North Korean IT Worker Threat Center

How to Detect North Korean IT Workers

No single signal proves that a candidate or employee is a North Korean IT worker. Detection becomes stronger when independent identity, device, network and workforce signals point in the same direction.

IdentityDoes the person stay consistent?
NetworkDoes the geography make sense?
DeviceWho is operating the endpoint?
WorkforceDo hiring and onboarding signals align?

The strongest detections combine signals

A VPN, VoIP number or remote-access tool can each have legitimate uses. The risk rises when several unrelated indicators appear together.

Lower confidence
Public VPN+VoIP number
Higher confidence
VPN / proxy+location mismatch+remote control+identity inconsistency

What to look for

These are examples of signals documented in government guidance, threat-intelligence research and imper.ai observations.

Identity

  • Low-activity or recently created email accounts
  • VoIP or reused phone numbers
  • Conflicting names, dates, education or work history
  • Identity details that change between stages

Network

  • Public VPN or anonymization services
  • Multi-hop or layered proxy routing
  • Latency inconsistent with claimed geography
  • Foreign origin despite a claimed domestic location

Device

  • RMM or remote desktop software
  • Unexpected virtualization
  • Device characteristics changing across sessions
  • Evidence that another operator controls the endpoint

Hiring & onboarding

  • Equipment sent to unrelated addresses
  • Changes in shipping or payment details
  • Different people appearing across interviews
  • Unusual MFA, enrollment or account-recovery events

Detect across the workforce lifecycle

A one-time check at the application stage is not enough. The person, device and environment should remain consistent as access increases.

1Application

Establish baseline identity, contact and digital-footprint signals.

2Interview

Compare the person, network, device and location across interactions.

3Offer & shipping

Validate changes in address, banking and equipment delivery.

4Onboarding

Watch device enrollment, remote access and first-use signals.

5High-risk events

Re-evaluate trust during recovery, access changes and unusual support requests.

imper.ai research: 4 of 600 candidates showed DPRK-consistent signals

Observed indicators included Astrill VPN, AnyDesk, layered proxy routing, geographic latency mismatch, VoIP phone numbers and low-activity email accounts. The candidates were identified before corporate credentials were issued.

Attribution confidence was moderate-to-high based on alignment with published DPRK IT worker tradecraft. imper.ai does not claim definitive attribution absent additional corroborating intelligence.

Detection FAQ

Does one indicator prove a worker is North Korean?

No. Many individual indicators have legitimate explanations. Detection should rely on multiple independent signals plus investigation and corroborating intelligence.

Can identity verification alone detect this threat?

Identity checks can identify some fraud, but they do not necessarily establish who is operating the corporate device later. Detection should connect identity with device, network, location and workforce events.

Why are VPNs and remote-access tools important?

Government and private-sector reporting repeatedly documents their use to conceal worker location or remotely operate company devices. Their presence should be evaluated in context rather than treated as proof by itself.

Should contractors be screened the same way?

Yes. FBI guidance specifically warns that third-party staffing and contracted IT work can create additional exposure because the company granting access may be removed from the original hiring process.

See the signals before access is granted

imper.ai correlates device, network, virtualization, remote-control and digital identity signals during hiring and onboarding.