Expert advice: notice these red flags and don’t hire a worker from North Korea
The forensic trail is genuinely wild, Huntress researchers say.

North Korean operatives keep getting hired by real organizatons. By Cybernews
- Huntress says it helped companies identify 5 suspected North Korean remote IT workers in 2026.
- Operatives used fake IDs, altered photos, VPNs, and proxy services to hide their identities and locations.
- Unusual work hours and remote-control devices can help employers spot suspicious accounts earlier.
- Huntress says faster detection can reduce risks of data theft, malware, and extortion.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
After uncovering 5 separate cases this year where North Korean operatives were successfully hired by real companies, Huntress researchers have concluded that it wasn’t even very difficult to do. It’s as if the fake remote hires are walking through the front door.
For years now, North Korean operatives have used fake or stolen identities to get hired at companies before sending their wages back to the regime, stealing data, or planting malware.
Irregularly, authorities across countries that the regime targets successfully disrupt these operations.
For instance, in November last year, the US Department of Justice announced that 5 people pled guilty to helping North Korean actors obtain remote IT employment with US companies to commit fraud.
And earlier this month, the FBI disclosed that a North Korean was even hired as a remote IT worker by a US government agency and worked there for several months.
Since Pyongyang can essentially train thousands of such operatives for similar missions, though, the stories of successful infiltrations keep appearing.
ID documents, VPNs, and weird activity hours
Lack of vigilance by hiring organizations is also at fault, cybersecurity firm Huntress said after announcing that it helped different companies to track down 5 North Korean workers in 2026 alone.
“These aren’t hackers breaking in. They're walking through the front door, getting onboarded, and doing the job, all while wiring their wages back to the regime,” Huntress said in a blog post.
Breaking down their investigations, researchers admit it’s challenging for the defenders to detect such remote workers because they’ve been hired just like normal employees.
Plus, “they’re not compromising legitimate accounts and oftentimes use VPNs and proxy services to mask their true locations,” says Huntress, adding that it has seen the impersonators use Astrill VPN more specifically.
Has your password leaked?
Nevertheless, it’s important to understand the broader modus operandi of these operatives to at least try to prevent them from gaining employment altogether.
For 3 of the 5 North Korean workers it has sniffed out, Huntress obtained and reviewed suspected fraudulent ID documents that helped to determine that they were unlikely to be legitimate individuals.
In fact, 2 allegedly different new “hires” had ID documents issued by the same Chinese police station, one day apart, and somehow photographed 8 minutes apart on the same iPhone. Obviously, the hiring firms missed this.
For another worker, Huntress identified a photo that had been stolen from a legitimate GitHub account where the face had been altered, and yet another was secretly using Raspberry Pi-based remote KVM device to control a company laptop from thousands of miles away before the security software was even installed.
Technical and identity signals
The North Korean operatives also extensively use VPN and proxy infrastructure to hide their real geolocations.
Even though the use of a VPN by itself is not a reliable indicator of compromise, one should look out for less-than-expected activity during usual business hours in the US. If peak activity overlaps with business hours in North Korea, you’ve got a fake worker on your hands.
Some other red flags include the suspicious workers using PiKVM, an open-source, Raspberry Pi-based KVM-over-IP device, and Guermok, a video capture card – particularly when they’re both used by user accounts.
Additional breadcrumbs are web services and browser extensions associated with screen, audio, and video redirection or recording, microphone testing, translation, and file sharing.
“We saw suspicious processes associated with browser-based screen streaming, like VDO.Ninja, Chrome plugins for recording tabs, and Toffeeshare for sending files. We also saw the threat actors using online microphone and webcam testing sites,” says Huntress.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The researchers also saw the threat actors publicly sharing their recurring Zoom meetings on Codeshare, a public codesharing service.
“Correlated technical and identity signals can help organizations uncover suspected activity earlier and respond before access is used for data theft, malware deployment, or extortion,” Huntress concludes.