North Korean Spies Are Getting Hired as IT Workers. Here Is How to Spot Them.

Security firm Huntress investigated three separate cases in 2026 where North Korean government operatives had successfully applied for, and been hired into, real jobs at Western companies. The red flags they left behind are now a playbook for anyone doing the hiring.

ThreatVectr Newsdesk· 4 min read
Full-frame overhead view of a cluttered developer's desk at night, glowing keyboard, open laptop showing abstract package manager output as coloured bars, small
Share

Key points

  • Huntress investigated three confirmed or strongly suspected North Korean fake-employee cases across 2026, targeting companies in healthcare and financial services.
  • Workers used tools including Astrill VPN and PiKVM, a small device that lets someone remotely control a computer as if sitting in front of it, to hide their real locations and identities.
  • Identity documents in two separate investigations had been digitally altered, with one employee's profile photo stolen from a real developer's GitHub account.
  • The North Korean government receives the workers' wages and may also direct them to steal data or plant malicious software once inside a company.
  • Huntress recommends notarised ID documents for new hires and alerts for specific remote-control hardware as first lines of defence.

North Korea runs one of the most unusual criminal enterprises in the world. Rather than breaking into companies the conventional way, the government trains its citizens to apply for remote IT jobs at foreign firms, work the role convincingly, and funnel their salaries back to Pyongyang. Depending on what the regime needs, those insiders may also steal sensitive data or install malware, software designed to damage or spy on a company's systems, on their way out.

Security company Huntress spent much of 2026 helping clients figure out whether people on their payroll were who they claimed to be. Three investigations, first reported by Dark Reading, laid out exactly how these operatives get hired and, crucially, how they slip up.

How did the fake workers get caught?

Patterns gave them away. No single sign was conclusive, but combinations of oddities added up fast.

In February, an Australian healthcare firm grew suspicious of three employees it believed were North Korean nationals posing as Chinese citizens. Huntress pulled six months of login records and activity logs and found all three were using Astrill VPN, a virtual private network service (software that disguises where in the world your internet connection is coming from) already linked to North Korean worker fraud in earlier cases. They had also connected through IPRoyal Proxy, a commercial proxy service that similarly masks a user's location, and routed traffic through WorkTitans B.V., a hosting provider in the Netherlands that was subsequently raided by the Dutch Fiscal Information and Investigation Service.

Two of the three employees' passport scans showed identical errors in the same places. Chinese electricity bills submitted as proof of address contained mistakes that matched across documents, and links on those bills pointed to Arizona Public Service, an American utility company. Somebody had assembled fake paperwork in a hurry and had not checked the details.

The August cases turned up different hardware. In both, employees had connected a PiKVM device, a small piece of kit that lets a remote user control a computer at the hardware level, as if physically plugging in a keyboard and mouse. Legitimate corporate users almost never have these. One employee had replaced their profile photo with a picture stolen and altered from a real developer's GitHub account. Another had browser extensions for translating English, recording audio and video, and coaching English pronunciation, and had posted internal Zoom meeting links to a public code-sharing website.

Investigation Month Sector Key indicator
Healthcare firm, Australia February 2026 Healthcare Astrill VPN across all three accounts; mismatched passport errors
Financial partner, investigation 1 August 2026 Financial services PiKVM device; stolen and altered profile photo
Financial partner, investigation 2 August 2026 Financial services PiKVM and Guermok USB devices; English translation and audio extensions

What should hiring managers actually do?

Huntress says the best time to catch a fake worker is before they start.

Background checks, reverse-image searches of submitted photos, and verification of employment history can eliminate many candidates before a contract is signed. For new hires, requiring identity documents to be notarised, meaning checked and stamped by an official who has verified the person is real, raises the cost and difficulty of submitting forged paperwork significantly.

Once someone is on staff, IT teams should set automatic alerts for PiKVM and Guermok hardware connecting to company systems. Broad use of VPNs and proxy services across a single user account, especially outside normal working hours, warrants a closer look. Employees who refuse to appear on camera or who will not show their surroundings during video calls, as one of the August cases involved, are worth querying directly.

Should ordinary employees be worried?

The immediate risk lands on the companies being defrauded, not their customers directly. That said, if an operative does steal customer data, those customers could see their personal information exposed or sold. Anyone who receives an unexpected notification that their details may have been caught up in a breach at an employer or service provider should change their passwords for that account and watch for unusual activity on linked financial accounts.

© 2026 Threat Vectr