The fake worker threat and the rise of human infiltration
The fake worker threat and the rise of human infiltration
How fake workers exploit trust, business processes and digital identities to gain legitimate access to organizations
Key takeaways
- Rather than exploiting vulnerabilities or stealing credentials, fake workers gain legitimate access by securing remote employment under false identities.
- Modern attack surfaces extend to recruiting, onboarding, and other business processes.
- Security teams, human resources, legal and business leaders must work together to strengthen the company against insider threats.
The Democratic Peopleâs Republic of Korea (DPRK), commonly known as North Korea, has thousands of highly skilled workers engaged in remote employment and related activities around the world. In most cases these workers have constructed false identities as individuals based in the United States (U.S.), Germany, Portugal, the United Kingdom (UK) and other Western countries. They often mask their locations through something like remote laptop farms and virtual private networks (VPNs).
This is the âNorth Korea fake worker scam,â also known as the âfake IT worker scam.â It is believed to have cost victim organizations hundreds of millions of dollars since its emergence in 2017.
There are different versions of the fake worker scam. Some operatives seek direct employment, others work through freelance platforms or staffing firms, while more sophisticated operations use front companies or developer recruitment schemes. This post will look at the most common of these, which is the direct employment scam.
DPRK cyber operations
The DPRK remains subject to extensive U.S., United Nations, and allied sanctions targeting its nuclear weapons and ballistic missile programs. The sanctions have constrained North Koreaâs access to international markets, foreign investment, and other sources of funds. In response to this pressure, the regime has developed a strong portfolio of cyber-enabled activities that generate revenue, support espionage operations, and acquire technology from abroad.
The countryâs intelligence agency, Reconnaissance General Bureau (RGB), operates several overlapping but distinct threat groups that conduct cryptocurrency theft, financial fraud, espionage, and operationally disruptive cyberattacks against companies around the world.
Researchers commonly associate these major threat clusters with the RGB:
- Andariel / APT45: Espionage and offensive cyber operations. Linked to attacks against South Korean military targets and defense contractors, and operations supporting broader DPRK cyber activities. Actors from this group have also been linked to the DPRK fake worker ecosystem. Also tracked as Onyx Sleet and Silent Chollima.
- Bluenoroff / APT38: The DPRK's primary financial cybercrime unit. This unit has been linked to Society for Worldwide Interbank Financial Telecommunication (SWIFT) thefts, cryptocurrency exchange intrusions, bank fraud, and other financial theft operations. The Bangladesh Bank theft is frequently attributed to this cluster. Also tracked as BeagleBoyz, Sapphire Sleet and Stardust Chollima.
- TraderTraitor: Assigned to cryptocurrency theft, blockchain companies, Web3 organizations, and digital asset platforms. The group frequently uses social engineering, fake job offers, and malware-laced recruitment schemes to compromise targets. Also tracked as Jade Sleet, Slow Pisces and UNC4899.
- Kimsuky / APT43: Collects political and strategic intelligence from governments, think tanks, academics, journalists, and policy experts. Also tracked as Emerald Sleet and Velvet Chollima.
- Lazarus Group: High-profile DPRK-affiliated threat group. Lazarus is linked to several high-profile incidents, including the 2014 Sony Pictures attack and the WannaCry ransomware outbreak. The name âLazarusâ may refer to a single entity or multiple overlapping groups. Also tracked as Hidden Cobra, Diamond Sleet and Labyrinth Chollima.
Public reporting often refers to DPRK-linked threat actors as Lazarus Group. Researchers will normally take the activity attributed to Lazarus Group and separate it into threat clusters based on the researchersâ own telemetry and other data. This is why we have different names and overlapping groups when we discuss these threat actors.
The group we will be looking at here is Famous Chollima, also tracked as UNC5267 (Mandiant / Google) and Jasper Sleet (Microsoft), and sometimes associated with Wagemole. This is the group widely attributed to the fake worker scam.
