CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

North Korean Remote Workers Infiltrating Government and Businesses: How to Expose Them Before Hiring

August 13, 2026

North Korean IT workers are increasingly infiltrating government agencies and businesses by applying for remote jobs, passing interviews, and obtaining legitimate credentials. A joint investigation by Mauro Eldritch (BCA LTD), Heiner García (NorthScan), and ANY.RUN used controlled sandboxes to observe suspected DPRK developers linked to the Lazarus Group. The operation revealed forged identities, AI-assisted workflows, and VPN/VPS infrastructure. Key red flags include identity inconsistencies, document manipulation, assisted interview behavior, and location mismatches. CISOs are advised to implement deep identity verification, use interactive sandboxes for safe validation, cross-check known infrastructure indicators, and integrate threat intelligence feeds for ongoing detection.

Attack groups: Lazarus Group

Companies: ANY.RUN, BCA LTD, NorthScan

Products: ANY.RUN Sandbox, ANY.RUN Threat Intelligence Lookup, ANY.RUN Threat Intelligence Feeds

Service providers: AstrillVPN