Hackfest - Level UP

Inside the North Korean Infiltrator Threat
Langue: English

The sun rises over Pyongyang, and a new shift begins for a global, remote IT workforce you likely employ. While the cybersecurity community tracks sophisticated state-sponsored actors, a quiet, effective army of North Korean IT workers has infiltrated Western organizations to evade sanctions and fund their state. They operate through a mix of purchased illicit accounts, stolen identities, and pirated software that leaves them uniquely susceptible to the very infostealers they utilize against others. We are currently observing a massive influx of these workers using sophisticated remote setups, fake resumes, and American collaborators. Are your hiring practices prepared to spot an applicant who isn't who they say they are? This talk pulls back the curtain on the DPRK IT worker playbook and operationalizes intelligence we’ve gathered by tracking their digital footprint.


The DPRK IT Worker Ecosystem:
Also known by monikers like Famous Chollima, Jasper Sleet, and UNC5267, these workers are tasked by the North Korean government to secure remote IT roles across North America, Europe, and Asia. They function as a revenue-generating machine, often working full-time or as contractors, funnelling the majority of their income back to the state.

The Stealer Log Footprint:
By leveraging a massive trove of stealer logs, researchers can now identify machines belonging to DPRK IT workers based on specific indicators. Key signatures include the heavy use of Google Translate, multiple throwaway Gmail and GitHub accounts, access to .kp domains, and the use of AI tools to alter profile photos and backgrounds for video calls.

Internal Tools & Infrastructure:
These workers rely on a proprietary stack of tools to maintain connectivity with North Korean internal networks. NetKey and OConnect facilitate access to the Kwangmyong intranet (including sites like star.kp), while "RB Site" serves as a back-office portal for device registration and payment submission. Once on a private network, they utilize IP Messenger (IPMsg.exe) to communicate, swap accounts, and request favors.

The Job Hunt Lifecycle:
The operation covers both freelance and full-time employment. For full-time roles, they often recruit Western collaborators—willing or victimized—to provide names, banking information, and physical addresses to bypass vetting. The lifecycle is distinct: they mass-apply, get onboarded, lean on LLMs and translation tools to perform tasks, and eventually face termination due to communication or performance issues.

Detection & Mitigation:
Mitigation requires moving beyond standard background checks. Organizations must watch for suspicious VPN/remote access software, scrutinize discrepancies between resumes and live interviews, and mandate in-person onboarding or frequent video calls—which DPRK workers often avoid.

The speaker’s profile picture
Chris d'Eon

Chris d'Eon is a threat intelligence researcher at Flare. With a focus on Asian cybercrime and nation-state activity, he is particularly interested in the social and geopolitical motivations of threat actors, painting a more qualitative picture of the human environment in which threat actors emerge.