Skip to main content

Protecting Your Organization from Fraudulent Remote IT Workers

Fraudulent remote IT workers represent a significant and evolving threat to organizations globally. While this issue can involve various malicious actors, a particularly sophisticated and widespread form is the scheme orchestrated by the Democratic People’s Republic of Korea (DPRK).

Thousands of highly skilled DPRK IT workers are dispatched worldwide or operate remotely from within the DPRK to generate revenue for the regime, specifically funding its weapons of mass destruction (WMD) and ballistic missile programs, in violation of U.S. and UN sanctions.

They exploit the demand for IT skills by obtaining freelance or full-time remote employment contracts from companies around the world, posing as non-North Korean nationals from locations like South Korea, China, Japan, Eastern Europe, or the U.S. They deliberately obfuscate their identities, locations, and nationality using fake or stolen identities, counterfeit documents, VPNs, proxies, intermediaries, and by avoiding video communication. This scheme is a complex, industrial-scaled nation-state operation supported by an ecosystem of services for document forgery, identity theft, and money laundering.

The potential impact and consequences of inadvertently hiring these fraudulent workers are severe and multi-faceted. Organizations face significant financial risks, including outright theft through fraudulent transactions or siphoning wages, as observed in cases involving theft of over $50,000 in small installments or illicitly gained revenue laundered through foreign bank accounts. Beyond financial fraud, these workers pose serious cybersecurity threats, potentially acting as insider threats. They can use privileged access gained as contractors to enable malicious cyber intrusions, share access to virtual infrastructure, facilitate the sale of stolen data, assist with money laundering and virtual currency transfers, and procure WMD-related items. They may introduce backdoors, steal proprietary information and intellectual property, disrupt business operations, or facilitate larger cyber operations. Recently, they have been observed intensifying extortion campaigns against employers who discover their true identity, threatening to release sensitive stolen data. Furthermore, inadvertently hiring or supporting DPRK IT workers can lead to reputational harm and significant legal consequences, including sanctions designation under U.S. and UN authorities, potentially resulting in fines, imprisonment, loss of financial accounts, and inability to work with U.S.-based entities. The scheme also involves human trafficking and forced labor, as workers are often subjected to excessive hours, surveillance, poor conditions, and have up to 90% of their wages withheld by the North Korean government. Most critically, enabling this activity directly contributes to funding North Korea’s sanctioned military programs, making it a national security concern that extends beyond individual companies to the broader global financial system.

To protect against potential exposure to these scams, organizations must adopt rigorous and layered security measures. Key strategies include:

  • Stringent Identity Verification: Require video interviews and verify identity through notarized documents and trusted services like E-Verify. Check inconsistencies across profiles, documents, and stated locations. Consider requiring physical IDs held up during video calls or even fingerprint/biometric verification.
  • Thorough Background Checks and Due Diligence: Go beyond standard checks. Verify employment and education history directly with the listed institutions using contact information obtained independently. Scrutinize documents for forgery. If using staffing firms, request documentation of their background check processes and consider conducting your own checks on individuals provided.
  • Enhanced Technical Controls: Implement measures like preventing remote desktop use on company devices, installing insider threat monitoring software, and regularly geolocating company laptops to verify they match login locations. Monitor and restrict the use of VPNs, remote administration tools, and IP-based KVM devices. Use hardware-based multi-factor authentication.
  • Robust Policies and Training: Implement Zero Trust and Need-to-Know policies to restrict access to sensitive data. Educate HR staff, hiring managers, IT security personnel, and all employees about the threat and red flag indicators. Use only reputable online platforms with robust identity verification measures.
  • Vigilant Communication and Work Practices: Be cautious of requests to communicate outside official platforms or to send equipment to addresses not listed on identification documents. Monitor activity against expected work hours and require employees to be on camera during remote interactions.
  • Financial Precautions: Avoid payments in virtual currency and verify banking information corresponds to other identification. Watch for unusual or small-scale transactions.
  • Information Sharing and Reporting: Stay informed about evolving tactics. Report suspicious activities and any suspected DPRK IT worker activity to relevant authorities like the FBI. Organizations are encouraged to share their experiences (anonymously if necessary) to help others.

