{"id":22729,"date":"2026-08-20T07:58:36","date_gmt":"2026-08-20T07:58:36","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=22729"},"modified":"2026-08-20T07:58:36","modified_gmt":"2026-08-20T07:58:36","slug":"how-to-protect-organization-against-north-korean-it-workers","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/","title":{"rendered":"North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated <strong>operation that bypasses traditional security perimeters<\/strong>. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recent investigations highlight that <strong>this scheme is no longer limited to the private sector, posing a direct threat to government agencies.<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s how organizations can <strong>defend against this threat effectively<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Escalating Risk of the DPRK Remote Worker Threat<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-1024x1024.png\" alt=\"DPRK Operatives caught\" class=\"wp-image-22474\" style=\"width:668px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-1024x1024.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-300x300.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-150x150.png 150w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-768x769.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-1534x1536.png 1534w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-70x70.png 70w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-370x370.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-270x270.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-740x741.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught.png 1636w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>DPRK Operatives caught by Bitso Quetzal Team while interviewing for a position at the Company<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The primary objective of the DPRK IT worker scheme <a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-attacks-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">operated by the Lazarus APT<\/a> has historically been revenue generation, collectively earning hundreds of millions of dollars annually for the DPRK. However, the <strong>threat has escalated from financial fraud to a direct national security concern<\/strong> as these operatives penetrate the U.S. public sector.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/federalnewsnetwork.com\/technology-main\/2026\/08\/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">FBI is currently investigating a recent case<\/a> where an unidentified U.S. federal agency <strong>unknowingly hired a North Korean remote IT worker<\/strong>. Last year, an individual who facilitated a North Korean national\u2019s work on software development contracts for the Federal Aviation Administration (FAA) <strong>received a prison sentence<\/strong>. Such breaches grant unauthorized actors access to sensitive government systems and proprietary data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The full lifecycle, tools, and operational methods of these infiltrators were exposed in a comprehensive two-part joint investigation conducted by BCA LTD, NorthScan, and <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN<\/strong><\/a>. <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation\/\" target=\"_blank\" rel=\"noreferrer noopener\">In Part 1, researchers gained unprecedented access by posing as facilitators<\/a><\/strong>, deploying custom ANY.RUN sandbox environments disguised as developer laptops to record every click, command, and network connection executed by the operatives in real time. <\/li>\n\n\n\n<li><strong><a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\" target=\"_blank\" rel=\"noreferrer noopener\">In Part 2, the team went a step further by establishing a simulated Web3 startup<\/a><\/strong>, tracking how Famous Chollima operatives collaborate, manage candidate pipelines, share infrastructure, and attempt to embed whole networks of &#8220;ghost developers&#8221; into target companies.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">How DPRK IT worker scheme Operatives Hijack the Personnel Supply Chain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As demonstrated in the<a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\"> investigations<\/a>, threat actors combine stolen identities and artificial intelligence to infiltrate organizations. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Lucas\u2019 Interview\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/dPAjfHr4kzk?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>An interview with a North Korean remote work for a position in a fake DeFi startup<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/dPAjfHr4kzk\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Watch the video on YouTube<\/strong><\/a> and<strong> <a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\" target=\"_blank\" rel=\"noreferrer noopener\">read the full investigation<\/a><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security experts describe this phenomenon as a <strong>critical risk within the personnel supply chain<\/strong>. While companies traditionally focus on defending against external attackers, the North Korean IT worker fraud flips this model by getting hired.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A DPRK IT worker functions as a &#8220;Trojan horse,&#8221;<\/strong> obtaining legitimate credentials, access to internal networks, and corporate resources. This creates a unique insider threat:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Persistent Access to Critical Infrastructure:<\/strong> Unlike traditional cyberattacks that are brief and noisy, an employee is expected to remain in the system, allowing months or years of continuous access to source code and intellectual property.<\/li>\n\n\n\n<li><strong>Malicious Influence on Decision-Making:<\/strong> Once embedded, operatives can influence critical engineering decisions, review code, and approve pull requests, potentially introducing intentional vulnerabilities.