North Korean IT Worker Threat Center
How to Detect North Korean IT Workers
No single signal proves that a candidate or employee is a North Korean IT worker. Detection becomes stronger when independent identity, device, network and workforce signals point in the same direction.
The strongest detections combine signals
A VPN, VoIP number or remote-access tool can each have legitimate uses. The risk rises when several unrelated indicators appear together.
What to look for
These are examples of signals documented in government guidance, threat-intelligence research and imper.ai observations.
Identity
- Low-activity or recently created email accounts
- VoIP or reused phone numbers
- Conflicting names, dates, education or work history
- Identity details that change between stages
Network
- Public VPN or anonymization services
- Multi-hop or layered proxy routing
- Latency inconsistent with claimed geography
- Foreign origin despite a claimed domestic location
Device
- RMM or remote desktop software
- Unexpected virtualization
- Device characteristics changing across sessions
- Evidence that another operator controls the endpoint
Hiring & onboarding
- Equipment sent to unrelated addresses
- Changes in shipping or payment details
- Different people appearing across interviews
- Unusual MFA, enrollment or account-recovery events
Detect across the workforce lifecycle
A one-time check at the application stage is not enough. The person, device and environment should remain consistent as access increases.
Establish baseline identity, contact and digital-footprint signals.
Compare the person, network, device and location across interactions.
Validate changes in address, banking and equipment delivery.
Watch device enrollment, remote access and first-use signals.
Re-evaluate trust during recovery, access changes and unusual support requests.
imper.ai research: 4 of 600 candidates showed DPRK-consistent signals
Observed indicators included Astrill VPN, AnyDesk, layered proxy routing, geographic latency mismatch, VoIP phone numbers and low-activity email accounts. The candidates were identified before corporate credentials were issued.
Attribution confidence was moderate-to-high based on alignment with published DPRK IT worker tradecraft. imper.ai does not claim definitive attribution absent additional corroborating intelligence.
Detection FAQ
Does one indicator prove a worker is North Korean?
No. Many individual indicators have legitimate explanations. Detection should rely on multiple independent signals plus investigation and corroborating intelligence.
Can identity verification alone detect this threat?
Identity checks can identify some fraud, but they do not necessarily establish who is operating the corporate device later. Detection should connect identity with device, network, location and workforce events.
Why are VPNs and remote-access tools important?
Government and private-sector reporting repeatedly documents their use to conceal worker location or remotely operate company devices. Their presence should be evaluated in context rather than treated as proof by itself.
Should contractors be screened the same way?
Yes. FBI guidance specifically warns that third-party staffing and contracted IT work can create additional exposure because the company granting access may be removed from the original hiring process.
See the signals before access is granted
imper.ai correlates device, network, virtualization, remote-control and digital identity signals during hiring and onboarding.
