Executive Summary
North Korea is operating one of the most structurally unusual cyber threat programmes in the threat landscape: a programme that does not begin with an exploit or a phishing email, but with a job application. Thousands of DPRK operatives, using AI-generated identities, scripted interview responses, and laptop farm infrastructure, are posing as skilled remote software developers and securing employment at technology, financial services, healthcare, and defence companies across the United States, Europe, and beyond.
The programme generates an estimated $350 million to $800 million in annual revenue for the North Korean regime — revenue that directly funds weapons development. But in 2025 and 2026, the threat has mutated: operatives are no longer just quietly collecting paycheques. They are conducting corporate espionage, exfiltrating proprietary source code, and in documented cases, extorting the companies that employ them after their covers are blown.
For enterprise security teams and HR functions, this threat sits uncomfortably outside traditional cybersecurity frameworks. The initial access vector is not a vulnerability. It is a CV.
Threat Actor Profile
The DPRK IT worker programme is not a single unit but a coordinated network of operatives managed and tasked by North Korean intelligence and military organisations — primarily the Reconnaissance General Bureau (RGB), which oversees DPRK foreign intelligence operations.
Mandiant tracks the programme’s operational infrastructure as UNC5267. Secureworks designates the activity cluster as Nickel Tapestry. The FBI and DOJ have referred to the broader network in indictments as the “DPRK IT Worker” scheme, implicating front companies based in China, Russia, Laos, and Southeast Asia that serve as operational hubs for workers and payment processing.
The scale is significant. US government estimates suggest tens of thousands of DPRK operatives are actively engaged in fraudulent remote employment. The programme has been operating since at least 2018, but enforcement attention and public documentation accelerated significantly after 2022.
TTPs and Tradecraft
Identity Construction
DPRK IT worker identities are systematically constructed to pass standard employment vetting. Operatives maintain multiple personas simultaneously — typically three to five active identities per operator — spread across platforms including LinkedIn, GitHub, Upwork, Freelancer, and Fiverr.
Profile photos are AI-generated using GAN-based face synthesis tools, producing faces that appear authentic in profile photos but fail certain deepfake detection tools. CVs are similarly AI-assembled, drawing on real public repositories and incorporating plausible employment histories at verifiable (but often defunct) companies.
By 2026, generative AI has become a force multiplier at every stage of the deception:
- Resume tailoring: AI generates targeted CVs matching specific job descriptions, incorporating relevant technical terminology and matching requested skills precisely
- Interview preparation: AI scripts responses to common technical interview questions; operatives rehearse using LLM-generated mock interview transcripts
- Real-time assistance: During live video calls, some operatives use AI-generated voice modification and maintain concealed screens with AI-assisted response prompts
- Content translation: English-language communications are refined by AI, removing the grammatical patterns that previously helped analysts identify non-native writers
Deepfake video has not yet fully replaced live video interviews — the latency and artefact issues remain detectable by alert interviewers — but partial synthetic enhancement of live video is documented.
Operational Infrastructure
Once hired, DPRK IT workers use several mechanisms to maintain their covers while routing access and payments safely.
Laptop farms: US-based facilitators (some witting, some unwitting) host physical laptops at residential or commercial addresses. The operative accesses the laptop remotely via RDP, VPN, or commercial remote access tools (AnyDesk, TeamViewer, Splashtop). The laptop farm address serves as the operative’s apparent US location. FBI raids in Nashville and Arizona in 2024 uncovered laptop farms running dozens of devices.
RMM tool persistence: During employment, operatives may install additional remote access tools under the guise of IT requirements. These tools provide persistent access independent of the original employment. In documented extortion cases, this access was retained after termination and used to threaten the company.
Payment routing: Operatives direct cryptocurrency payments rather than USD wire transfers where possible. When fiat payment is unavoidable, complex routing through facilitators, shell companies, and cryptocurrency conversion services obscures the final destination. Several documented cases used payment platforms that do not conduct OFAC screening.
Escalation to Espionage and Extortion
In 2025 and 2026, the programme’s threat profile escalated materially. Three distinct escalation modes have been documented:
-
Proprietary IP theft: Operatives with developer access exfiltrate source code, algorithm documentation, and product roadmaps during employment. The exfiltrated material is believed to support North Korean domestic technology development and potentially sold on criminal markets.
-
Credential collection: IT workers with legitimate access to internal systems — particularly CI/CD pipelines, cloud infrastructure, and repository services — collect credentials during employment for later use or transfer to other DPRK threat actor clusters.
-
Post-termination extortion: When an operative’s cover is blown, the response in multiple documented cases has been extortion rather than departure. The operative, retaining access via pre-planted RMM tools or stolen credentials, threatens to release sensitive data or grant access to competitors or criminal groups unless the company pays a ransom. This behaviour was reported in cybersecurity sector targets in 2025, creating a particularly uncomfortable dynamic given the reputational sensitivity.