<\/li>\n\n\n\n<li><strong>Legitimate Cover:<\/strong> By maintaining a facade of productivity, operatives generate legitimate salaries while gathering intelligence and staging future cyberattacks.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Actionable Steps for SOCs to Detect North Korea Remote IT Workers Infiltration Early<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Standard background checks, especially automated ones, are insufficient to ensure DPRK IT worker detection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Defending against this requires SOC and recruitment teams to adopt a technical vetting model that treats hiring as an attack vector.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Spot Mass Outreach and GitHub Exploitation Tactics<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The initial stage of the North Korean scheme often begins with wide-scale recruitment efforts targeting developers on platforms like Telegram and GitHub.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"963\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-963x1024.png\" alt=\"Angelo\u2019s comment on GitHub looking for facilitators\" class=\"wp-image-22552\" style=\"aspect-ratio:0.9404355812122802;width:680px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-963x1024.png 963w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-282x300.png 282w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-768x816.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-1445x1536.png 1445w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-370x393.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-270x287.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-740x786.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment.png 1592w\" sizes=\"auto, (max-width: 963px) 100vw, 963px\" \/><figcaption class=\"wp-element-caption\"><em>A North Korean operative looking for facilitators on GitHub<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">A highly specific tactic involves recruiters spamming GitHub repositories with fraudulent job offers. These messages are often delivered as <strong>pull requests directly on a developer\u2019s own repositories<\/strong>, making them difficult to ignore.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recruiters seek individuals who appear to have experience working with US companies, offering them &#8220;partnerships&#8221; where they can increase their income by attending interviews on behalf of the operative.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Eliminate Rogue Team Leads from the Hiring Process<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Famous Chollima operations often rely on a key team lead (a &#8220;horse trader&#8221; or agency manager) who acts as the primary point of contact to build trust and scale their footprint inside targeted organizations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Beware of &#8220;Bring Your Own Team&#8221; Offers:<\/strong> A single lead will apply for or land a role, establish rapport with hiring managers, and then offer to recruit, manage, or refer additional developers. Under the guise of a turnkey contracting team, this facilitator brings in multiple North Korean operatives using fake or stolen identities.<\/li>\n\n\n\n<li><strong>Enforce Direct, Individual Vetting:<\/strong> Never permit a single contractor, agency manager, or team lead to bypass individual KYC\/background checks for their referred developers. Every individual applicant must undergo separate, direct identity verification and technical assessment.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Safely Triage Applicant Files and Links with a Sandbox<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Your Security Operations Center (SOC) must actively participate in the vetting process by validating suspicious candidate deliverables before finalizing a hire.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"636\" src=\"\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-1024x636.jpg\" alt=\"\" class=\"wp-image-11084\" style=\"aspect-ratio:1.6101563709552562;width:754px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-1024x636.jpg 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-300x186.jpg 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-768x477.jpg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-370x230.jpg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-270x168.jpg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5-740x459.jpg 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/5.jpg 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>DPRK-linked malware detected and analyzed inside ANY.RUN&#8217;s Interactive Sandbox<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Applicants routinely submit portfolios, code archives, or external links during technical assessments. Opening these directly on internal corporate workstations exposes the network to staging malware (such as <em><a href=\"https:\/\/any.run\/cybersecurity-blog\/ottercookie-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">OtterCookie<\/a><\/em>, <em><a href=\"https:\/\/any.run\/cybersecurity-blog\/invisibleferret-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">InvisibleFerret<\/a><\/em>, and <a href=\"https:\/\/any.run\/cybersecurity-blog\/pylangghost-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">PyLangGhost RAT<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Integrating ANY.RUN\u2019s <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Interactive Sandbox<\/strong><\/a> into the technical vetting and SOC triage and response workflows provides critical security value and operational efficiency:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Uncover Evasive Phishing &amp; Malware in under 60 seconds<\/strong>: Automated tools often miss stealthy malware that requires human interaction. ANY.RUN allows analysts to actively interact with the candidate&#8217;s files and URLs in real time, clicking links and triggering behaviors that reveal hidden payloads.