How to Detect North Korean Remote Workers Hiding Inside Your Company

Four video interviews. A clean background check. Verified references. A spotless resume for a principal software engineer. Then KnowBe4 shipped the new hire a Mac, and the moment it powered on, it started loading malware. The company published the whole embarrassing story so the rest of us could learn. 

The candidate was a North Korean operative using a stolen US identity.

Most coverage of North Korean remote workers stops at the front door: how they get hired, how they beat verification. That is useful… but it is only Act One. What should worry you is what they do after onboarding. 

This guide covers the DPRK remote IT worker operation end-to-end: the money, the timeline, the hiring pipeline, the post-access tradecraft, and seven detection opportunities you can action this week. Let’s get stuck in!


The Operation Behind the Payroll Fraud

Forget the lone hacker in a basement. This is a state-run staffing agency whose only product is fraudulent labor.

The US Treasury’s Office of Foreign Assets Control (OFAC) has designated Department 53 as a body created by North Korea’s Ministry of National Defense to earn foreign currency through front companies in IT and software development. 

Other reporting ties IT worker delegations to the Munitions Industry Department, the Reconnaissance General Bureau, and the Science and Education Department. This is a distributed revenue machine, not a single unit, and profiling it demands the rigor you would apply to any other state-sponsored threat actor.

You will see the Reconnaissance General Bureau (RGB) named as this program’s parent, usually because the RGB owns the Lazarus Group. Be careful with that shortcut. OFAC’s designations point at the Ministry of National Defense. Use estimative language rather than asserting an org chart the sourcing does not support. 

Scale is where analysts get burned by bad numbers, so here is what primary sourcing says.

The UN Security Council Panel of Experts estimated roughly 3,000 DPRK IT workers abroad plus another 1,000 inside North Korea, generating $250 million to $600 million per year. In March 2026, OFAC put the take at nearly $800 million for 2024 alone, and assesses that the regime withholds up to 90 percent of what these workers earn for weapons of mass destruction and ballistic missile programs.

The salary is not a cover story for espionage. The salary is the mission. Once you internalize that, every strange behavior in this playbook makes sense. 

To understand how to defend against this emerging threat, you first need to know how we got here. Let’s break down the timeline!


Timeline

None of this tradecraft arrived fully formed. It took a decade of sanctions pressure and one global accident.

PeriodShift
2011 to 2013Destructive posture. The March 2013 DarkSeoul wiper disabled roughly 32,000 machines across South Korean banks and broadcasters. No revenue model.
2016 to 2017Sanctions tighten under UN Resolution 2270. The regime pivots to theft, pulling $81 million from Bangladesh Bank via SWIFT. By March 2017, DPRK banks are cut off from SWIFT.
2018 to 2020Freelance genesis. Secureworks traces the campaign tracked as Wagemole to 2018, with operators testing stolen identities on gig platforms.
2020 to 2023COVID. Every company goes remote first, nobody meets engineers in person, and the laptop farm becomes the dominant way in.
2024 to nowThe DOJ launches the DPRK RevGen: Domestic Enabler Initiative and arrests follow. The network does not fold. It relocates to Europe and shifts from collecting a salary to extorting employers.

The 2020 inflection point deserves a second look. A laptop farm needs only a domestic address and a local accomplice. Remote work did not create this threat. It just reduced the friction.

With this in mind, let’s take a look at the technical details.


DPRK Remote IT Workers: Technical Details

The Hiring Pipeline

It all starts with building a convincing identity. Here is a breakdown of the pipeline used to achieve this.

Stage one is identity harvesting. They do not invent people; they buy real ones. Social security numbers, driver’s licenses, and passport scans are pulled from old breaches and broker forums. A clean US identity costs almost nothing against the salary it extracts.

Stage two is account laundering, the part most write-ups skip. Western facilitators rent out a verified identity, sit a drug screen, or show their face on a background check call for a monthly cut. Microsoft has observed Jasper Sleet advertising these roles as legitimate-sounding partnerships.

Stage three is the fabricated footprint. A large language model (LLM) writes the CV, a static host serves the portfolio, and the GitHub profile shows ten years of green squares. However, the squares are fake. Unsigned Git commits let you set any author date you want, so a repository that appears to date from 2011 may have been compiled last year. Pull the commit metadata and the fabrication is visible.

Microsoft tracks DPRK remote IT worker activity as Jasper Sleet (formerly Storm-0287). Secureworks’ Counter Threat Unit tracks the same activity as Nickel Tapestry, which overlaps with Famous Chollima, Wagemole, and Mandiant’s UNC5267. These are not separate groups. They are vendors naming overlapping slices of one program, exactly the kind of thing your threat profiling process must reconcile before a CTI report reaches a consumer. 

Once an identity has been established, the group then needs to defeat the hiring process.

Beating the Interview: Deepfakes and Stand-Ins

There are three layers to bypassing the interview problem.

Layer one is the face. Microsoft has documented Jasper Sleet using face-swapping apps to paste operator faces onto stolen identity documents and generate polished headshots. Secureworks separately observed live streaming tools faking webcam presence.

