logo

DPRK IT Workers Impersonating Individuals Using Real LinkedIn Accounts to Apply for Remote Roles

ID: 2bd96c43-947e-52f2-a07d-95627b37834b

STIX ID: report--2bd96c43-947e-52f2-a07d-95627b37834b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

North Korean operatives have shifted from synthetic identities to hijacking real LinkedIn profiles to secure remote IT roles in Western tech firms, using verified documentation and control of applicant communications to bypass screening; the activity aims to funnel salaries to the DPRK and to gain privileged access for espionage or malware, and defenders are urged to validate account control (e.g., via connection requests or direct platform messages) and monitor for impersonation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.