<\/li>\n\n\n\n<li><strong>Ensure Early-Stage Attack Vector Neutralization<\/strong>: Proactive analysis of suspicious objects sent by candidates enables SOC teams to identify malicious intent early and prevent threat actors from ever obtaining legitimate corporate credentials, company laptops, or access to sensitive infrastructure.<\/li>\n<\/ul>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Close malware &#038; phishing visibility gaps in your SOC.<\/span><br>\nDetect threats in <60 sec and cut MTTR by 21 min per case.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&#038;utm_term=200826&amp;utm_content=linktoenterpriseform\/#contact-sales\" rel=\"noopener\" target=\"_blank\">\nIntegrate ANY.RUN<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Inspect Applicant Documents for AI Artifacts and Forensic Inconsistencies<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">North Korean operatives frequently submit manipulated identity documents containing digital creation fingerprints.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"645\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-1024x645.png\" alt=\"Lazarus Angelo's driving license\" class=\"wp-image-22556\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-1024x645.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-300x189.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-768x484.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-1536x968.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-370x233.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-270x170.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2-740x466.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-Angelos-ID-2.png 1698w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>A fake ID card provided by one of the operatives <\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Investigations show forged licenses often contain metadata proving processing via AI tools like Google Gemini, or feature embedded SynthID watermarks.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"543\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-1024x543.png\" alt=\"Lazarus investigation: Angelo\u2019s License Metadata\" class=\"wp-image-22557\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-1024x543.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-300x159.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-768x408.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-1536x815.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-2048x1087.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-370x196.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-270x143.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-License-Metadata-740x393.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>The ID card&#8217;s metadata<\/em> <em>showing it was generated by AI<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Analyze candidate data for geographic discrepancies (e.g., <a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\">claiming residence in Texas while presenting a California driver&#8217;s license and a New York bank account<\/a>). Forensic analysis often reveals stolen authentic photos re-used across multiple applications.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Monitor for AI-Assisted and Suspicious Live Behavior<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Apart from North Korean IT worker AI-generated personas, operatives rely heavily on live translation and dynamic AI prompt generators.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Cough syrup\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/hjpQBRR7lQ4?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>A video of a DPRK operative faking a cough after his AI live translation tool<\/em>&#8216;s<em> malfunction during a call<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/hjpQBRR7lQ4\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Watch the video on YouTube<\/strong><\/a> and <a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>read the full investigation<\/strong><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Watch for off-screen glances, unusual delays before answering technical queries, or physical distractions. In recorded instances, operatives faked medical emergencies or prolonged coughing fits to avoid speaking when translation tools failed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Trace Mule Accounts and Cryptocurrency Infrastructure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Salary exfiltration relies on complex networks of mule accounts, payment intermediaries, and digital wallets designed to route funds back to the DPRK.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Always verify that the account holder&#8217;s name on banking or crypto payment details matches the verified candidate&#8217;s identity. <strong>Operatives frequently request payroll transfers to third-party accounts<\/strong>, domestic facilitators, or mule accounts tied to stolen Social Security Numbers (SSNs) and completely different names.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To bypass traditional banking compliance and international sanctions, operatives push to receive compensation or transfer funds through non-custodial wallets or exchange wallets on platforms.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Analyze Network Markers: Proxies, VPNs, and Jump Boxes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To maintain the illusion of being local U.S. residents, North Korean IT worker tactics involve multi-layered networking designed to hide their origin.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During <a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>the BCA LTD, NorthScan, and ANY.RUN investigation<\/strong><\/a>, researchers successfully exposed operatives&#8217; true locations by asking candidates to scan a QR code during a live interview to access a coding test. Embedded Canary Tokens silently recorded the candidates&#8217; actual IP addresses, User-Agents, and geolocation data, completely bypassing active VPNs like AstrillVPN.