Layer two is the voice. Microsoft reports voice-changing software used in interviews to flatten regional accents.

Layer three is the stand-in. The person answering your technical questions may not be the person on camera. Microsoft documents operators relying on facilitators to sit interviews for them outright. Assume the voice, the face, and the expertise can each belong to a different person.

Once the group bypasses the technical interview and lands a position, they then pivot to post-hiring tactics, techniques, and procedures (TTPs) to achieve their objectives. 

Post-Hiring TTPs: The Laptop Farm and Hardware KVM

The operator’s core problem is geography. Logging in from an embargoed IP block flags instantly, so they need a clean domestic anchor. That is why the laptop farm exists. Your corporate laptop ships to a US address, where a local facilitator receives it, powers it on, and keeps it online for a monthly fee.

Many operators use a hardware KVM (keyboard, video, mouse) such as a PiKVM or TinyPilot, plugged straight into the laptop’s HDMI and USB ports. The operator connects over the internet, receives a raw video stream of the screen, and the KVM emulates a keyboard and mouse in hardware.

So when the operator types, the laptop sees a locally attached human interface device. So does your EDR. No remote session in the process table, no odd outbound from the host. As far as the endpoint is concerned, someone is sitting at that desk typing.

Because one person often runs three or four jobs at once, they add activity fakers such as mouse jigglers or Caffeine so no machine sleeps and their Slack status stays green.

These are not their only tools. They also use:

Astrill VPN

Documented across Secureworks, Flare, and government reporting as the near-default egress VPN, often layered with residential proxies. Its consistency is itself an indicator.

Personal Cloud Storage

Data exfiltrated to personal Google Drive accounts, often via corporate virtual desktop infrastructure (VDI).

Payment Services

Payoneer, plus repeated payroll changes

Kudelski Security’s research mapped the internal terminology these cells use, including military-style team designations. DTEX analyzed an exposed internal DPRK payment server holding 390 worker accounts, chat logs, and cryptocurrency records tied to OFAC-sanctioned entities. The regime tracks its workforce with the diligence of a payroll department to ensure the cash keeps flowing in.

To understand how this manifests in the real world, let’s explore the case of Christina Chapman.


Case Study: Christina Chapman

Christina Marie Chapman ran a laptop farm from a house in Litchfield Park, Arizona.

In July 2025, the Department of Justice announced her sentence: 102 months, eight and a half years. Her operation defrauded 309 US businesses and two international ones, burned 68 stolen identities, and generated more than $17 million.

She ran it from October 2020 until the FBI raid in October 2023. Agents seized more than 90 laptops from her home, each carrying a note naming its company and stolen identity. She had shipped another 49 devices overseas, including to a Chinese city on the North Korean border.

image
DOJ evidence: Photograph of Chapman’s laptop shelves, each machine labeled with its company and stolen identity.

Here is the number that should reframe your thinking. Chapman billed the North Koreans $176,850 for three years of work, against a scheme that cleared over $17 million. The facilitator captured roughly one percent.

The victim list reads like a stock index: 

  • A top five television network
  • A Silicon Valley tech company
  • An aerospace manufacturer
  • An American car maker
  • A luxury retailer
  • A media company. 
  • Two US government agencies.

Nike identified itself as a victim. In a statement filed before sentencing, Chris Gharst, Nike’s director of global investigations, described paying roughly $75,000 to one operative over five months, plus the investigation that followed.

Chapman was not a hacker. She received parcels, plugged in laptops, forged payroll checks, and filed tax paperwork under other people’s names. The highest impact node in a state intelligence operation was a domestic logistics job. Model your insider threat accordingly. 

Since Chapman’s arrest, the group has shifted from targeting a salary to the company itself. 


Nickel Tapestry: From Salary to Extortion

Here is where it stops being a payroll problem.

Secureworks’ CTU documented a 2024 shift in Nickel Tapestry behavior, from passive revenue collection to active coercion. In one investigation, a contractor began exfiltrating proprietary data almost immediately after starting, moving it to a personal Google Drive through the company’s own VDI.

They were then terminated for poor performance.

Then the emails started. ZIP archives of the stolen documents, followed by a six-figure cryptocurrency ransom demand.

This is not a bluff, and that is the whole point. The data left before you suspected anything. By the time you begin termination, you are not preventing a breach. You are negotiating about one that already happened. Your incident response playbooks should account for that sequence.

Google Threat Intelligence Group has documented the same escalation, noting extortion intensified as US law enforcement pressure grew.

There is a second-order risk most boards have not considered:

  1. An embedded operator holds the access of a trusted engineer
  2. That access has more than one buyer. Sell that channel to a ransomware crew, and nobody breaches your perimeter. 
  3. They walk in on credentials your IT team provisioned, through a device your IT team enrolled.

So, let’s dive into how you can start detecting this emerging threat!


Detection Opportunities

Seven detection opportunities, mapped to where each sits in the cyber kill chain. Hand them to whoever owns your detection engineering lifecycle, and feed gaps back into your intelligence requirements.

Detection 1: GitHub Commit Discrepancy (Pre-Hire)

Clone the candidate’s headline repository and compare author dates against commit dates and signature status. Unsigned commits dated years before the repository’s real activity indicate fabricated history.

