North Korean Secret IT Workers Use Fake Identities to Land Remote Jobs

North Korean tech workers are using fake documents and AI tools to trick Western companies into giving them remote jobs.
North Korean Remote Workers

Secret North Korean tech workers use fake documents and AI tools to land remote company jobs and access private systems.

Secret North Korean technology workers are tricking big business owners and government offices into hiring them for work-from-home jobs. Cyber researchers recently found that these workers use stolen photos, fake names, and artificial intelligence programs to clear job interviews and look like regular applicants.

Instead of trying to break into secure computers from the outside using virus programs, these tricksters simply apply for open computer jobs, get hired legally by unsuspecting bosses, and gain direct access to private network systems.

Investigating teams from security organizations like BCA LTD, NorthScan, and ANY.RUN caught several of these secret operators during a planned test in August 2026. The researchers created fake job posts and hired suspected workers linked to a well-known hacking group called the Lazarus Group. Once hired, the workers were placed inside special, safe computer rooms that looked like real company networks.

This setup allowed researchers to secretly watch and record every single action the fake workers took on their screens without exposing real corporate data.

During the daily work routines, these secret workers used smart computer programs to complete their daily tasks and hide where they were actually located. Many of them relied on live artificial intelligence translation software to talk with their managers because they did not speak English well.

When video calls happened, workers often looked away from the screen to read answers generated by AI tools. They also used fake network tools to make it look like their computer was sitting inside a house in America or Europe, when they were actually working from somewhere else.

This sneaky hiring tactic is growing rapidly because many companies now hire computer coders from home instead of making them come into an office. Businesses often fail to properly double check who is actually on the other side of the computer screen.

See Also: Safaricom Wins Top Cybersecurity Award for Keeping Customer Money and Data Safe

Once inside a business, these workers earn large salaries that get sent back to funding state projects, while some also steal company secrets or prepare future cyber attacks against their employers.

Warning bosses about how easy it is to fall into this trap, security researchers noted that companies are used to thinking about attackers as outsiders trying to break in, adding that North Korean IT workers flip that model as they apply for jobs, pass interviews, receive legitimate credentials, and end up inside the same systems companies spend millions trying to protect.

To prevent bad actors from getting onto official payrolls, business owners are being urged to check job candidates very carefully before handing over work laptops or password access.

Experts advise hiring teams to watch out for small mistakes, such as bank account names that do not match identity cards, strange delays during video calls, or strange internet locations. Combining deep document checks with live video tests makes it much harder for fake applicants to trick hiring managers and slip into trusted office networks.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.