North Korean IT Worker Threat Center

North Korean IT workers use false or concealed identities to obtain remote jobs and contractor access. This resource tracks how the schemes operate, the signals organizations can use to detect them, current government guidance, and imper.ai research.

Last updated: August 2026

Start with the question you need to answer

Use the Threat Center as the overview. Go deeper into detection, insider risk, threat intelligence, or response when you need operational detail.

Detection & indicators

How to detect North Korean IT workers

Device, network and identity indicators observed in a 600-candidate hiring cohort.

View detection guidance →
Insider risk

Why normal behavior can still be risky

Why a technically capable worker using legitimate access can evade traditional insider-risk controls.

Explore insider risk →
Threat intelligence

DPRK IT worker TTPs and activity

Government guidance, researcher tracking names, infrastructure, tools and campaign patterns.

View threat intelligence →
Incident response

Think you hired one?

What security, IT, HR, legal and finance teams should do when an employee or contractor is suspected.

View response guidance →

What is a North Korean IT worker?

North Korean IT workers are technology workers associated with the DPRK’s overseas revenue-generation programs who obtain employment or contract work while concealing their nationality, location, identity, or who is actually operating the account.

Government agencies have documented stolen identities, U.S.-based facilitators, laptop farms, VPNs, remote-access software, AI-assisted applications and unusual payment arrangements. Once hired, the worker can receive legitimate credentials, corporate devices and authorized access to internal systems.

How the scheme works

The exact tactics vary, but government and private-sector investigations repeatedly show the same basic sequence.

1

Identity

Use a stolen, borrowed or fabricated identity and digital profile.

2

Hiring

Apply for remote technical roles and pass interviews or assessments.

3

Laptop farm

A facilitator may receive a corporate device and enable remote control.

4

Legitimate access

The worker uses approved credentials and may perform the assigned job normally.

Why this matters beyond hiring fraud

A worker can perform the job well and still create material national-security, sanctions and enterprise risk.

01 Your payroll can fund DPRK weapons programs

U.S. Treasury says revenue from overseas IT workers supports North Korea’s unlawful nuclear, WMD and ballistic-missile programs.

02 It creates sanctions and legal exposure

The schemes are designed to evade U.S. and UN sanctions. An unwitting employer can still face serious compliance, legal and reputational consequences.

03 Legitimate access can become a security problem

Once hired, the worker may hold approved credentials and corporate access. U.S. authorities have also documented malware, extortion and sensitive-data theft in some cases.

Why North Korean IT workers can be hard to detect

A fraudulent worker does not have to be bad at the job. They may write code, attend meetings, close tickets, authenticate normally and stay within assigned privileges. Conventional insider-risk controls may therefore see activity that looks consistent with the role.

Traditional insider-risk question What is this trusted user doing?

Useful for detecting unusual downloads, privilege abuse, policy violations and data exfiltration.

DPRK IT worker question Is this trusted user actually the person we believe them to be?

Requires identity, device, network, location, remote-control and hiring signals to be connected.

Who needs to be involved?

No single team sees the full picture. Detection depends on connecting signals across the workforce lifecycle.

Talent acquisition

Candidate identity, interview consistency, employment history, payment and shipping details.

Identity

Whether the authenticated account is being operated by the person the company intended to hire.

IT & help desk

Device enrollment, remote-access tools, MFA resets, location conflicts and unusual support activity.

Insider risk

Normal-looking work may still be performed under a concealed identity or by a remote operator.

Threat intelligence

DPRK infrastructure, facilitators, tools and known TTPs need to become operational detection and escalation rules.

What imper.ai observed in a 600-candidate hiring cohort

In Q1 2026, imper.ai identified four candidates exhibiting overlapping device, network and identity signals consistent with published DPRK IT worker tradecraft before corporate credentials were issued.

600

candidates analyzed

4

candidates with DPRK-consistent signals

Astrill VPN

AnyDesk

Layered proxies

Location / latency mismatch

VoIP numbers

Low-activity email accounts

Attribution confidence is moderate-to-high based on alignment with published DPRK IT worker tradecraft. imper.ai does not claim definitive attribution absent additional corroborating intelligence.

Latest North Korean IT worker developments

This section should be kept current as government guidance and significant investigations are published.

July 31, 2026

Eleven governments issue coordinated warning

The U.S. and ten partner governments warned employers about false identities, laptop farms, remote access, AI-assisted impersonation and sanctions exposure.

Read imper.ai analysis →
August 2026

FBI discloses apparent worker inside U.S. federal government

Federal News Network reported that an FBI official said an apparent DPRK remote IT worker had been employed by an unnamed federal agency.

Read the report →
August 2026

Coverage expands across major U.S. media

The Wall Street Journal, TechCrunch, CBS, Fox Business, Fox News and others brought the issue to wider business and national audiences.

View the media roundup →
FBI DPRK IT Workers wanted poster
Primary source · FBI Most Wanted

The FBI has publicly named alleged participants in the DPRK IT worker scheme

The FBI lists 14 individuals wanted for their alleged involvement in a conspiracy to generate and launder revenue for the North Korean regime. Federal arrest warrants were issued in December 2024.

This is useful context, not a facial detection strategy. DPRK IT worker risk is broader than a list of known individuals and should be assessed through identity, device, network and workforce signals.

Source: Federal Bureau of Investigation. Poster shown unaltered and linked to the original FBI source.

Frequently asked questions

Are North Korean IT workers actually hackers?

Not necessarily in the conventional sense. The core scheme involves obtaining legitimate employment or contractor access while concealing identity, nationality or location. Once hired, that legitimate access can create security, intellectual-property, sanctions and insider-risk exposure.

Are North Korean IT workers technically qualified?

They can be. Technical competence does not establish that the person’s identity, location or affiliation is legitimate. A capable worker can perform assigned duties while still operating under a concealed identity.

What is a North Korean IT worker laptop farm?

A laptop farm is an arrangement in which employer-issued devices are hosted at a location that makes the worker appear domestic while the devices are remotely operated from somewhere else, often with help from a facilitator.

Can a background check detect a North Korean IT worker?

Background checks can identify some inconsistencies, but they do not necessarily establish who is operating the account or corporate device after hiring. Detection needs to combine identity, device, network, location and workforce signals.

Can insider-risk tools detect North Korean IT workers?

They may detect malicious activity after hiring, but a worker who performs expected job functions using approved access may not generate conventional behavioral anomalies. This is why recruiting, identity, IT, insider risk and threat intelligence signals need to be connected.

Detect workforce impersonation before access is granted

imper.ai analyzes device, network, virtualization, remote-control and behavioral signals during high-risk workforce interactions.