State Sponsored “Cyber Warriors” — North Korean Remote IT Workers

No ratings

Presented at CODE BLUE 2025 by

The presentation will cover North Korean remote IT workers and the broad operational methods they utilize. It will start with their likely methods of faking, stealing, or purchasing credentials or identities, and some ways they fake their identity and background in an interview. Next, it will cover their malicious actions once they gain employment, including deploying ransomware or malware, or stealing information from the employer to sell on the dark web. There will be a section on their preferred targets and how to spot a “laptop farm” that North Koreans set up through their proxies overseas. The presentation will also include details on the software they use to obfuscate their identity and real location, as well as an overview of insights gleaned from the data logs of a suspected North Korean IT worker’s computer. It will end with a discussion on some mitigations to prevent companies from unintentionally hiring North Korean IT workers.