North Korean IT Worker Threat Center

North Korean IT Workers and Insider Risk

The difficult part of this threat is that the worker may not look malicious. They can use legitimate credentials, perform expected work and stay within assigned privileges while concealing identity, location or who is actually operating the device.

Core insider-risk gap Normal activity can still come from the wrong person.

Behavior can look legitimate even when identity, location or device control is not.

Why traditional insider-risk controls can miss them

A fraudulent worker does not have to behave like a malicious insider. They may be technically capable, follow normal workflows, and stay within the access granted to their role.

Traditional insider-risk question What is this trusted user doing?

Useful for finding unusual downloads, privilege abuse, policy violations, data exfiltration and sudden changes in user behavior.

DPRK IT worker question Is this trusted user actually the person we believe them to be?

The answer may depend on identity, device, network, location, remote-control and hiring signals that sit outside a traditional insider-risk platform.

What can look completely normal

The absence of obviously malicious activity does not establish that the employee behind an account is the person the organization intended to hire.

Writes production codeThe worker may genuinely have the skills needed to perform the assigned role.
Attends meetings and collaboratesNormal participation does not establish the worker’s true identity or location.
Authenticates successfullyApproved credentials and MFA prove account access, not necessarily the human using them.
Stays within assigned privilegesThe employment scheme itself can create risk even without obvious privilege abuse.
Why it matters

Normal work does not make the risk benign

The worker may be productive. The underlying employment scheme can still fund a sanctioned regime and place a concealed operator inside the trusted workforce.

Revenue

U.S. Treasury says DPRK IT worker revenue supports unlawful nuclear, WMD and ballistic-missile programs.

Exposure

The scheme is built around sanctions evasion, creating compliance, legal and reputational risk for victim companies.

Access

Good performance can coexist with legitimate credentials, corporate access and concealed identity or location.

Where the anomaly may actually live

The important signals may appear outside application behavior itself.

Identity

Conflicting identity details, low-activity accounts, VoIP numbers, reused identities or inconsistencies across recruiting stages.

Device

Remote administration tools, unexpected virtualization, inconsistent device characteristics or evidence of a remote operator.

Network

VPNs, layered proxies, latency inconsistent with the claimed geography, or infrastructure linked to known tradecraft.

Workforce process

Unrelated shipping addresses, repeated recovery events, changes in payment information or mismatches between hiring and onboarding.

The signal gap across teams

Each function may see a legitimate-looking fragment. The risk becomes clearer only when those fragments are connected.

Talent acquisitionQualified candidate

Interview and résumé look credible.

+
IdentitySuccessful authentication

Credentials and MFA work normally.

+
IT / Help DeskManaged device

Support events can look routine.

+
Insider RiskExpected behavior

Activity fits the assigned role.

=
Combined viewIdentity risk becomes visible

Device, network and workforce context explain what behavior alone cannot.

No single team has the full picture.

How insider-risk programs should adapt

The goal is not to replace behavioral monitoring. It is to add identity and operating-environment context before and after access is granted.

1

Add pre-access context

Carry recruiting, identity, device and network risk signals into the security program instead of treating hiring as a separate workflow.

2

Connect high-risk events

Correlate onboarding, shipping, device enrollment, account recovery, remote-access and location anomalies.

3

Define escalation paths

Give Talent Acquisition, IT and Help Desk clear criteria for when an administrative inconsistency becomes a security investigation.

4

Verify beyond day one

Re-establish trust during high-risk changes such as device activation, recovery events, access changes and suspicious support interactions.

What imper.ai observed: 4 of 600 candidates

In a Q1 2026 cohort of 600 candidates, imper.ai identified four candidates with overlapping device, network and identity indicators consistent with published DPRK IT worker tradecraft. Signals included Astrill VPN, AnyDesk, layered proxying, location and latency mismatch, VoIP numbers and low-activity email accounts.

Insider-risk FAQ

Why might UEBA not detect a North Korean IT worker?

UEBA is designed to identify unusual behavior. A technically capable worker who performs expected duties using approved credentials may not create a strong behavioral anomaly. The strongest signals may instead come from identity, network, device or workforce-process inconsistencies.

Are North Korean IT workers malicious insiders?

The employment scheme creates insider risk because the worker gains legitimate internal access while concealing material facts about identity, location or affiliation. That does not mean every worker will immediately perform an overtly malicious action after being hired.

What should insider-risk teams monitor?

In addition to user behavior, teams should incorporate device, network, remote-control, location and identity signals, plus high-risk workforce events such as onboarding, equipment shipping, device enrollment and account recovery.

Who should own DPRK IT worker investigations?

There is rarely a single owner. Effective investigations usually require coordination across insider risk, security operations, threat intelligence, identity, IT, Help Desk, Talent Acquisition, HR, legal and, where appropriate, finance.

What should we do if we suspect an existing worker?

Treat the situation as a potential security incident, preserve relevant device and network evidence, review access and remote-control activity, and coordinate security, legal, HR and finance before taking account or employment actions. See the Threat Center’s incident-response guidance for the full workflow.

Extend insider risk to the human behind the account

imper.ai analyzes device, network, virtualization, remote-control and behavioral signals during high-risk workforce interactions.