Skip to content
Logo

Insider Threats (DPRK)

Security SpecialistOperations & StrategyCommunity & MarketingHREngineer/Developer

Authored by:

blackbigswan
blackbigswan
SEAL

Reviewed by:

Yaniv Sofer
Yaniv Sofer
EY
Dickson Wu
Dickson Wu
SEAL

🔑 Key Takeaway: DPRK IT Workers are fraudulently hired remote workers who fund a sanctioned regime and can pivot to theft, extortion, or supply-chain sabotage. Hiring and access control are primary defenses.

This framework is an entry point to organizational and personal risk from insider threats, most commonly associated with DPRK IT Workers—North Korean IT freelancers using false identities. It is for teams already affected and for teams hardening before incident.

Topics covered:

  • Who insider threat actors are and what they do
  • How to recognize them
  • How to interact when a candidate or hire is suspect
  • How to mitigate impact and harden defenses
  • Consequences for the organization

Overview of risks to your organization

  1. Defrauding the company: payment to someone whose identity is unknown or false
  2. Weak operational security: shared credentials, poor source-control hygiene, intentional or accidental access leaks
  3. Extortion: pressure for additional payment after access or work completes
  4. Follow-on hacking: knowledge of internal systems reused later
  5. Sanctions violations: payments that benefit North Korea-related networks can violate sanctions regimes
  6. Funding of DPRK priorities: worker pay is routed to regime priorities rather than ordinary freelancers
  7. Supply-chain compromise: intentional weaknesses in software depended on by others
  8. Reputational damage: brand and user trust
  9. Asset freeze / loss of financial access: banks or exchanges may restrict access when sanctions risk is suspected
  10. Criminal investigations: law enforcement scrutiny, fines, or charges depending on jurisdiction and facts

What this framework covers

  1. General Information: definitions, operational structure, goals, scale, average profile indicators.
  2. Techniques, Tactics, and Procedures: how they get jobs, interview signals, post-hire discovery.
  3. Mitigating DPRK IT Workers: hiring and org hardening, response after discovery, data collection.
  4. Case Studies: anonymized real deviations from common patterns.
  5. Summary: quick-reference checklist of the framework.

Further Reading