Blog

The IT Crowd of North Korea:

How the DPRK has made billions using their tech-savvy citizens to commit cybercrimes.

When COVID-19 swept the world trapping everyone in their homes, many careers were saved by a sudden shift to remote work. Even years after the pandemic, remote jobs make up a large percentage of the positions companies offer, especially in the computer industry. However, this timely surge in remote work was also the perfect opportunity for a certain type of cybercriminal to flourish: the North Korean IT worker.

These IT workers from the Democratic People’s Republic of Korea (DPRK) will go to great lengths crafting an American persona that they use to get hired at Western companies. Once hired, these workers are used by their authoritarian regime to generate money for the DPRK’s nuclear weapons program or simply to steal data and cryptocurrency. According to the “CrowdStrike 2025 Threat Hunting Report”, from the cybersecurity giant Crowdstrike, in the last 12 months they have investigated over 320 incidents of Famous Chollima (their general term for DPRK-nexus cybercriminals) infiltrating Western companies as remote IT workers, a startling 220% increase in such incidents from the year before.

How They Operate

Famous Chollima is particularly proficient in using generative AI at each stage of infiltrating a company. To get interviews at companies they will use genAI to create attractive resumes for synthetic identities, even going as far to create fake social media accounts to make their identities seem more legitimate. Once they get an interview, they will use AI to craft desirable answers to any interview questions they are asked, and will often go so far as to deepfake their appearance over a video call. Finally, once they are on the job they will use AI for assistance in daily tasks, to enable communication in English, and to manage streams of communication from different jobs, since these workers often work three or four jobs simultaneously.

Another crucial aspect of Famous Chollima’s operation is their reliance on US-based laptop farms facilitated by in-country associates. When a North Korean IT worker needs a company laptop for their job, they will give the company the address of one of these farms. Once the laptop arrives, their associate sets up a remote access connection that the IT worker can use to do their work from across the world.

Efforts to Stop Them

Unsurprisingly, the United States has taken several actions to counter this surge of ill-intentioned IT workers. In 2023, the US levied several sanctions against four entities that reportedly employed “thousands” of these workers. Then, this year the US has indicted several individuals who helped run this scheme from within the country, including people who ran some of the aforementioned laptop farms that these IT workers rely on.

But if Crowdstrike’s report is any indicator, this scheme will probably continue being a major threat to Western companies. The DPRK has likely made billions of dollars using their tech-savvy citizens like this, so there is little incentive for them to stop.

What do we do?

CrowdStrike put this piece of advice in their introduction: “Innovation is a critical cornerstone to outmaneuver and disrupt the enterprising adversary. Novel technologies and threat hunting are required to anticipate the adversary’s next moves, understand their evolving methodologies, and adapt defenses to stay ahead.” At Crimson Vista, we offer such “novel technologies” as well as services that can improve your cyber safety and threat hunting capabilities. For instance, our SecurityHub service offers opportunities to train, guide, and even augment your cybersecurity team to better handle advanced cybersecurity issues, including ones related to Artificial Intelligence. These illicit IT North Korean IT workers may be persistent, but with the right security attitude, you can always stay one step ahead of them.

Sources:

  1. CrowdStrike 2025 Threat Hunting Report
  2. Remote Work Productivity
  3. US Government Targets North Korea’s Illicit IT Workforce
  4. US Indicts Five Individuals in Crackdown
  5. Two North Korean Nationals Indicted
  6. US Government Takes Down Major Operation
  7. North Korean Spies Posing as Remote Workers
  8. North Korean Hackers Have Stolen Billions
  9. North Korea’s Cybercrimes Pay for Weapons Programs

Continue

Keep reading.