North Korean Remote Workers: Expansion Beyond IT and Concealment Techniques

North Korean workers employed as remote employees are expanding their fields of activity, moving from the IT sector to roles in sales, marketing, and medical professions. The discovery, made by Huntress, reveals a concerning pattern: these workers use fake identities and sophisticated techniques to mask their true location and identity, presenting a significant challenge for corporate security.

Quick Response

  • North Korean workers use VPNs like Astrill and proxies like IPRoyal to hide their location.
  • Fake identity documents, such as passports and ID cards, show technical and visual inconsistencies.
  • Devices like PiKVM and Guermok USB capture card facilitate remote control of corporate computers.

Suspicious Identity Documents: Falsified Passports and ID Cards

In a case in the Australian healthcare sector, Huntress analyzed six months of access logs, discovering that three accounts connected via Astrill VPN and IPRoyal Proxy showed only 50% of activity during working hours. Activity peaks coincided with 9 a.m. in North Korea.

Two workers had uploaded passports, ID cards, and utility bills as proof of identity. The passports had been issued in the same city with a one-day difference, the ID cards had identical validity dates and the same issuing police station. The photos were taken with the same phone model and similar angles, with a few minutes difference.

Investigators noted that both individuals seemed to have accidentally used the same photo on the back of the ID card, based on consistent visible damage between the two images. The utility bills contained the same typos and appeared to be based on an online template, suggesting possible translation or optical character recognition issues.

Suspicious Hardware Devices: PiKVM and Guermok USB Capture Card

In another case, at a financial services company, investigators found a PiKVM device, an open-source Raspberry Pi-based device that allows remote control of a computer, connected to a new hire's laptop a few hours after its delivery to a residential address.

Windows logs showed that the laptop had been moved from a managed service provider's network to a travel router, then to a home Wi-Fi network called “Pickle_Rick”, ending up on a fixed Ethernet connection. This sequence could indicate that the laptop had become part of a “farm” of laptops.

The same laptop also had a Guermok USB capture card connected. This device registered as a webcam on the computer, allowing any video stream to be sent as webcam input in video conferencing applications like Zoom. Although the Guermok device alone is not proof of North Korean involvement, it becomes significant when associated with a PiKVM.

Identity Documents with Altered Photos

In another case, at a partner organization, a worker hired in sales and marketing 13 days earlier seemed to have used the identity information of another person, with the photo replaced. Investigators found a mugshot of a person whose name, date of birth, and place matched the information in the identity documents. The person in the mugshot did not match the photo on the presented identity document. The identification numbers exceeded validity checks, suggesting that the documents contained information belonging to an existing person and had been digitally altered.

Implications for Corporate Security

The threat posed by North Korean remote workers is significant and growing. These individuals do not just steal credentials or exploit vulnerabilities in corporate systems; they are hired directly as employees, often legitimately performing the tasks for which they were hired. This approach makes them difficult to detect and poses a unique risk to information security.

To mitigate these risks, companies must adopt rigorous measures during the hiring process, including in-depth background checks on new hires, online research, and verification of their work histories. Employee awareness and training on identifying potential signs of fraud are equally crucial to prevent these workers from infiltrating organizations.

At this point, it is clear that the challenge is no longer limited to the IT sector. The diversification of roles assumed by North Korean workers requires a holistic approach to corporate security that goes beyond traditional measures to protect computer systems.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.

In the Crypto sector, every investment involves risks: the reader is invited to always inform themselves autonomously before making any decision.