Insider Threats (DPRK)
Security SpecialistOperations & StrategyCommunity & MarketingHREngineer/Developer
🔑 Key Takeaway: DPRK IT Workers are fraudulently hired remote workers who fund a sanctioned regime and can pivot to theft, extortion, or supply-chain sabotage. Hiring and access control are primary defenses.
This framework is an entry point to organizational and personal risk from insider threats, most commonly associated with DPRK IT Workers—North Korean IT freelancers using false identities. It is for teams already affected and for teams hardening before incident.
Topics covered:
- Who insider threat actors are and what they do
- How to recognize them
- How to interact when a candidate or hire is suspect
- How to mitigate impact and harden defenses
- Consequences for the organization
Overview of risks to your organization
- Defrauding the company: payment to someone whose identity is unknown or false
- Weak operational security: shared credentials, poor source-control hygiene, intentional or accidental access leaks
- Extortion: pressure for additional payment after access or work completes
- Follow-on hacking: knowledge of internal systems reused later
- Sanctions violations: payments that benefit North Korea-related networks can violate sanctions regimes
- Funding of DPRK priorities: worker pay is routed to regime priorities rather than ordinary freelancers
- Supply-chain compromise: intentional weaknesses in software depended on by others
- Reputational damage: brand and user trust
- Asset freeze / loss of financial access: banks or exchanges may restrict access when sanctions risk is suspected
- Criminal investigations: law enforcement scrutiny, fines, or charges depending on jurisdiction and facts
What this framework covers
- General Information: definitions, operational structure, goals, scale, average profile indicators.
- Techniques, Tactics, and Procedures: how they get jobs, interview signals, post-hire discovery.
- Mitigating DPRK IT Workers: hiring and org hardening, response after discovery, data collection.
- Case Studies: anonymized real deviations from common patterns.
- Summary: quick-reference checklist of the framework.
Related frameworks
- IAM: least privilege, lifecycle, and revocation after bad hire discovery
- Supply Chain: intentional dependency and delivery risk
- OpSec: operator and credential hygiene
- Awareness: social-engineering context for recruiters and hiring managers
- Incident Management: investigation and response after compromise (DPRK attack playbook when relevant)
- User and Team Security: staff security posture (when expanded)
Further Reading
- DPRK Attack Playbook: response steps once a worker is found inside your organization
- OFAC North Korea Information Technology Workers Advisory: the sanctions guidance that makes payment a legal risk
- Google Threat Intelligence: mitigating the DPRK IT worker threat: vendor research on current tactics