The threat of human infiltration
Famous Chollima blurs the line between insider threat and cyber intrusion. Rather than exploiting a software vulnerability or stealing credentials, the group gains access through fraudulent employment. By successfully embedding operatives within organizations as remote workers, it achieves many of the same objectives as a traditional cyber intrusion while leveraging trust, employment processes and human relationships as its initial access mechanism.
Hereâs a quick look at the targets of this scam:
- Company type: High-value sectors and industries include aerospace companies, defense contractors, blockchain, cryptocurrency and decentralized finance (DeFi), software development firms, and other high-tech companies. From April 2025 to May 2026, Famous Chollima accounted for 47% of all state-sponsored interactive intrusions against the technology sector.
- Location: The United States (U.S.) has been the primary target. In 2025, the Google Threat Intelligence Group (GTIG) identified an increase in coordinated operations in several European countries.
- Size: Public reporting has documented the group's efforts to infiltrate companies of all sizes, from small startups to large Fortune 500 organizations. The employee count is not as important as access to revenue, data or privileged systems.
One of the key takeaways from these attacks is that modern attack surfaces extend beyond technology. Recruiting, identity verification, payroll, contractor management, and remote-work programs can all become targets for a threat actor who wants to embed themselves into an organization.
Exploiting the business trust stack
Most of us have heard of social engineering attacks like the fake tech support scam and invoice fraud. Deepfakes and synthetic personas have encouraged companies to harden many of their business processes already. If youâre struggling to communicate the risk of unsecure or unchecked business processes, the following âtrust stackâ may help.
- Human trust: Relationships, assumptions, and social cues that help people decide who is credible, trustworthy, and authorized to act. This layer enables the next, which is business processes.
- Business processes: Organizational workflows that convert trust into action, such as hiring, onboarding, approving payments, recovering accounts, or granting access. This layer creates digital identities for employees, contractors, etc.
- Digital identities: Accounts, credentials, permissions, and privileges that represent a person within an organization's systems. Digital identities provide access to technology.
- Technology: Devices, applications, networks, and data that digital identities are ultimately allowed to access and use.
Traditional cyberattacks often begin at the technology or digital identity layers. Threat actors exploiting a CVE or other vulnerability are attacking the technology layer, while attacks using stolen credentials or account takeover (ATO) are attacking digital identities. Famous Chollima starts the attack by manipulating trust.
How the fake worker scam works
We can map each of the tactics, techniques and processes (TTPs) to the layers of the trust stack. Since trust is a factor throughout the screening and hiring process, layers 1, 2 and 3 may overlap.
Layer 1 - human trust
Objective: Convince people that the operative is a legitimate and employable professional.
TTPs:
- Fabricated professional personas, synthetic profiles with AI-enhanced photos
- AI-assisted translations and communications, manipulated interview appearances, voice-changing software
- Stolen or altered identity documents, fabricated references
- Relationship building with recruiters and hiring managers
Layer 2 â business processes:
Objective: Convert the trust established in layer 1 into authority within the company. Since trust is also established and increased during the hiring process, layers 1 and 2 often overlap.
TTPs:
- Applying to open positions directly or through staffing companies
- Working through the screening and interview processes with manipulated video and AI assisted translations (overlaps with layer 1)
- Hiding location through laptop farms, proxy workers and other facilitators
- Navigating the onboarding procedures and falsifying payment, tax and employment documentation
DPRK workers create fraudulent identities using documents such as passports, driver's licenses, and Social Security cards. These may be legitimate stolen documents or forgeries of varying quality. When authentic documents are unavailable, operatives create synthetic identities by combining real and fake information, including AI-generated or AI-manipulated photos.
The above images show an image of a fraudulent driverâs license and the metadata of the image. These were uncovered in an extensive investigation into the fake worker scam.
Layer 3 - digital identity
Objective: Obtain legitimate organizational identities.