Targeting Profile
The programme’s targeting has evolved from opportunistic freelance work toward strategic employment objectives:
Technology and software companies represent the highest-volume targets. Developer roles offer legitimate access to source code, cloud infrastructure, and product data. Equity compensation (stock options) provides financial upside beyond salary. Remote-first hiring cultures reduce in-person vetting.
Cryptocurrency and financial services firms are targeted for both revenue generation and intelligence collection on DeFi protocols, smart contract vulnerabilities, and institutional crypto holdings. Lazarus Group’s concurrent operation (TraderTraitor, which conducts direct crypto theft via social engineering) creates a parallel but distinct threat vector.
Defence contractors and government-adjacent organisations represent high-value intelligence targets. CSIS documented operatives applying to roles at European defence contractors and government-related organisations in Germany, Portugal, and the United Kingdom. These applications prioritise intelligence access over revenue.
Healthcare and biotechnology firms have become increasingly targeted as North Korea’s domestic healthcare sector development priorities expanded.
Historical Incidents and Enforcement Actions
The enforcement record against the DPRK IT worker programme is documented but incomplete:
2023: The US DOJ indicted multiple North Korean nationals and their US-based facilitators for wire fraud, money laundering, and sanctions violations related to IT worker schemes. Front company networks in China were identified as operational hubs.
2024: FBI raids in Nashville and Arizona dismantled two laptop farm operations with dozens of devices. Witting facilitators were arrested and subsequently prosecuted.
2025: Enforcement expanded internationally, with UK authorities issuing advisories about North Korean IT workers targeting British companies, including tech firms and financial services. The Home Office issued guidance to recruitment agencies.
2026: The threat intelligence community documented the first widespread extortion incidents following termination, elevating the programme from a financial crime threat to a direct security incident vector. Skadden published a legal advisory in June 2026 noting that companies employing DPRK IT workers — even unknowingly — may face OFAC sanctions exposure and UN sanctions violations.
Geographic Expansion
The programme has deliberately expanded geographically to reduce dependence on the US market. The European expansion brings specific risks: EU member states have weaker sanctions monitoring frameworks than the US for employment payments, DPRK operatives have registered on EU-based employment platforms using EU identity documents (some forged, some obtained through identity theft), and data protection regulations in some jurisdictions restrict background screening that would catch the inconsistencies in DPRK-constructed identities.
The UK, given its tech sector concentration and remote work penetration, is a priority target. NCSC and the Home Office have both issued warnings, but awareness among SMEs and scale-up companies remains low.
Defensive Implications
HR and Recruitment Controls
The first line of defence is not in a SOC — it is in HR. Controls that reduce exposure:
Device control: Require company-issued devices with MDM enrollment for all remote positions. Prohibit remote desktop software on those devices that is not company-managed. This directly counters laptop farm operations and blocks the operative’s ability to access the company device from a separate physical location.
Video call authentication: Mandate live, unfiltered video in interviews. Request candidates to perform spontaneous actions (turn head, move camera angle, hold up physical ID) that defeat deepfake implementations with current latency constraints. Some companies have moved to in-person or hybrid onboarding requirements for all roles with significant code or infrastructure access.
Background verification: Use background screening providers with OFAC and sanctions list checking. Request physical mail delivery confirmation to apparent address — laptop farms are often detected by delivery mismatches. Check claimed employment history with specific calls to HR departments at named employers, not just email verification.
Payment method scrutiny: Be alert to candidates who prefer cryptocurrency payment, routing through unusual payment platforms, or payment to third parties rather than personal bank accounts.
Technical Controls
For operatives who do succeed in obtaining employment, the technical control environment should limit their access and detect anomalous behaviour:
Least privilege access: Developer roles should not carry cloud console access, production deployment rights, or access to unrelated repositories by default. Formal access review processes reduce the intelligence value of any single compromised position.
Endpoint monitoring: MiTree, UBA/UEBA tools, and DLP policies should alert on large code repository cloning, bulk file access, and connections to unusual external storage services.
Off-boarding procedures: Immediate revocation of all access, including credential rotation for shared systems, on the same day as any termination where IT worker fraud is suspected. Do not permit the standard two-week access continuation common in legitimate off-boarding.
Legal and compliance review: Any confirmed or suspected DPRK IT worker situation should trigger immediate counsel engagement for sanctions exposure assessment. OFAC and UN sanctions violations carry significant penalties, and proactive voluntary disclosure is the most favourable posture in the event of inadvertent employment.
The DPRK IT worker programme is operationally mature, geographically expanding, and increasingly willing to escalate beyond revenue collection to active extortion. It is a threat that requires cross-functional response — not just a security problem, but an HR, legal, finance, and compliance one simultaneously.