This is a serious fraud and national security concern that requires rigorous identity verification, enhanced remote work security, and intelligence sharing to counter evolving tactics

Given the sophisticated and evolving nature of this threat, a helpful next step would be to analyze the specific IT roles your organization commonly hires for remotely and map the technical and human-centric mitigation measures to the unique risks associated with those positions and the platforms typically used for recruitment.


📝 Protecting Your Organization from Fraudulent IT Workers Checklist, https://bit.ly/42ZTGz9

References

➡️ Inside the Scam: North Korea’s IT Worker Threat, https://bit.ly/4cMc6a4

➡️ The ultimate insider threat: North Korean IT workers, https://bit.ly/3S7KmD2

➡️ North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn, https://bit.ly/3YgC6V4

➡️ North Korean IT worker scam spreading to Europe after US law enforcement crackdown, https://bit.ly/3Rwk9hn

➡️ North Korean Fake Employees Are Everywhere! How to Protect Your Organization, https://bit.ly/4jJmem3

➡️ Additional Guidance on the Democratic People’s Republic of Korea Information Technology Workers, https://bit.ly/3GjPaTz

📺 Massive North Korean Fraud Planted Tech Workers, Hit 300 U.S. Companies, https://bit.ly/42J9m8H

Comments

Popular posts from this blog

Skype for Business and VTC Interoperability

Skype for Business (SfB) has a very, very strong potential, I have written about it in my previous post . I can't think of any other platform that shows as much promise in terms of bridging personal and business communications as well as unifying different modes and mediums. And all of this may have started with a strategic acquisition of Skype by Microsoft in 2011. That said, the road ahead is not without challenges. For example, interoperability with other platforms. Making SfB work with existing Video TeleConferencing (VTC) systems, many of which represent significant capital investments in organizations' infrastructure, could be of a particular importance. After reading statements like Skype for Business is based on Session Initiation Protocol (SIP) standards and supports H.264 (MPEG-4 video coding standard) one can come to a quick conclusion that integration and/or interoperability with other VTC solutions is easy or nearly automatic. Unfortunately, the industry is not...

WordPress displays weird characters

Sometimes after a database conversion (e.g. from MySQL to MariaDB) or due to encoding issues a situation might arise when WordPress is showing weird characters. A quick way of remedying the situation would involve examining the pages to discover a pattern (what characters are being substituted, in the example below the apostrophe was replaced by  ’ ) then running an queries against the database to reverse the effect. Here's a quick example (common tables that store content): UPDATE  wp_posts  SET  post_content =  REPLACE (post_content,  'Â' ,  '' )      UPDATE  wp_posts  SET  post_content =  REPLACE (post_content,  '’' ,  "'" )      UPDATE  wp_postmeta  SET  meta_value =  REPLACE (meta_value,  'Â' ,  '' )      UPDATE  wp_postmeta  SET  meta_value =  REPLACE (me...

IBM-Apple deal and its impact on Microsoft

IBM and Apple may seem to be the unlikeliest of partners at first, but the relationship truly is mutually beneficial – highlighting individual strengths (Apple – devices and ecosystem, IBM – enterprise capabilities and services) while avoiding competition (IBM is out of the device business, Apple is not particularly strong in the enterprise). This would not have been possible with IBM and Microsoft (both are competing in the enterprise market) or Apple and Microsoft (both are competing in mobile market). So, on the surface it appears to be a very important deal for the enterprise customers. It is also a deal that needs to be watched carefully as things develop (a somewhat similar arrangement between IBM and Palm did not generate much success). Read more on this subject here - Why the Apple-IBM deal matters How does this impact Microsoft? To a degree, though I don't think the impact is going to be very profound (something I can't say about other enterprise mobility players, ...