North Korean IT Worker Threat Center
North Korean IT Workers and Insider Risk
The difficult part of this threat is that the worker may not look malicious. They can use legitimate credentials, perform expected work and stay within assigned privileges while concealing identity, location or who is actually operating the device.
Behavior can look legitimate even when identity, location or device control is not.
Why traditional insider-risk controls can miss them
A fraudulent worker does not have to behave like a malicious insider. They may be technically capable, follow normal workflows, and stay within the access granted to their role.
Useful for finding unusual downloads, privilege abuse, policy violations, data exfiltration and sudden changes in user behavior.
The answer may depend on identity, device, network, location, remote-control and hiring signals that sit outside a traditional insider-risk platform.
What can look completely normal
The absence of obviously malicious activity does not establish that the employee behind an account is the person the organization intended to hire.
Normal work does not make the risk benign
The worker may be productive. The underlying employment scheme can still fund a sanctioned regime and place a concealed operator inside the trusted workforce.
U.S. Treasury says DPRK IT worker revenue supports unlawful nuclear, WMD and ballistic-missile programs.
The scheme is built around sanctions evasion, creating compliance, legal and reputational risk for victim companies.
Good performance can coexist with legitimate credentials, corporate access and concealed identity or location.
Where the anomaly may actually live
The important signals may appear outside application behavior itself.
Conflicting identity details, low-activity accounts, VoIP numbers, reused identities or inconsistencies across recruiting stages.
Remote administration tools, unexpected virtualization, inconsistent device characteristics or evidence of a remote operator.
VPNs, layered proxies, latency inconsistent with the claimed geography, or infrastructure linked to known tradecraft.
Unrelated shipping addresses, repeated recovery events, changes in payment information or mismatches between hiring and onboarding.
The signal gap across teams
Each function may see a legitimate-looking fragment. The risk becomes clearer only when those fragments are connected.
Interview and résumé look credible.
Credentials and MFA work normally.
Support events can look routine.
Activity fits the assigned role.
Device, network and workforce context explain what behavior alone cannot.
No single team has the full picture.
How insider-risk programs should adapt
The goal is not to replace behavioral monitoring. It is to add identity and operating-environment context before and after access is granted.
Add pre-access context
Carry recruiting, identity, device and network risk signals into the security program instead of treating hiring as a separate workflow.
Connect high-risk events
Correlate onboarding, shipping, device enrollment, account recovery, remote-access and location anomalies.
Define escalation paths
Give Talent Acquisition, IT and Help Desk clear criteria for when an administrative inconsistency becomes a security investigation.
Verify beyond day one
Re-establish trust during high-risk changes such as device activation, recovery events, access changes and suspicious support interactions.
What imper.ai observed: 4 of 600 candidates
In a Q1 2026 cohort of 600 candidates, imper.ai identified four candidates with overlapping device, network and identity indicators consistent with published DPRK IT worker tradecraft. Signals included Astrill VPN, AnyDesk, layered proxying, location and latency mismatch, VoIP numbers and low-activity email accounts.
Insider-risk FAQ
Why might UEBA not detect a North Korean IT worker?
UEBA is designed to identify unusual behavior. A technically capable worker who performs expected duties using approved credentials may not create a strong behavioral anomaly. The strongest signals may instead come from identity, network, device or workforce-process inconsistencies.
Are North Korean IT workers malicious insiders?
The employment scheme creates insider risk because the worker gains legitimate internal access while concealing material facts about identity, location or affiliation. That does not mean every worker will immediately perform an overtly malicious action after being hired.
What should insider-risk teams monitor?
In addition to user behavior, teams should incorporate device, network, remote-control, location and identity signals, plus high-risk workforce events such as onboarding, equipment shipping, device enrollment and account recovery.
Who should own DPRK IT worker investigations?
There is rarely a single owner. Effective investigations usually require coordination across insider risk, security operations, threat intelligence, identity, IT, Help Desk, Talent Acquisition, HR, legal and, where appropriate, finance.
What should we do if we suspect an existing worker?
Treat the situation as a potential security incident, preserve relevant device and network evidence, review access and remote-control activity, and coordinate security, legal, HR and finance before taking account or employment actions. See the Threat Center’s incident-response guidance for the full workflow.
Extend insider risk to the human behind the account
imper.ai analyzes device, network, virtualization, remote-control and behavioral signals during high-risk workforce interactions.