TTPs:
- Receiving company-issued credentials, corporate email accounts, VPN access, and creating long-term persistent identities within the enterprise
- Gaining access to resources like business-critical applications and software development platforms like GitHub, Azure, Jira, etc.
Layer 4 â technology
Objective: Access technical resources and carry out instructions
TTPs:
- Conduct reconnaissance on source code repositories, development environments, cloud infrastructure, internal documentation, cryptocurrency wallets, DeFi platforms, and any other proprietary data
- Installing software including malware within approved workflows
- Exfiltrating data for espionage purposes or extortion operations
The workers can continue to harm the company after they are discovered and separated from the company. They may leave behind backdoors and other malware, or they may conduct extortion operations using the data they stole earlier.
Laptop farms and domestic facilitators
Domestic facilitators play an important role in the success of the fake worker scam. These are people who agree to help hide the true locations of the Famous Chollima operatives as they seek employment. This can include creating front companies to support false identities, helping remote workers launder their earnings, receiving equipment and correspondence on behalf of the worker, and providing infrastructure designed to hide the workersâ locations.
One of the most important pieces of infrastructure is the laptop farm, which is a physical location operated by a domestic facilitator. A laptop farm hosts company-issued laptops for the worker to use remotely. This creates a technical footprint in the target country, helping remote workers hide their true locations. These laptop farms and other domestic facilitator activities became targets of law enforcement in March 2024 under the DPRK RevGen: Domestic Enabler Initiative.
Why fake workers?
The North Korea fake worker operation is unique in its scale, organization and state-sponsorship. Other fake worker incidents have been uncovered, but investigators have found it difficult to distinguish DPRK actors from copycats. The concern among researchers is that fake worker scams are spreading as other threat actors adopt DPRK TTPs.
Unlike ransomware, business email compromise (BEC) and other cybercrime, DPRK workers are harder for companies to recognize as hostile intrusion. The regime benefits from the fake worker scam in two primary ways.
Revenue generation
The first and most important function of the fake worker scam is revenue generation through the collection of workersâ salaries, contractor payments, consulting fees and other earnings. Individual workers have been found to earn as much as $300,000 per year, while collective earnings are measured in hundreds of millions of dollars annually. One former North Korean IT worker told Bloomberg they are allowed to keep about 15-25% of their earnings, and the role was a âgreat choiceâ that earned them enough to support a family and âeven buy a house in Pyongyang.â
The U.S. Treasury estimated that North Korea generated nearly $800 million from these fake workers in the 2024 calendar year.
Espionage and intelligence collection
The US Department of Justice (DOJ) has documented DPRK workers stealing source code and International Traffic in Arms Regulations (ITAR) data from a California-based defense contractor that develops artificial intelligence-powered equipment and technologies. The Google Threat Intelligence Group has also observed these workers increasing their pursuit of roles in European defense and government-adjacent organizations.
Famous Chollima v law enforcement and industry analysts
Famous Chollima was formerly tracked as the BadClone activity cluster and has been active since at least 2018, but it didnât enter public awareness for another couple of years. The COVID-19 pandemic was a critical accelerant for remote work. Video interviews, remote onboarding, and electronic documents became more commonplace. Famous Chollima took advantage of this environment, scaling up its operations to gain trusted access to organizations.
- 2022 â The U.S. and several other governments issue formal warnings about the North Korean IT workers.
- October 2023 - U.S. authorities seized domains allegedly used to support North Korean IT worker operations.
- May 2024 - The DOJ announced criminal charges and disruptions targeting major fake-worker networks, revealing that more than 300 U.S. companies had been affected and that operatives had unsuccessfully attempted to obtain employment with U.S. government agencies.
- July 2024 â Security awareness company KnowBe4 disclosed that a newly hired software engineer who had successfully passed its hiring and background-screening process was a North Korean operative using a stolen identity. The fraud was detected when the individual attempted to download malware onto a company workstation.