Bash
# Author date, commit date, and signature status per commit

git log --all --date=iso --format="%ad | %cd | %G? | %an"

# Repo creation date for comparison

curl -s https://api.github.com/repos/OWNER/REPO | jq .created_at

A %G? value of N means unsigned, which is what makes backdating possible.

Detection 2: Resume Clustering (Pre-Hire)

Compare CV text across your entire applicant pool, not within a single candidate. Secureworks found fraudulent contractors providing references for each other and reusing near-identical resumes. A human reviewer never catches this. Pool-wide text comparison catches it first pass.

    Detection 3: Deepfake Occlusion Tells (Interview)

    Face swap pipelines break on movements outside their training envelope. Ask the candidate to cover their mouth or turn sharply in profile, then watch for jawline slip, ear distortion, or flicker at the hair boundary. Microsoft also flags pixelation around eyes and glasses, and inconsistent facial lighting.

    Detection 4: timezone and number mismatch (Interview)

    Cross-check the phone area code against the stated location and interview slot chosen. A candidate claiming Pacific residence who only books slots convenient for an Asian timezone is worth a second look.

        Detection 5: Hardware KVM hunting (Endpoint)

        PiKVM and TinyPilot default to the display identifier LNX777# in their EDID data, documented by Grumpy Goose Labs and corroborated by SANS Internet Storm Center. On Windows, review Microsoft-Windows-DeviceSetupManager/Admin Event 112 for display connections, not just USB. Caveat honestly: the identifier is user configurable, so absence proves nothing.

          Detection 6: Egress and activity fakers (Network & Process)

          Alert on Astrill VPN egress, matching server ranges rather than the domain alone. Secureworks found that pivoting from AnyDesk and Chrome Remote Desktop session logs to the recorded source IP surfaced Astrill infrastructure directly, so pull remote-access logs even where the tool is policy-approved. 

            Also flag Tailscale outside approved use, plus Caffeine, Amphetamine, or any mouse jiggler as a running process. Anyone needing software to fake activity is breaking policy at best.

            Detection 7: Payroll geography mismatch (Behavioral)

            The laptop farm makes login origin look domestic, but the money trail is harder to fake. A new hire whose device shipped to one state, who logs in from that state, but who routes direct deposit elsewhere, warrants scrutiny.

              Why This Works as a Detection Program

              • Cheap Coverage
                Items one, two, four, and seven cost only a process change, and live in HR, not the SOC.
              • Cross-functional by Design
                This threat lives in the seam between HR, IT, and security, which is why it survives. Detections spanning those teams close it.
              • Hardware Indicators are Expensive to Evade
                Rotating an identity is trivial. Re-architecting the KVM and egress stack is not, putting these high on the Pyramid of Pain.
              • Directly Testable
                Every item validates against telemetry you already collect, making them candidates for Sigma rules and threat hunting hypotheses. 


              Conclusion

              This guide has walked you through how North Korean remote workers get hired, how they stay hidden, and how the scheme escalated into data theft and extortion. Strip away the deepfakes and the laptop farms, and one lesson remains.

              The operator was not running malware. They were a trusted insider using legitimate credentials and your own tooling, which is why your EDR had nothing to say. The most dangerous adversaries do not break in… they blend in.

              That logic is not unique to North Korea. Volt Typhoon runs the same living-off-the-land approach against US critical infrastructure, with dwell times measured in years. If DPRK remote IT workers show why trusted access is the hardest thing to defend, our Volt Typhoon threat profile shows what a state does with that idea when the target is power rather than payroll.

              Go pull those GitHub commit dates. Good luck!

              Frequently Asked Questions

              What Are DPRK Remote IT Workers?

              North Korean nationals who use stolen or fabricated identities to obtain legitimate remote employment at Western companies, mostly in software development. OFAC assesses that the regime withholds up to 90 percent of their salary for weapons programs. Treat them as an insider threat, not a malware problem.

              How Much Money do North Korean Remote Workers Generate?

              The UN Panel of Experts estimated $250 million to $600 million per year. OFAC’s March 2026 designations put it at nearly $800 million for 2024 alone. Estimates vary because operators hold multiple jobs under multiple identities at once.

              What is a Laptop Farm?

              A residence where a domestic facilitator receives, hosts, and powers corporate laptops for overseas operators, giving logins a domestic origin. Christina Chapman’s Arizona farm hosted more than 90 machines serving 309 US businesses.

              Can EDR Detect a Hardware KVM?

              Not directly, and that is the crux of the problem. A hardware KVM emulates a USB keyboard and mouse, so the endpoint registers ordinary local input with no remote session in the process table. Detection relies on device connection telemetry, EDID identifiers such as LNX777#, and egress patterns rather than process behavior.

              Is This an Insider Threat or an External Attack?

              Both, and that ambiguity is why it works. Access is granted legitimately through hiring, making it an insider threat. The operator is a state actor conducting revenue generation, data theft, and potentially access brokering, making it an external campaign. Programs treating these as separate disciplines miss it.