North Korean Spies Are Getting Hired as IT Workers. Here Is How to Spot Them.

Security firm Huntress investigated three separate cases in 2026 where North Korean government operatives had successfully applied for, and been hired into, real jobs at Western companies. The red flags they left behind are now a playbook for anyone doing the hiring.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 5 min read
A corporate hiring office or HR workspace with employment applications and background check documents displayed, with suspicious red flags and warning indicator
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Huntress investigated three confirmed or strongly suspected North Korean fake-employee cases across 2026, targeting companies in healthcare and financial services.
  • Workers used tools including Astrill VPN and PiKVM, a small device that lets someone remotely control a computer as if sitting in front of it, to hide their real locations and identities.
  • Identity documents in two investigations had been digitally altered, with one employee's profile photo stolen from a real developer's GitHub account.
  • The North Korean government receives the workers' wages and may also direct them to steal data or plant malicious software once inside a company.
  • Huntress recommends notarised ID documents for new hires and alerts for specific remote-control hardware as first lines of defence.

North Korea runs one of the most unusual criminal enterprises in the world. Rather than breaking into companies the conventional way, the government trains its citizens to apply for remote IT jobs at foreign firms, work the role convincingly, and funnel their salaries back to Pyongyang. Those insiders may also steal sensitive data or install malware, software designed to damage or spy on a company's systems, when the regime requires it.

Security company Huntress spent much of 2026 helping clients figure out whether people on their payroll were who they claimed to be. Three investigations, first reported by Dark Reading, laid out exactly how these operatives get hired and how they slip up. We reported on a related sting in August, when researchers set up a fake crypto company and hired three suspected North Korean workers, recording every keystroke to expose the wage-funnelling scheme.

How did the fake workers get caught?

Patterns gave them away. No single sign was conclusive, but combinations of oddities added up fast.

In February, an Australian healthcare firm grew suspicious of three employees it believed were North Korean nationals posing as Chinese citizens. Huntress pulled six months of login records and activity logs and found all three were using Astrill VPN, a virtual private network service (software that disguises where in the world your internet connection is coming from) already linked to North Korean worker fraud in earlier cases. They had also connected through IPRoyal Proxy, a commercial proxy service that similarly masks a user's location, and routed traffic through WorkTitans B.V., a hosting provider in the Netherlands that was subsequently raided by the Dutch Fiscal Information and Investigation Service.

Two of the three employees' passport scans showed identical errors in the same places. Chinese electricity bills submitted as proof of address contained mistakes that matched across documents, and links on those bills pointed to Arizona Public Service, an American utility company. Somebody had assembled fake paperwork in a hurry and hadn't checked the details.

The August cases turned up different hardware. In both, employees had connected a PiKVM device, a small piece of kit that lets a remote user control a computer at the hardware level, as if physically plugging in a keyboard and mouse. Legitimate corporate users almost never have these. One employee had replaced their profile photo with a picture stolen and altered from a real developer's GitHub account. Another had browser extensions for translating English and coaching English pronunciation, along with one for recording audio and video, and had posted internal Zoom meeting links to a public code-sharing website.

Investigation Month Sector Key indicator
Healthcare firm, Australia February 2026 Healthcare Astrill VPN across all three accounts; mismatched passport errors
Financial partner, investigation 1 August 2026 Financial services PiKVM device; stolen and altered profile photo
Financial partner, investigation 2 August 2026 Financial services PiKVM and Guermok USB devices; English translation and audio extensions

What should hiring managers actually do?

Huntress says the best time to catch a fake worker is before they start.

Background checks, reverse-image searches of submitted photos, and verification of employment history can eliminate many candidates before a contract is signed. For new hires, requiring identity documents to be notarised (checked and stamped by an official who has verified the person is real) raises the cost and difficulty of submitting forged paperwork. Our coverage from August noted that identity verification is now the soft spot attackers are exploiting most aggressively, and these cases confirm it.

Once someone is on staff, IT teams should set automatic alerts for PiKVM and Guermok hardware connecting to company systems. Broad use of VPNs and proxy services across a single user account, especially outside normal working hours, warrants a closer look. Employees who refuse to appear on camera or won't show their surroundings during video calls are worth querying directly; that behaviour surfaced in one of the August cases.

Should ordinary employees be worried?

The immediate risk lands on the companies being defrauded, not their customers. If an operative does steal customer data, though, those customers could see their personal information exposed or sold. Anyone who receives an unexpected notification that their details may have been caught up in a breach at an employer or service provider should change passwords for that account and watch for unusual activity on linked financial accounts.

What matters most here is the operational patience behind these schemes. These workers are skilled enough to hold a job and stay quiet for months. The lag between hire date and detection is where the real damage happens.

© 2026 Threat Vectr