Fake North Korean IT workers are rampant on LinkedIn – security experts warn operatives are stealing profiles to apply for jobs and infiltrate firms
The scammers' latest efforts mark a significant escalation in tactics, experts have warned
North Korean IT workers are hijacking genuine LinkedIn profiles to apply for remote jobs and infiltrate enterprises.
Security Alliance (SEAL) said the technique, which marks an escalation from previous fake worker schemes, is hard to spot initially as the profiles appear completely genuine - as, in a way, they are.
The fraudsters appropriate real identities, leverage verified workplace emails and identity badges, and construct credible employment histories to pass background checks.
Once settled into remote roles, they route corporate laptops through “laptop farms” to maintain the appearance of a regionally based workforce.
While salary diversion helps finance the regime, there's also a more strategic threat in the form of persistent access, including the installation of malware and the theft of intellectual property.
Darren Guccione, CEO and co-founder of Keeper Security, warned the news should be viewed as a structural shift and significant escalation in cyber risk.
"What we are seeing is not an isolated fraud campaign, but the industrialization of professional identity manipulation, where nation-state actors combine stolen personal data, AI-generated imagery and deepfake video interviews to embed themselves inside unwitting organizations."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
There are relatively simple ways to spot the fraud, however, such as asking applicants to connect with you on LinkedIn to ensure they have ownership and control of the account.
Meanwhile, SEAL said users experiencing identity impersonation involving fraudulent job applications should consider posting a warning on other social media pages to protect their identity and the broader ecosystem.
This should include the date the fraud was detected and the tactics that were observed. Users should list the accounts they control - and the communication channels not used for job discussions. Elsewhere, they should provide a method of verification, for example, "contact via company email".
Identity security needs a rethink
Guccione said enterprise leaders need to face up to the fact that identity is now the primary attack surface - and that in a remote and hybrid hiring environment, perimeter security offers little protection when adversaries are granted legitimate credentials and endpoint access.
Organizations must respond by hardening identity governance, for example. That includes rigorous identity verification during onboarding, enforcing phishing-resistant multi-factor authentication, applying least-privilege access from day one, and continuously monitoring for anomalous behavior.
“Privileged access has to be tightly controlled and audited at all times," he said.
"This campaign is a stark reminder that trust in digital identity must be earned and continuously validated. Without strong identity and access management controls, companies now risk providing expansive internal access to the very threat actors they are trying to defend against."
North Korea has been using fake remote workers to raise money for the regime for years now, with fraudsters claiming to be based anywhere from Italy and Ukraine to Japan, Malaysia, or Singapore.
While the scam initially targeted US companies, it has spread into Europe over the last year or so, with Google warning last summer that workers in Europe were recruited through various online platforms, including Upwork, Telegram, and Freelancer.
Payment was managed via cryptocurrency, the TransferWise service, and Payoneer.
FOLLOW US ON SOCIAL MEDIA
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Freelance tech pros beware: North Korean cyber criminals are targeting gig workers in a new malware campaignNews Fake tests during the recruitment process infect applicants' devices to steal cryptocurrency
-
Fake North Korean IT workers are rampant: Here’s how to spot the telltale signs a new hire is a hackerNews New analysis from Huntress reveals the red flags to look out for when taking on new hires
-
‘The scale of PurpleDelta’s operation is easy to miss’: Fake North Korean IT workers are submitting so many job applications that companies can’t keep upNews The PurpleDelta group is applying for thousands of jobs to steal proprietary data, source code, and internal communications
-
Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effectNews The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft
-
Two US nationals sentenced for role in prolific fake worker laptop farmsNews The Americans were raising money for the North Korean regime by allowing fake IT workers to appear as legitimate US-based employees
-
North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victimsNews A fake interview process uses coding tests and repo downloads to deliver malware
-
Cloudflare warns state-backed hackers are ‘weaponizing legitimate enterprise ecosystems’ as ‘living off the land’ attacks surgeNews Chinese, North Korean, and Russian-backed threat groups now favor longer-term compromises over brute force attacks
-
Amazon CSO Stephen Schmidt says the company has rejected more than 1,800 fake North Korean job applicants in 18 months – but one managed to slip through the netNews Analysis from Amazon highlights the growing scale of North Korean-backed "fake IT worker" campaigns

