{"id":66,"date":"2025-10-18T17:32:54","date_gmt":"2025-10-18T17:32:54","guid":{"rendered":"https:\/\/racter.com\/blog\/?p=66"},"modified":"2026-08-03T16:19:42","modified_gmt":"2026-08-03T16:19:42","slug":"dprk-it-workers","status":"publish","type":"post","link":"https:\/\/racter.com\/en\/blog\/dprk-it-workers\/","title":{"rendered":"DPRK IT Workers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I\u2019ve been digging into this &#8216;DPRK IT Worker&#8217; threat, and we&#8217;re not just fighting fake resumes anymore; we&#8217;re fighting an adversary who has a U.S.-based accomplice making their overseas activity look like it&#8217;s coming from the USA rather than North Korea\/China\/Russia.<br><br>So, how do we catch them?<br><br>For me, it starts at the endpoint. I&#8217;m pushing my team to tune our EDR to hunt for legit remote access tools that just&#8230; shouldn&#8217;t be there. Think AnyDesk, ScreenConnect, or weird IP-KVM drivers on a standard build. We&#8217;re even looking for &#8220;mouse jigglers&#8221;!<br><br>On the network, &#8220;impossible travel&#8221; alerts are a classic for a reason. You can&#8217;t be on our VPN from a U.S. home IP and logging into O365 from Eastern Europe five minutes later.<br><br>I&#8217;m also a big fan of UEBA for spotting weird behaviors. Is your &#8220;U.S.&#8221; employee suddenly working a perfect 3 AM to 11 AM shift every single day? That&#8217;s a huge red flag they&#8217;re in a completely different time zone.<br><br>But honestly, the one control I&#8217;d bet on? Hardware-based MFA. I&#8217;m talking YubiKeys or other FIDO2 tokens. A facilitator in the U.S. can&#8217;t tap a physical key for an operative overseas. It&#8217;s a simple, physical roadblock that just stops this whole scheme cold.<br><br>#Cybersecurity  #NorthKoria #DPRK #ITWorkerScheme #InsiderThreat #RemoteWork #ZeroTrust #SecurityControls #InfoSec<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"800\" src=\"https:\/\/racter.com\/blog\/wp-content\/uploads\/2025\/10\/image.png\" alt=\"\" class=\"wp-image-67\" srcset=\"https:\/\/racter.com\/blog\/wp-content\/uploads\/2025\/10\/image.png 800w, https:\/\/racter.com\/blog\/wp-content\/uploads\/2025\/10\/image-300x300.png 300w, https:\/\/racter.com\/blog\/wp-content\/uploads\/2025\/10\/image-150x150.png 150w, https:\/\/racter.com\/blog\/wp-content\/uploads\/2025\/10\/image-768x768.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>I\u2019ve been digging into this &#8216;DPRK IT Worker&#8217; threat, and we&#8217;re not just fighting fake resumes anymore; we&#8217;re fighting an adversary who has a U.S.-based accomplice making their overseas activity look like it&#8217;s coming from the USA rather than North Korea\/China\/Russia. So, how do we catch them? For me, it starts at the endpoint. I&#8217;m [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-66","post","type-post","status-publish","format-standard","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts\/66","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":1,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"predecessor-version":[{"id":68,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts\/66\/revisions\/68"}],"wp:attachment":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}