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SOC and recruiting teams should closely monitor candidate connectivity and verify real network locations wherever possible:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Track network telemetry, User-Agent strings, and IP locations<\/strong> during video calls, technical assignments, or onboarding tasks to flag proxies and VPN exit nodes.<\/li>\n\n\n\n<li><strong>Enforce strict policies against commercial VPN services<\/strong> (e.g., AstrillVPN) commonly used by Famous Chollima operatives to spoof major U.S. exit nodes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">DPRK IT Worker IOCs<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IPv4: 89[.]187[.]185[.]11 \/\/ DPRK-operated VPS<\/li>\n\n\n\n<li>IPv4: 45[.]77[.]71[.]42 \/\/ DPRK-operated VPS<\/li>\n\n\n\n<li>IPv4: 185[.]152[.]67[.]39 \/\/ DPRK-operated VPS<\/li>\n\n\n\n<li>IPv4: 104[.]250[.]148[.]58 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4: 192[.]200[.]115[.]226 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4: 107[.]150[.]38[.]250 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4: 206[.]217[.]134[.]34 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4:199[.]168[.]112[.]175 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd<\/li>\n\n\n\n<li>0xA3D6938f152C47A411263573Bb3AF324C25A8eba<\/li>\n\n\n\n<li>0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Keep Defenses Updated with Fresh Threat Intelligence <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While North Korean IT worker schemes primarily rely on identity fraud and social engineering, their operations heavily overlap with broader state-sponsored campaigns run by North Korean APT groups (such as Lazarus \/ Famous Chollima). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat actors routinely reuse command-and-control (C2) infrastructure, staging servers, malware delivery domains, and phishing URLs across both cyber espionage and remote worker infiltration schemes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SOC analysts can collect context on indicators from alerts like URLs, file hashes, mutexes, or proactively gather actionable intel on active threats using ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Lookup<\/strong><\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Powered by real-time telemetry contributed by <strong>over 16,000 organizations and 700,000 security professionals worldwide<\/strong>, TI Lookup instantly cross-references indicators against known Lazarus\/Famous Chollima malware samples (such as BeaverTail or InvisibleFerret), phishing infrastructure, and active C2 servers.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"578\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-1024x578.png\" alt=\"\" class=\"wp-image-22753\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-1024x578.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-300x169.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-768x433.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-1536x866.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-370x209.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-270x152.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen-740x417.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/lazrus_ti_lookup_screen.png 1833w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>TI Lookup provides the latest IOCs and other threat intel on Lazarus APT attacks<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For example, running a query like <a href=\"https:\/\/intelligence.any.run\/analysis\/lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookup#{%22query%22:%22threatName:%5C%22lazarus%5C%22%22,%22dateRange%22:180}\" target=\"_blank\" rel=\"noreferrer noopener\">threatName:&#8221;lazarus&#8221;<\/a> reveals numerous indicators belonging to the latest malware campaigns run by Lazarus like TigerRAT and others. SOC teams can use these indicators to enrich their defense systems to identify attacks early and prevent an incident.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"468\" src=\"\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-1024x468.png\" alt=\"\" class=\"wp-image-18792\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-1024x468.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-300x137.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-768x351.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-370x169.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-270x123.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1-740x338.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/monitoring_feeds1.png 1465w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Threat Intelligence Feeds: data, features, integrations<\/em> <\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Security teams can also ingest continuously updated <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Feeds<\/strong><\/a> directly into their SIEM, EDR, and perimeter firewalls. By feeding real-time network indicators (IPs, domains, URLs) gathered from global investigations directly into your security stack, your SOC can automatically block malicious connections and prevent unauthorized data exfiltration.<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Enrich your SOC&#8217;s triage, response, and hunting with actionable threat context. \n <\/span><br>Shorten investigations to stops threats before they become incidents. \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/plans-ti\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&#038;utm_term=200826&amp;utm_content=linktotiplansform#contact-sales\" target=\"_blank\" rel=\"noopener\">\nIntegrate ANY.RUN&#8217;s Threat Intelligence\n<\/a>\n<!