North Korean remote workers are broadening their job hunt beyond IT
ID: 7d77e3f5-b3d5-507f-a594-a64ab07d1988
STIX ID: report--7d77e3f5-b3d5-507f-a594-a64ab07d1988
Feed Name: Help Net Security
Huntress investigations found suspected North Korean remote workers infiltrating organizations by obtaining legitimate remote jobs and using stolen/fabricated identity documents, VPNs/proxies (Astrill, IPRoyal), and covert hardware (PiKVM, Guermok USB capture) to hide their location and enable remote control; multiple cases across healthcare and finance showed document template reuse, swapped photos, and anomalous device/network activity, and the report recommends stronger interview-stage vetting and background checks to mitigate this emerging threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
