Full Report
Multiple countries have taken legal action against North Koreans or local handlers following a report from the United Nations about Pyongyang’s illicit IT worker scheme. The Multilateral Sanctions Monitoring Team (MSMT) — a U.S.-led international committee tasked with tracking compliance of UN sanctions on the Democratic People’s Republic of Korea (DPRK) — released a new report on…
Analysis Summary
# Threat Actor: North Korean Illicit IT Workers
## Attribution & Identity
* **Actor Identification:** North Korean (DPRK) nationals operating as part of a state-sponsored illicit IT worker scheme.
* **Aliases:** DPRK IT Workers, North Korean Remote Workers.
* **Known Associations:** Administered and sanctioned by the government of the Democratic People’s Republic of Korea (DPRK); monitored by the Multilateral Sanctions Monitoring Team (MSMT) and the United Nations.
## Activity Summary
The actor group involves thousands of North Korean nationals who reside illegally in foreign countries to obtain high-paying IT employment. A recent report by the MSMT (released September 2026) and a preceding UN study indicate that these workers leverage stolen or purchased identities to bypass sanctions and generate revenue for the North Korean regime. Recent legal actions have been taken by multiple countries against both the workers and their local handlers who facilitate the scheme.
## Tactics, Techniques & Procedures
* **Identity Fraud:** Purchasing or stealing legitimate IDs to bypass background checks and employment verification systems.
* **Identity Substitution:** Using local "handlers" or intermediaries to pose as the worker during the hiring process or to manage local logistics.
* **Remote Work Exploitation:** Targeting companies that offer remote IT roles to mask their physical location.
* **Sanctions Evasion:** Operating from third-party countries to funnel hard currency back to the DPRK.
* **MITRE ATT&CK IDs:**
* T1078 (Valid Accounts) — via stolen/purchased IDs.
* T1566 (Phishing) — often used in the initial stages of identity theft or procurement.
## Targeting
* **Sectors:** Information Technology (IT), Software Development, and various high-paying technical industries.
* **Geography:** Primarily based in China, but active in approximately 40 other countries globally.
* **Victims:** Large enterprises and technology companies offering high-paying, remote-friendly IT positions.
## Tools & Infrastructure
* **Malware Families:** While primarily a revenue-generation scheme, these workers are often associated with the broader DPRK cyber apparatus, which utilizes custom backdoors and financial theft malware.
* **Infrastructure:**
* Third-party payment platforms and crypto-exchanges to move funds.
* Local handlers/intermediaries providing physical addresses and banking access.
* Remote Desktop Protocol (RDP) and VPNs to obfuscate North Korean or Chinese origin points.
## Implications
The scheme represents a dual threat: it provides a critical source of illicit revenue for the DPRK's weapons programs and places state-linked actors inside the internal networks of global corporations. This creates a significant insider threat risk, potential for corporate espionage, and future deployment of ransomware or destructive malware.
## Mitigations
* **Enhanced Identity Verification:** Implement multi-factor authentication (MFA) and rigorous video-based identity verification during the hiring process.
* **Infrastructure Monitoring:** Monitor for suspicious login patterns, such as unexpected VPN usage or RDP connections from high-risk jurisdictions.
* **Background Screening:** Conduct deep-dive background checks that include verifying the authenticity of identification documents against government databases where possible.
* **Legal Compliance:** Ensure HR and procurement departments are trained to recognize signs of the DPRK IT worker scheme to maintain compliance with UN and U.S. sanctions.