-- CTA Link -->\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n.regular-banner__link:hover {\nbackground-color: #FFFFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The North Korean IT worker scheme represents a unique hybrid threat, combining traditional human infiltration, social engineering, identity fraud, and software supply chain risk. Defensive strategies that focus strictly on traditional malware detection are insufficient when an attacker holds valid credentials, corporate devices, and a legitimate seat on your engineering team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protecting your organization requires aligning HR, recruiting, and SOC workflows. By enforcing strict identity verification, monitoring candidate connection telemetry, running interactive file\/link sandboxing during technical assessments, and feeding real-time Threat Intelligence into your security stack, companies and government agencies can stop Famous Chollima operatives before they gain a permanent foothold.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a><\/strong> is a leading provider of interactive malware analysis and threat intelligence solutions, trusted by more than 16,000 organizations and over 700,000 security professionals worldwide.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <strong><a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a><\/strong> enables SOC teams, MSSPs, and threat researchers to analyze malware, suspicious files, URLs, and candidate deliverables in controlled, live virtual environments. By offering full behavioral visibility in under 60 seconds, ANY.RUN helps analysts observe execution chains, capture network traffic, and make fast, confident response decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, <strong><a href=\"https:\/\/intelligence.any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotiservice\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Threat Intelligence<\/a><\/strong> aggregates real-time indicators from global investigations. This allows security teams to enrich local SIEM\/EDR alerts, uncover shared adversary infrastructure, and stay ahead of evolving APT tactics, phishing campaigns, and insider threat schemes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions (FAQ)<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1787177239111\"><strong class=\"schema-faq-question\"><strong>1. Why are North Korean IT workers targeting government agencies and corporate SOCs?<\/strong><\/strong> <p class=\"schema-faq-answer\">Beyond earning revenue for the DPRK, placing operatives inside corporate or public sector organizations grants long-term, persistent access to source code, intellectual property, and internal networks. Operatives can gather intelligence, manipulate software supply chains, and stage future cyberattacks without ever needing to exploit software vulnerabilities.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787177254143\"><strong class=\"schema-faq-question\"><strong>2. How do operatives bypass standard background checks and automated HR screening?<\/strong><\/strong> <p class=\"schema-faq-answer\">Operatives rely on stolen identities, rented Social Security Numbers (SSNs), synthetic personas created with AI tools like Google Gemini, and domestic facilitators who host &#8220;laptop farms&#8221;. Standard background checks confirm that the identity itself exists, but they often fail to verify whether the remote candidate behind the screen is actually the person named in the documents.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787177263630\"><strong class=\"schema-faq-question\"><strong>3. What is a &#8220;laptop farm&#8221; and how does it obscure the operative&#8217;s location?<\/strong><\/strong> <p class=\"schema-faq-answer\">A laptop farm is a physical setup managed by a domestic facilitator (often based in the U.S. or EU). Corporate equipment sent by the employer is delivered to the facilitator&#8217;s address. The facilitator connects the devices to local residential internet and grants the North Korean operative 24\/7 remote desktop access (via AnyDesk, Google Remote Desktop, etc.). This makes all network connections appear to originate from a legitimate local residence.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787177275158\"><strong class=\"schema-faq-question\"><strong>4. How can a SOC safely inspect coding assignments, portfolios, or links sent by candidates?<\/strong><\/strong> <p class=\"schema-faq-answer\">Candidate deliverables should never be opened directly on corporate endpoints. Using an interactive environment like <strong><a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Interactive Sandbox<\/a><\/strong>, SOC teams can open suspicious files, scripts, or URLs in a secure cloud container. Analysts can interactively test the submission, observe process trees, and monitor outbound network connections in real time without risking the internal network.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787177378540\"><strong class=\"schema-faq-question\">5. <strong>How does Threat Intelligence help detect North Korean operative schemes?<\/strong><\/strong> <p class=\"schema-faq-answer\">North Korean remote worker schemes heavily share infrastructure with state-sponsored APT groups like Lazarus (Famous Chollima). Operatives routinely reuse C2 servers, malware delivery domains, phishing links, and malicious code samples (such as <em>BeaverTail<\/em> or <em>InvisibleFerret<\/em>). Cross-referencing candidate links, domains, or infrastructure against <strong><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Threat Intelligence Lookup<\/a><\/strong> and <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Feeds<\/strong><\/a> allows SOC analysts to instantly spot overlaps with known DPRK cyber campaigns and block threats at the perimeter.<\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses traditional security perimeters. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders. Recent investigations highlight that this scheme is no longer limited to the private sector, posing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":22769,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[57,10,58],"class_list":["post-22729","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-lifehacks","tag-anyrun","tag-cybersecurity","tag-cybersecurity-training"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>North Korean IT Workers Scheme: Detection Steps for SOC Teams<\/title>\n<meta name=\"description\" content=\"See actionable steps and IOCs to protect your organization against hiring North Korean IT workers and avoid compromising your infrastructure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs\",\"datePublished\":\"2026-08-20T07:58:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/\"},\"wordCount\":984,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/dprk_workers-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"cybersecurity training\"],\"articleSection\":[\"Cybersecurity Lifehacks\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/\",\"name\":\"North Korean IT Workers Scheme: Detection Steps for SOC Teams\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/dprk_workers-scaled.png\",\"datePublished\":\"2026-08-20T07:58:36+00:00\",\"description\":\"See actionable steps and IOCs to protect your organization against hiring North Korean IT workers and avoid compromising your infrastructure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177239111\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177254143\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177263630\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177275158\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177378540\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/dprk_workers-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/dprk_workers-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"North Korean IT workers\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity Lifehacks\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/lifehacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177239111\",\"position\":1,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177239111\",\"name\":\"1. Why are North Korean IT workers targeting government agencies and corporate SOCs?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Beyond earning revenue for the DPRK, placing operatives inside corporate or public sector organizations grants long-term, persistent access to source code, intellectual property, and internal networks. Operatives can gather intelligence, manipulate software supply chains, and stage future cyberattacks without ever needing to exploit software vulnerabilities.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177254143\",\"position\":2,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177254143\",\"name\":\"2. How do operatives bypass standard background checks and automated HR screening?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Operatives rely on stolen identities, rented Social Security Numbers (SSNs), synthetic personas created with AI tools like Google Gemini, and domestic facilitators who host \\\"laptop farms\\\". Standard background checks confirm that the identity itself exists, but they often fail to verify whether the remote candidate behind the screen is actually the person named in the documents.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177263630\",\"position\":3,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177263630\",\"name\":\"3. What is a \\\"laptop farm\\\" and how does it obscure the operative's location?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A laptop farm is a physical setup managed by a domestic facilitator (often based in the U.S. or EU). Corporate equipment sent by the employer is delivered to the facilitator's address. The facilitator connects the devices to local residential internet and grants the North Korean operative 24\\\/7 remote desktop access (via AnyDesk, Google Remote Desktop, etc.). This makes all network connections appear to originate from a legitimate local residence.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177275158\",\"position\":4,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177275158\",\"name\":\"4. How can a SOC safely inspect coding assignments, portfolios, or links sent by candidates?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Candidate deliverables should never be opened directly on corporate endpoints. Using an interactive environment like <strong><a href=\\\"https:\\\/\\\/any.run\\\/features\\\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding\\\" target=\\\"_blank\\\" rel=\\\"noreferrer noopener\\\">ANY.RUN Interactive Sandbox<\\\/a><\\\/strong>, SOC teams can open suspicious files, scripts, or URLs in a secure cloud container. Analysts can interactively test the submission, observe process trees, and monitor outbound network connections in real time without risking the internal network.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177378540\",\"position\":5,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/how-to-protect-organization-against-north-korean-it-workers\\\/#faq-question-1787177378540\",\"name\":\"5. How does Threat Intelligence help detect North Korean operative schemes?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"North Korean remote worker schemes heavily share infrastructure with state-sponsored APT groups like Lazarus (Famous Chollima). Operatives routinely reuse C2 servers, malware delivery domains, phishing links, and malicious code samples (such as <em>BeaverTail<\\\/em> or <em>InvisibleFerret<\\\/em>). Cross-referencing candidate links, domains, or infrastructure against <strong><a href=\\\"https:\\\/\\\/any.run\\\/threat-intelligence-lookup\\\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding\\\" target=\\\"_blank\\\" rel=\\\"noreferrer noopener\\\">ANY.RUN Threat Intelligence Lookup<\\\/a><\\\/strong> and <a href=\\\"https:\\\/\\\/any.run\\\/threat-intelligence-feeds\\\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding\\\" target=\\\"_blank\\\" rel=\\\"noreferrer noopener\\\"><strong>Threat Intelligence Feeds<\\\/strong><\\\/a> allows SOC analysts to instantly spot overlaps with known DPRK cyber campaigns and block threats at the perimeter.