- August 2024 âLarge-scale infiltration revealed: After investigating an April 2024 incident, CrowdStrike uncovered a widespread campaign in which DPRK fake workers had infiltrated more than 100 companies.
- August 2024 â A Tennessee man is arrested for operating a laptop farm used by Famous Chollima actors.
- December 2024 âThe U.S. DOJ charges 14 North Korean nationals for a multi-year fake worker fraud scheme.
- January 2025 â The FBI issues an advisory on DPRK fake workers stealing proprietary data and extorting former employers after losing access or being terminated.
- June 2025 âThe DOJ announces multiple indictments, arrests, searches of 29 suspected laptop farms across 16 states, and the seizure of financial accounts and fraudulent websites used to support the fake worker scam.
AprilâMay 2026 - Two U.S.-based facilitators are sentenced to 108 and 92 months in prison for operating laptop farms and assisting DPRK fake workers.
How to defend your company
Preventing human infiltration requires companies to protect the business processes through which trust and access are established. Following its 2024 incident, KnowBe4 introduced phone-based reference checks, stronger identity verification, and document and facial-recognition technologies designed to detect forged identities and impersonation.
Governments, regulators and security experts have recommended these best practices:
Screening and onboarding controls
- Require live video identity verification: Conduct live video interviews using anti-deepfake techniques, including asking candidates to perform unpredictable physical actions during the call to confirm their identity and presence.
- Strengthen reference and background checks: Require phone-based reference verification rather than relying solely on email and train recruiters to assess the quality, consistency, and legitimacy of applicantsâ public professional profiles.
- Implement advanced identity verification: Use airport-grade biometric identity verification technologies capable of detecting forged identification documents and facial-image mismatches.
- Require in-person verification for privileged roles: Mandate face-to-face identity verification for employees who will receive privileged access, even if the position is otherwise remote.
- Validate equipment shipping addresses: Do not ship company laptops or other corporate assets to addresses that differ from those associated with the employeeâs verified identity and employment records.
Technical controls
- Monitor for suspicious activity and anomalies: Watch for the use of remote monitoring and management (RMM) tools and keyboard-video-mouse (KVM) devices. Monitor for unusual working hours, connections or geolocation patterns.
- Monitor for data exfiltration attempts: Implement enhanced monitoring and alerting for unusual activity involving source code repositories, SharePoint, OneDrive, and other file-sharing platforms that could be used to steal proprietary data.
- Enforce least-privilege access:Limit new hires to onboarding-level permissions and gradually expand access only after identity verification and trust have been established.
Financial/payment controls
- Require verified banking information: Ensure employee and contractor payments are made only to verified U.S.-based bank accounts that match the individualâs validated identity records. Avoid cryptocurrency-based payments to freelancers whenever possible.
- Monitor for suspicious fund transfers: Flag and investigate payments that are immediately forwarded, withdrawn, converted to cryptocurrency, or transferred to other accounts shortly after receipt, as this behavior may indicate money-laundering activity or funds being routed to DPRK-controlled networks.
- If a suspected DPRK worker is identified, immediately freeze access and preserve forensic evidence before confrontation. Report the incident to the FBI and conduct a full audit of what the remote worker downloaded or accessed.
Barracuda can help
Human infiltration campaigns such as Famous Chollima are designed to obtain legitimate access, making early detection critical. While hiring and identity-verification controls remain the first line of defense, organizations also need visibility into what happens after an account is created. Barracuda Managed XDR helps security teams identify anomalous activity that may indicate a compromised, misused, or fraudulently obtained account, including unusual login behavior, unexpected geolocation patterns, abnormal file access or transfer behavior, and other behavior associated with fraudulent employees. By continuously monitoring and investigating these signals across the environment, Barracuda Managed XDR can help organizations detect signs of insider-risk activity and respond more quickly when trusted access is being used in unexpected ways.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.