DPRK IT Worker Networks (UNC5267 / Nickel Tapestry)
North Korean state-directed (RGB — Reconnaissance General Bureau) · Revenue generation for DPRK regime via employment fraud / espionage via insider access / extortion post-infiltration
Tactics, Techniques & Procedures (TTPs)
- Employment fraud at industrial scale: thousands of North Korean operatives posed as freelance developers and remote employees across global companies
- Deepfake video and AI-generated profile photos for remote interview fraud — bypassing video verification entirely
- Laptop farm networks: facilitators in the US, Europe, and Southeast Asia receive corporate laptops, connect them to DPRK-controlled infrastructure, and relay sessions to operators overseas
- Post-infiltration escalation: once inside as an "employee," access is expanded to proprietary code, customer data, authentication systems, and cloud environments
- Extortion upon discovery: operatives who detect they are being investigated threaten to publish stolen code or data unless paid
- Legitimate project delivery maintained to avoid detection — operatives genuinely complete work assignments while conducting parallel espionage
- Use of VPNs, multiple remote desktop hops, and cryptocurrency payment channels to obscure true location
Known Targets
Analyst Notes
The DPRK IT worker programme is the world's most successful state-run employment fraud operation, generating an estimated $250M–$600M annually for the regime. Thousands of operatives work across multiple simultaneous jobs, each appearing as an independent contractor. The operation has matured significantly since 2022: deepfake interview technology now bypasses video verification; extortion is now standard when operatives face exposure; and AI-specific targeting (access to LLM API keys, training datasets, and model weights) reflects Pyongyang's strategic interest in AI as both a capability and a revenue source. Multiple US DOJ indictments (2024) and Treasury OFAC sanctions have had limited operational impact as the programme operates from DPRK territory. Companies using remote developers without verified hardware controls, strong identity proofing, and behavioural monitoring represent ongoing exposure.
Also Known As
MITRE ATT&CK Techniques