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"North Korean IT Workers Scheme: Detection Steps for SOC Teams","description":"See actionable steps and IOCs to protect your organization against hiring North Korean IT workers and avoid compromising your infrastructure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs","datePublished":"2026-08-20T07:58:36+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/"},"wordCount":984,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/dprk_workers-scaled.png","keywords":["ANYRUN","cybersecurity","cybersecurity training"],"articleSection":["Cybersecurity Lifehacks"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/","url":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/","name":"North Korean IT Workers Scheme: Detection Steps for SOC Teams","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/dprk_workers-scaled.png","datePublished":"2026-08-20T07:58:36+00:00","description":"See actionable steps and IOCs to protect your organization against hiring North Korean IT workers and avoid compromising your infrastructure.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177239111"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177254143"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177263630"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177275158"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177378540"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/dprk_workers-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/dprk_workers-scaled.png","width":2560,"height":1243,"caption":"North Korean IT workers"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity Lifehacks","item":"https:\/\/any.run\/cybersecurity-blog\/category\/lifehacks\/"},{"@type":"ListItem","position":3,"name":"North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177239111","position":1,"url":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177239111","name":"1. Why are North Korean IT workers targeting government agencies and corporate SOCs?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Beyond earning revenue for the DPRK, placing operatives inside corporate or public sector organizations grants long-term, persistent access to source code, intellectual property, and internal networks. Operatives can gather intelligence, manipulate software supply chains, and stage future cyberattacks without ever needing to exploit software vulnerabilities.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177254143","position":2,"url":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177254143","name":"2. How do operatives bypass standard background checks and automated HR screening?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Operatives rely on stolen identities, rented Social Security Numbers (SSNs), synthetic personas created with AI tools like Google Gemini, and domestic facilitators who host \"laptop farms\". Standard background checks confirm that the identity itself exists, but they often fail to verify whether the remote candidate behind the screen is actually the person named in the documents.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177263630","position":3,"url":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177263630","name":"3. What is a \"laptop farm\" and how does it obscure the operative's location?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"A laptop farm is a physical setup managed by a domestic facilitator (often based in the U.S. or EU). Corporate equipment sent by the employer is delivered to the facilitator's address. The facilitator connects the devices to local residential internet and grants the North Korean operative 24\/7 remote desktop access (via AnyDesk, Google Remote Desktop, etc.). This makes all network connections appear to originate from a legitimate local residence.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177275158","position":4,"url":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177275158","name":"4. How can a SOC safely inspect coding assignments, portfolios, or links sent by candidates?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Candidate deliverables should never be opened directly on corporate endpoints. Using an interactive environment like <strong><a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Interactive Sandbox<\/a><\/strong>, SOC teams can open suspicious files, scripts, or URLs in a secure cloud container. Analysts can interactively test the submission, observe process trees, and monitor outbound network connections in real time without risking the internal network.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177378540","position":5,"url":"https:\/\/any.run\/cybersecurity-blog\/how-to-protect-organization-against-north-korean-it-workers\/#faq-question-1787177378540","name":"5. How does Threat Intelligence help detect North Korean operative schemes?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"North Korean remote worker schemes heavily share infrastructure with state-sponsored APT groups like Lazarus (Famous Chollima). Operatives routinely reuse C2 servers, malware delivery domains, phishing links, and malicious code samples (such as <em>BeaverTail<\/em> or <em>InvisibleFerret<\/em>). Cross-referencing candidate links, domains, or infrastructure against <strong><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Threat Intelligence Lookup<\/a><\/strong> and <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Feeds<\/strong><\/a> allows SOC analysts to instantly spot overlaps with known DPRK cyber campaigns and block threats at the perimeter.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=22729"}],"version-history":[{"count":44,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22729\/revisions"}],"predecessor-version":[{"id":22778,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22729\/revisions\/22778"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/22769"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=22729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=22729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=22729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}