Free tools Windows power users keep installed
One-click scans. No signup required.
North Korean IT-worker fraud is more than a fake résumé or a payroll scam. DPRK-linked workers have used false identities and intermediaries to secure legitimate remote jobs, then collected wages while gaining access to company systems and data. Mandiant’s Michael Barnhart discussed the threat with CyberScoop’s Greg Otto in a Safe Mode interview published October 3, 2024. The practical lesson for employers is that hiring, device delivery and ongoing access controls are all part of the security perimeter.
What is the North Korean IT-worker scheme?
Mandiant, part of Google Cloud’s Google Threat Intelligence Group, tracks identified DPRK IT-worker activity under the designation UNC5267. The label does not necessarily describe a conventional, centrally organized threat group. Mandiant says it has tracked the activity since 2022 and has observed workers located primarily in China or Russia, with smaller numbers elsewhere, presenting themselves as workers in the United States or other countries. See Mandiant’s account of the operation.
The basic scheme is to obtain a remote job under a stolen or fabricated foreign identity. A worker may use a false résumé, professional profile and references; a facilitator may help with interviews, identity checks, banking, tax paperwork or receipt of company equipment. The worker then performs assigned duties, sometimes while holding multiple jobs, and salary payments are routed through intermediaries or other channels.
In some cases, the employer ships a laptop to an address controlled by a facilitator. The worker accesses that machine remotely, making the device appear to be operating from the claimed location. Mandiant has documented overlapping résumé language and inconsistent names, contact details, universities and employment histories across personas.
#1 Best Overall
Why North Korea wants the jobs
The immediate objective is revenue for the DPRK regime and sanctions evasion. A legitimate job can also provide access to source code, credentials, cloud systems, internal communications and customer information. That access creates opportunities for espionage, data theft or later intrusion, but a fraudulent hire should not automatically be described as a confirmed espionage operation. Mandiant has said its incident-response engagements often found workers initially performing ordinary assigned duties.
What a laptop farm is
A laptop farm is a location where a facilitator physically hosts multiple employer-issued computers. A worker elsewhere may connect to a laptop farm device using remote-management software or an IP-based keyboard-video-mouse (KVM) device. Mandiant has observed tools including GoToRemote/LogMeIn, GoToMeeting, Chrome Remote Desktop, AnyDesk, TeamViewer and RustDesk in investigations. None of these products, by itself, proves fraudulent employment; each also has legitimate uses.
Which employers and roles face greater exposure?
Risk depends less on a single industry label than on the hiring arrangement and access granted. Mandiant has observed applications across sectors and work of varying complexity, not only advanced engineering.
- Fully remote, contract and freelance roles, especially when identity checks and device handoff are entirely remote.
- Software development, DevOps, cloud administration, IT support and other technical positions.
- Jobs with privileged access to source code, production systems, CI/CD pipelines, secrets, cloud consoles or customer data.
- Organizations that ship devices without confirming who receives and physically controls them.
- Employers whose HR identity checks are disconnected from IT provisioning and access reviews.
- Hiring processes that rely heavily on automated résumé screening or a single remote interview.
What warning signs should hiring teams check?
These indicators are reasons to verify more carefully, not proof of DPRK affiliation. A legitimate candidate may have an unusual address, use a VPN or need an accommodation. Assess evidence across several independent sources, and do not screen people based on nationality, ethnicity, accent or appearance.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallIdentity and résumé inconsistencies
- Education, employment dates, job titles or contact details differ across the résumé, professional profiles, references and background-check records.
- Several supposedly unrelated candidates use identical or unusually similar résumé wording, work histories or portfolio material.
- A claimed address, university or past employer cannot be independently verified, or the candidate’s online profiles appear to describe different people.
- A phone number or profile photograph raises questions that cannot be resolved through ordinary, lawful verification.
Interview and background checks
- The candidate’s answers about location, education, employers or technical experience are inconsistent across interviews.
- The person on a live interview does not appear to match identity documentation, or the candidate repeatedly avoids reasonable live verification.
- References can be contacted only through details supplied by the candidate, or cannot substantiate the stated work history.
A camera issue, delayed answer or reluctance to use video may have an innocent explanation, including accessibility, privacy or connectivity needs. Use a consistent process that allows reasonable accommodations and escalates unresolved discrepancies rather than making assumptions.
Equipment delivery and physical control
- The worker claims to live in one location but requests delivery to another, without a credible explanation.
- A third party receives or stores the company laptop, or the employee cannot explain who has physical possession of it.
- Device location or network activity repeatedly conflicts with the employee’s declared work location.
Mandiant has observed devices delivered to facilitator-controlled locations, including laptop farms. A shipping discrepancy merits follow-up; it is not conclusive evidence on its own.
Rank #3
Why ordinary cybersecurity tools may not catch a fraudulent hire
A worker who uses valid credentials and performs assigned tasks may not trigger a malware alert. The risk begins when the organization trusts a false identity and grants access. That access can include the ability to view or change code, administer systems or reach sensitive infrastructure. Security teams therefore need to connect hiring and device records with identity, endpoint, network and data activity throughout employment.
