Find notable cyber news and cases, enriched with sources, timelines, and signals.

North Korean remote IT worker infiltration trend across companies

Trend
First reported
Last updated
Happening score
H score 34
4 unique sources, 5 articles

Summary

Hide ▲

North Korean remote IT worker infiltration has reportedly topped 320 incidents in the last 12 months, up 220% from the prior year, as operators use GenAI-made résumés, real-time deepfake interviews, AI coding tools, and laptop farms to win jobs and generate revenue. The same pattern is tied to Famous Chollima (WageMole), which uses stolen identities, fake recruiters, and remote-access tooling like AnyDesk and Astrill VPN to pose as legitimate developers. A Nisos investigation added a June 2025 case involving a supposed Florida-based AI architect whose interview answers appeared AI-assisted. Nisos traced the operative to a hidden laptop farm with PiKVM, Tailscale mesh VPN, about 40 devices, and roughly 20 in active use.

Related Happenings

North Korean remote IT worker scam operation targeting American companies

Campaign
H score41 First: 16.04.2026 19:00 Last: 16.04.2026 19:00 Sources 1

About this happening: A long-running North Korean remote IT worker scam operation used stolen identities and fake placements to embed operators inside more than 100 American companies. The...

Masjesu IoT DDoS botnet activity

Malware Activity
H score31 First: 08.04.2026 14:49 Last: 08.04.2026 14:49 Sources 1

About this happening: The Masjesu botnet is actively infecting IoT devices and using them for DDoS attacks, creating a distributed attack platform that can generate large traffic floods. It...

DPRK-linked cryptoasset theft campaign continuing into 2026

Campaign
H score35 First: 03.04.2026 11:35 Last: 03.04.2026 11:35 Sources 1

About this happening: The DPRK-linked cryptoasset theft campaign is continuing into 2026, keeping crypto and Web3 targets at risk of repeated theft and laundering activity. The operation us...

North Korean fake-persona remote job infiltration campaign against Western tech companies

Campaign
H score34 First: 25.03.2026 17:30 Last: 25.03.2026 17:30 Sources 1

About this happening: A North Korean fake-persona campaign is using remote job applications to gain trusted insider access at Western tech companies, creating theft and espionage risk....

Contagious Interview cryptocurrency social-engineering and malware-delivery campaign

Campaign
H score37 First: 23.03.2026 20:09 Last: 23.03.2026 20:09 Sources 1

About this happening: A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...

Timeline

  1. 20.08.2025 12:18 5 articles · 10mo ago

    North Korean remote IT workers infiltrate companies at scale

    Campaign Scope Update

    CrowdStrike said North Koreans posing as remote IT workers infiltrated companies in more than 320 incidents over the past 12 months, a 220% increase from the prior year. The scheme uses GenAI to create attractive résumés, real-time deepfake interviews, AI code tools, and laptop farms to support illicit employment and revenue generation.

    Show sources