North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
Researchers expose DPRK remote IT worker infiltration tactics, including forged identities and AI-assisted interview behavior.
A joint investigation by Mauro Eldritch, Heiner García, and ANY.RUN hired suspected DPRK developers linked to Lazarus Group into controlled sandboxes, revealing forged IDs, remote-access tools, AI-assisted workflows, and VPN/VPS infrastructure. The FBI is investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. The article outlines verification steps and indicators including VPS and AstrillVPN exit node IPs.