Inside the DPRK: Spotting Malicious Remote IT Applicants

May 21, 2025, 8:18 p.m.

Description

The Democratic People’s Republic of Korea (DPRK) deploys skilled IT workers remotely to organizations globally funding its weapons of mass destruction (WMD) and missile programs, violating sanctions. In recent weeks, the techniques leveraged to evade detection have evolved, reducing reliance on traditional “laptop farms”. The threat has also expanded beyond the U.S. with active operations within Europe and other regions. Included is a list of emails that are tied and associated with DPRK Insider IT Worker infrastructure that may have been used for potential employment opportunities.

Date

  • Created: May 15, 2025, 1:26 p.m.
  • Published: May 15, 2025, 1:26 p.m.
  • Modified: May 21, 2025, 8:18 p.m.

Indicators

Attack Patterns

Additional Informations

  • United Kingdom of Great Britain and Northern Ireland
  • United States of America