After onboarding, potential consequences include multiple-job salary fraud, unauthorized repository access, copying code to personal accounts or cloud storage, theft of secrets or customer data, and access that could support a later intrusion. The FBI warned on January 23, 2025, that North Korean IT workers had copied company code repositories, including GitHub repositories, to personal profiles or cloud accounts, and had used data extortion. Read the FBI/IC3 advisory.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →How to reduce the risk before and after hiring
Build identity checks into recruiting
- Conduct a live interview and compare the candidate with identity documents through a lawful, privacy-compliant process.
- Verify education and employment using independent sources. Contact references using details obtained independently where possible.
- Reconcile inconsistent names, dates, addresses, phone numbers and work histories before approving the hire.
- Require a clear explanation for a shipping address different from the employee’s verified location; arrange in-person pickup when practical.
- Give recruiters and hiring managers a documented route to escalate concerns to security, HR, legal and compliance teams.
Secure devices and remote access
- Enroll every company device in endpoint management before use; record its serial number and use device attestation and hardware-backed authentication where practical.
- Use endpoint detection and response, restrict installation of remote-access tools, and alert on unapproved tools or several remote-control products appearing on one device.
- Monitor for IP-based KVM devices and unusual human-interface-device activity. Correlate endpoint telemetry with device location and identity-provider logins.
- Investigate unexplained geography, impossible-travel events, anonymization services and location changes. Treat VPN alerts as leads: employees may legitimately use corporate VPNs or travel.
- Allowlist legitimate remote-support software and require monitored, privileged workflows rather than indiscriminately blocking tools used by the help desk.
Limit access and monitor sensitive data
- Use phishing-resistant MFA or hardware security keys for privileged accounts and apply least privilege.
- Separate developer, production, administrative and finance permissions; review contractor access regularly.
- Monitor unusual OAuth grants, API-token creation, repository cloning, bulk downloads and cloud-console activity.
- Restrict unauthorized repository mirroring and personal cloud-storage synchronization; use secrets scanning and short-lived credentials.
- Maintain prompt offboarding procedures for access revocation, and keep administrative and repository activity logs.
Location monitoring and identity checks must comply with employment, privacy and labor rules in the relevant jurisdiction. Give clear notice, limit collected data to what is needed, and review automated flags through a consistent human process.
Rank #4
What to do if a suspicious worker is already employed
Handle the concern as a potential security incident, not as a settled attribution. Avoid an unplanned confrontation that could prompt deletion or data transfer. Coordinate containment with security, HR and legal, and preserve evidence before changing systems wherever practical.
- Preserve records. Secure identity and hiring records, interview materials where lawfully retained, shipping details, device logs, VPN and authentication history, remote-access software records, repository activity and relevant payment information.
- Contain access proportionately. Revoke privileged tokens, isolate affected devices and disable unexplained remote tools while preserving devices and logs for forensic review.
- Establish the scope. Determine which systems, repositories, credentials, cloud accounts and customer data the account could access, and review activity for copying, bulk downloads or unusual changes.
- Rotate exposed secrets. Replace API keys, SSH keys, cloud credentials, signing keys and service-account credentials that may have been accessible.
- Look for related personas. Search for repeated résumé language, references, phone numbers, email addresses, devices, IP addresses and payment details.
- Coordinate reporting and response. In the United States, consider reporting suspected activity to the FBI and IC3; follow applicable legal, regulatory and contractual notification duties. The FBI’s alert to U.S. businesses and the IC3 advisory describe the threat and reporting route.
- Plan for extortion risk. Preserve messages and evidence, involve legal and incident-response specialists, and assess what data could be exposed; termination alone may not end the incident.
- Update controls. Document what failed and adjust hiring, device-delivery, access and monitoring procedures.
How the threat has changed—and what the figures mean
In April 2025, Google Threat Intelligence reported activity involving European job sites and HR platforms, as well as facilitators in Europe. The report also described increasing extortion attempts against former employers, including threats involving proprietary data and source code. These are dated observations, not a complete census of all activity. See Google Threat Intelligence’s April 2025 report.
Mandiant described one facilitator-linked case involving more than 60 compromised identities and more than 300 affected companies. It said the case generated at least $6.8 million for overseas IT workers from approximately October 2020 through October 2023. Those figures apply to that case, not the total DPRK program.
Best Value
Mandiant’s M-Trends 2026 materials, based on its 2025 investigations, reported a 122-day median dwell time for the categories covering cyber-espionage and DPRK IT-worker incidents. This is a statistic from Mandiant-investigated incidents, not the average duration of every fraudulent hire or an estimate of the total population.
Where security products help—and where they do not
No commercial product should be treated as a standalone North Korean IT-worker detector. Tools can help correlate telemetry after onboarding, but they do not replace lawful identity and employment verification.
- Applicant and identity verification: supports HR checks before an offer and device shipment.
- Device management and endpoint detection: provides visibility into company devices, remote tools and unusual endpoint behavior.
- Identity monitoring and SIEM/SOAR: correlates sign-ins, device location, VPN activity, cloud actions and repository events; useful only when the organization collects relevant data and can investigate alerts.
- Threat hunting and incident response: helps assess whether a suspected worker, facilitator or remote-access route has affected systems.
For example, Google SecOps and Mandiant services can support detection, hunting or response for organizations with the telemetry and operational capacity to use them. Mandiant Digital Threat Monitoring can identify external exposure or targeting, but cannot prove an applicant’s identity. Mandiant Security Validation can test whether controls detect selected attack behaviors; it is not applicant screening. Product fit depends on the organization’s existing tools, staffing, privacy obligations and incident-response needs.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →




