Companies are used to thinking about attackers as outsiders trying to break in.

North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect.

That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency.

For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access.

When the Threat Gets Hired

A recent joint investigation by Mauro Eldritch (BCA LTD), Heiner García (NorthScan), and ANY.RUN showed what this looks like from inside the operation.

Researchers deliberately hired suspected DPRK developers linked to Lazarus Group and gave them what looked like ordinary virtual desktops. In reality, they were controlled ANY.RUN Sandboxes, capturing their activity in real time.

The operation exposed forged identities, remote-access tools, AI-assisted workflows, and VPN and VPS infrastructure.

See the full investigation on the ANY.RUN blog for the recorded interviews, live operator activity, infrastructure findings, and complete toolset breakdown.

Check Investigation Details

The Red Flags Start Before Day One

The investigation showed that the strongest warning signs were often small inconsistencies across the hiring process rather than one obvious giveaway.

Security and hiring teams should pay closer attention to:

  • Identity details that don’t line up: addresses, states, documents, or banking information that contradict each other.
  • Signs of document manipulation: unusual metadata, visual inconsistencies, or evidence that an ID has been altered with AI.
  • Interview behavior that feels assisted: repeated off-screen glances, delayed responses, or dependence on live translation and AI tools.
  • Location mismatches: network activity that does not match where the candidate claims to live or work.

None of these signals proves malicious intent on its own. But when several appear together, they should trigger deeper verification before the candidate receives company access.

How CISOs Can Keep a DPRK Operative Off the Payroll

The Famous Chollima investigation showed that there is rarely one obvious sign that gives a fraudulent worker away. Instead, the clues appear across identity documents, interviews, location data, infrastructure, and activity after onboarding.

Based on what researchers observed, here are several steps security leaders can take to make it much harder for a spy to get onto the company payroll.

1. Fully Verify the Person Behind the Documents

A convincing identity document should not be the end of verification.

The researchers encountered manipulated IDs, stolen identities, conflicting personal information, and financial details that did not always match the person being hired.

For sensitive remote roles, CISOs should make sure identity checks use several independent signals. The candidate’s documents, location, interview behavior, employment history, and financial details should tell a consistent story before access is approved.

Roles with access to source code, cloud infrastructure, production systems, or financial assets should receive a higher level of scrutiny from the start.

2. Give Security Teams a Safe Way to Validate Suspicious Activity

The researchers used specially configured ANY.RUN Sandbox environments to observe the operatives' activity without exposing real corporate systems. This gave them visibility into the files they opened, tools they used, network connections they made, and other behavior that would have been difficult to assess from identity checks alone.

CISOs can apply the same principle by making sure security teams have access to interactive sandboxes like ANY.RUN when suspicious files, links, scripts, or tools appear around employee activity. 

Instead of relying only on alerts or isolated indicators, teams can safely examine how the activity behaves and gather stronger evidence before deciding whether escalation or containment is necessary.

This can help reduce uncertainty, speed up response, and lower the risk of suspicious activity reaching critical systems.

3. Check Whether the Same Infrastructure Appears in Your Environment

The investigation uncovered specific infrastructure used by the suspected DPRK operatives. Security teams can cross-check these indicators against historical logs, EDR telemetry, proxy records, DNS data, and other security sources to see whether the same infrastructure has already appeared inside the organization.

Examples from the investigation include:

  • IPv4: 62[.]33[.]223[.]165 // INVESTSTROY-NET (InvestStroyTrest)
  • IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS
  • IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS
  • IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS
  • IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node
  • IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node
  • IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node
  • IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node
  • IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node
  • 0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd
  • 0xA3D6938f152C47A411263573Bb3AF324C25A8eba
  • 0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0

A match should not be treated as proof of DPRK activity on its own, but it can be a strong reason to look deeper when combined with other suspicious signals.

With ANY.RUN’s Threat Intelligence Lookup, security teams can investigate indicators in more context, including related sandbox sessions, associated threats, and targeting patterns across countries and industries.

This helps teams determine whether an unusual connection is isolated or part of a broader malicious pattern and prioritize the cases that need attention first.

4. Turn Investigation Findings into Ongoing Detection

The researchers identified infrastructure used by the suspected DPRK operatives, including IP addresses, VPN endpoints, and VPS providers.

For CISOs, the next step is making sure findings like these are not checked once and forgotten. They should become part of ongoing detection, so security teams can spot the same or related infrastructure if it appears elsewhere in the environment.

ANY.RUN’s Threat Intelligence Feeds can support this by continuously supplying fresh indicators from real-world investigations to existing security tools.

That turns intelligence from cases like this into earlier warning signs for future activity.

Don’t Let a Fraudulent Hire Become a Trusted Insider

North Korean remote-worker schemes show why hiring can no longer sit outside the security conversation. A candidate may pass interviews, present convincing documents, and receive legitimate access long before traditional security controls see anything suspicious.

For CISOs, the priority is to reduce that gap: verify identity more deeply, give security teams the right solutions to validate suspicious activity, check known infrastructure against the environment, and turn confirmed findings into ongoing detection.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows.

Strengthen Your Investigations with ANY.RUN

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.