Apply for remote technical roles and pass interviews or assessments.
Laptop farm
A facilitator may receive a corporate device and enable remote control.
Legitimate access
The worker uses approved credentials and may perform the assigned job normally.
Why this matters beyond hiring fraud
A worker can perform the job well and still create material national-security, sanctions and enterprise risk.
U.S. Treasury says revenue from overseas IT workers supports North Korea’s unlawful nuclear, WMD and ballistic-missile programs.
The schemes are designed to evade U.S. and UN sanctions. An unwitting employer can still face serious compliance, legal and reputational consequences.
Once hired, the worker may hold approved credentials and corporate access. U.S. authorities have also documented malware, extortion and sensitive-data theft in some cases.
Why North Korean IT workers can be hard to detect
A fraudulent worker does not have to be bad at the job. They may write code, attend meetings, close tickets, authenticate normally and stay within assigned privileges. Conventional insider-risk controls may therefore see activity that looks consistent with the role.
Useful for detecting unusual downloads, privilege abuse, policy violations and data exfiltration.
Requires identity, device, network, location, remote-control and hiring signals to be connected.
Who needs to be involved?
No single team sees the full picture. Detection depends on connecting signals across the workforce lifecycle.
Talent acquisition
Candidate identity, interview consistency, employment history, payment and shipping details.
Identity
Whether the authenticated account is being operated by the person the company intended to hire.
IT & help desk
Device enrollment, remote-access tools, MFA resets, location conflicts and unusual support activity.
Insider risk
Normal-looking work may still be performed under a concealed identity or by a remote operator.
Threat intelligence
DPRK infrastructure, facilitators, tools and known TTPs need to become operational detection and escalation rules.
What imper.ai observed in a 600-candidate hiring cohort
In Q1 2026, imper.ai identified four candidates exhibiting overlapping device, network and identity signals consistent with published DPRK IT worker tradecraft before corporate credentials were issued.
600
candidates analyzed
4
candidates with DPRK-consistent signals
Astrill VPN
AnyDesk
Layered proxies
Location / latency mismatch
VoIP numbers
Low-activity email accounts
Attribution confidence is moderate-to-high based on alignment with published DPRK IT worker tradecraft. imper.ai does not claim definitive attribution absent additional corroborating intelligence.
Latest North Korean IT worker developments
This section should be kept current as government guidance and significant investigations are published.
Eleven governments issue coordinated warning
The U.S. and ten partner governments warned employers about false identities, laptop farms, remote access, AI-assisted impersonation and sanctions exposure.
Read imper.ai analysis →FBI discloses apparent worker inside U.S. federal government
Federal News Network reported that an FBI official said an apparent DPRK remote IT worker had been employed by an unnamed federal agency.
Read the report →Coverage expands across major U.S. media
The Wall Street Journal, TechCrunch, CBS, Fox Business, Fox News and others brought the issue to wider business and national audiences.
View the media roundup →The FBI has publicly named alleged participants in the DPRK IT worker scheme
The FBI lists 14 individuals wanted for their alleged involvement in a conspiracy to generate and launder revenue for the North Korean regime. Federal arrest warrants were issued in December 2024.
This is useful context, not a facial detection strategy. DPRK IT worker risk is broader than a list of known individuals and should be assessed through identity, device, network and workforce signals.
Source: Federal Bureau of Investigation. Poster shown unaltered and linked to the original FBI source.Frequently asked questions
Are North Korean IT workers actually hackers?
Not necessarily in the conventional sense. The core scheme involves obtaining legitimate employment or contractor access while concealing identity, nationality or location. Once hired, that legitimate access can create security, intellectual-property, sanctions and insider-risk exposure.
Are North Korean IT workers technically qualified?
They can be. Technical competence does not establish that the person’s identity, location or affiliation is legitimate. A capable worker can perform assigned duties while still operating under a concealed identity.
What is a North Korean IT worker laptop farm?
A laptop farm is an arrangement in which employer-issued devices are hosted at a location that makes the worker appear domestic while the devices are remotely operated from somewhere else, often with help from a facilitator.
Can a background check detect a North Korean IT worker?
Background checks can identify some inconsistencies, but they do not necessarily establish who is operating the account or corporate device after hiring. Detection needs to combine identity, device, network, location and workforce signals.
Can insider-risk tools detect North Korean IT workers?
They may detect malicious activity after hiring, but a worker who performs expected job functions using approved access may not generate conventional behavioral anomalies. This is why recruiting, identity, IT, insider risk and threat intelligence signals need to be connected.
Detect workforce impersonation before access is granted
imper.ai analyzes device, network, virtualization, remote-control and behavioral signals during high-risk workforce interactions.
