North Korean IT workers are increasingly infiltrating government agencies and businesses by applying for remote jobs, passing interviews, and obtaining legitimate credentials. A joint investigation by Mauro Eldritch (BCA LTD), Heiner García (NorthScan), and ANY.RUN used controlled sandboxes to observe suspected DPRK developers linked to the Lazarus Group. The operation revealed forged identities, AI-assisted workflows, and VPN/VPS infrastructure. Key red flags include identity inconsistencies, document manipulation, assisted interview behavior, and location mismatches. CISOs are advised to implement deep identity verification, use interactive sandboxes for safe validation, cross-check known infrastructure indicators, and integrate threat intelligence feeds for ongoing detection.
Attack groups: Lazarus Group
Companies: ANY.RUN, BCA LTD, NorthScan
Products: ANY.RUN Sandbox, ANY.RUN Threat Intelligence Lookup, ANY.RUN Threat Intelligence Feeds
Service providers: AstrillVPN
Original source: thehackernews.com