logo

North Korean Hacker Lands Remote IT Job, Caught After VPN Slip

ID: 57c99136-bd61-5d50-956c-384087c11094

STIX ID: report--57c99136-bd61-5d50-956c-384087c11094

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Research from LevelBlue describes a suspected North Korean operative who bypassed hiring checks to obtain a remote IT position with access to Salesforce data, using Astrill VPN to mask origin (initially showing logins from China, then an anomalous login from St. Louis). Behavioural analytics and crowdsourced threat data detected the anomaly, the EntraID account was revoked within 10 days, and the report links this incident to an organized state-sponsored recruitment ecosystem that monetizes access and can support data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.