Huntress describes real investigations where suspected North Korean remote workers tricked companies into hiring them using stolen or doctored identity documents and tools to remotely control “employee” laptops. Cases span healthcare, financial services, and sales/marketing roles, showing a repeatable hiring-fraud playbook (fake documents, VPN/proxy use, and reluctance to appear on camera). This is a people-process risk as much as a technical one, starting at recruiting and onboarding.
Key findings
- Suspected DPRK workers are expanding beyond IT into sales/marketing and medical roles.
- The scheme relies on being hired under false identity rather than “breaking in”: attackers “trick companies into remotely hiring them.”
- Identity verification artifacts showed signs of templating and reuse (similar passport issuance timing, identical ID validity dates/issuing station, repeated photo characteristics, and electricity bills with the same typos).
- A financial services case found hardware (PiKVM + USB capture card) connected to a new hire’s laptop soon after delivery, suggesting remote operation/laptop-farm behavior.
- One hire refused to show their workspace and was reluctant to appear on camera, leaving their identity “questionable.”
- Mitigation focus: stronger interview-stage verification and rigorous background checks before onboarding.
Who’s being targeted
- Commonly targeted roles: HR / Recruiting, Hiring Managers, IT Onboarding / Service Desk, Security Operations, Compliance / Background Check teams.
- Affected industries: Healthcare, Finance/Insurance, Sales and Marketing.
- Attack channels: teams, physical, website.
- Impersonated: Legitimate job candidate/new employee (using a stolen or altered identity), Legitimate remote employee (while another operator controls the laptop), A real person whose identity details are reused, with the applicant’s photo swapped in.
Awareness takeaways
- Treat recruiting and onboarding as a security control: require strong identity verification before granting access.
- Use multiple verification methods (not just submitted documents) and look for document templating/reuse patterns.
- Escalate when a remote worker resists reasonable video/workspace verification checks.
- Monitor for “laptop farm” indicators: unexpected remote-control hardware, strange network transitions, and suspicious peripherals.
Red flags to watch for
- Refuses to show workspace when asked
- Reluctant to appear on camera during verification
- Identity remains “questionable” after reasonable verification requests
- Unusual hardware attached shortly after device delivery (PiKVM/KVM-over-IP)
- Network path changes that suggest routing through travel router/home Wi‑Fi before fixed Ethernet
- Video/capture device masquerading as a webcam for conferencing
- Identity numbers pass checks but photo appears altered/swapped
- Submitted documents show templating patterns (same typos, reused formats)
- Mismatches found via open-source checks (e.g., mugshot doesn’t match submitted ID photo)
Read the video transcript
Some North Korean workers aren’t hacking in, they’re tricking us into hiring them as remote employees. Huntress found remote hires using reused passport templates and even a PiKVM box wired into their company laptop, so someone else could drive it from a laptop farm. The pattern: stolen or doctored IDs, same expiry dates, same typos on utility bills, plus a "new hire" who won’t show their room and is always reluctant to turn on video. If a remote hire’s identity still feels questionable, or they dodge reasonable video and workspace checks, pause onboarding and escalate to Security and HR before granting access.