Site navigation

North Korean Fake IT Workers Targeting European Firms

Tom Quinn

,

fake IT workers
The fake IT worker scheme out of North Korea is spreading, and European businesses are in the DPRK’s crosshairs, according to the latest threat intelligence report from Google.

North Korea has reportedly stepped up its malicious cyber operations across Europe, according to the latest report from the Google Threat Intelligence Group.

In an update to its earlier report detailing the infiltration of organisations by fake IT workers from the DPRK, Google has now warned that the scope and scale of these operations have expanded to focus on the penetration of European firms.

Running a corps of undercover operatives that routinely apply for multiple remote tech roles, the ongoing scam is designed to generate revenue for the hermit kingdom’s regime by stealing data and demanding ransoms in what has been described as a sophisticated insider threat scheme.

Google’s Threat Group said that in late 2024, it had detected one DPRK IT worker operating at least twelve personas across Europe and the US, using them to seek employment with multiple organisations, particularly those in the defence and government sectors.

Other fake IT worker personas were uncovered seeking employment in Germany and Portugal using login credentials for user accounts of European job websites and human capital management platforms.

Most worryingly for the UK, Google said it had observed DPRK IT workers taking part in web, bot, and blockchain technology development projects at British companies, which had already been warned of the same threat in a report from Secureworks last October.

At the moment, it has been nearly impossible for threat researchers to determine the limits of North Korea’s operation, although the details that have surfaced point to a complex logistical chain spanning continents and oceans. 

For example, in one instance, Google ID’d a corporate laptop, outwardly intended for use in New York, that was found to be operational in London.

The global nature of the threat ties with the results of previous investigations, including one from the UK’s National Cyber Security Centre and its allies, which last year exposed a cyber espionage campaign carried out by attackers in the United States and the Republic of Korea. 

Across the board, these fake personas have been witnessed using an elaborate web of fabricated references, bogus CVs, and false nationalities, including the use of fraudulent passports, to find jobs, and have even used other personas they controlled to vouch for their credibility.

Using various online platforms, including Upwork, Telegram, and Freelancer, Google said that the fake IT workers in Europe looked for payments in cryptocurrency to hide the origin and destination of funds.

Alongside global expansion, the DPRK’s IT workers have been busy evolving their tactics.

Using data from multiple sources, Google said it had uncovered an increase in the number of extortion attempts by fake IT workers against larger organisations since October 2024, aggressive tactics possibly driven by rising pressure from US law enforcement actions.

In these newly revealed extortion incidents, recently sacked IT workers threatened to release their employers’ sensitive data or provide it to a competitor, rather than attempt to provide references for their other personas to be rehired by the company, as had previously been the case. 


Recommended reading


“Global expansion, extortion tactics, and the use of virtualized infrastructure all highlight the adaptable strategies employed by DPRK IT workers,” said Google’s threat report.

“In response to heightened awareness of the threat within the United States, they’ve established a global ecosystem of fraudulent personas to enhance operational agility. 

“Coupled with the discovery of facilitators in the UK, this suggests the rapid formation of a global infrastructure and support network that empowers their continued operations.”

The cyber-threat from the DPRK does not end with fake IT workers, however, as Google issued another warning in January that it had witnessed state-sponsored cyber-criminals, including those from North Korea, using its Gemini AI to support and accelerate their malicious activities, while the US accused North Korean actors of the alleged theft of hundreds of millions of dollars in cryptocurrency, including $308 million (£253 million) in Bitcoin.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data