North Korean IT Workers Infiltrate Western Tech Firms Using Fake Identities
Blockchain investigator ZachXBT has uncovered a sophisticated operation involving North Korean IT workers who infiltrated Western technology companies through remote development positions. The operation, revealed on Aug. 13, involved five workers from the Democratic People's Republic of Korea (DPRK) using fake identities to secure jobs on platforms like Upwork and LinkedIn.
The workers systematically purchased fake social security numbers, accounts on freelancing platforms, phone numbers, and rented computers to maintain their cover. Google Drive exports and Chrome browser profiles showed extensive use of Google products for organizing team schedules, tasks, and budgets, with communication primarily in English.
Weekly reports from 2025 indicated struggles with job requirements, with one worker noting, 'I can’t understand job requirement, and don’t know what I need to do,' alongside a directive to 'put enough efforts in heart.' The team relied on tools like AnyDesk for remote access, alongside subscriptions to AI services, VPNs, and proxies to maintain their fake identities.