Insights into Suspected DPRK Workers: Red Flags to Look Out For

Key Takeaways

  • North Korean (DPRK) remote IT workers (sometimes referred to as FAMOUS CHOMILLA) continue to pose a prolific threat to global organisations. DPRK-aligned operatives use fake or stolen identities to get hired at companies before sending their wages back to North Korea's regime, stealing data, or planting malware.

  • Throughout 2026, Huntress has helped a number of organizations validate suspicions that they've hired North Korean nationals posing as legitimate workers.

  • Detecting DPRK remote workers is inherently challenging for defenders because the workers have been hired by organisations just like a normal employee. They're not compromising legitimate accounts and oftentimes use VPNs and proxy services to mask their true locations. Public reporting has given defenders a better idea on certain indicators and activity associated with these threat actors once they are hired into an organisation; however, it's important to understand their wider modus operandi and how they can be identified during the hiring process to prevent them from gaining employment altogether.

  • After being alerted by organizations who were already suspicious that they had DPRK workers in their environments, Huntress helped verify that the workers in question weren't legitimate by tracking down several indicators that were tied to previous DPRK-linked incidents. Huntress also identified another case through proactive threat hunting that indicated a DPRK worker was likely present in a different environment.

  • We are releasing our investigations, correlations, and findings in this blog to help other defenders uncover potential FAMOUS CHOMILLA intrusions. 

Acknowledgements: Special thanks to Dray Agha, Casey Smith, Dave Kleinatland, Matt Kiely, Rich Mozeleski, Michael Tigges, Josh Allman, Anton Ovrutsky, Michael Brown, Harlan Carvey, and Lindsey Welch for their contributions to this investigation and writeup.

Introduction

North Korean workers (sometimes referred to as FAMOUS CHOLLIMA) have significantly improved and increased their activity over the past few years. These actors will pretend to be legitimate workers, apply for remote positions at companies, and once hired and onboarded funnel wages back to the North Korean regime in an effort to help North Korea generate revenue while evading international sanctions. Some public reports also cite DPRK workers infiltrating companies to exfiltrate data, deploy malware, or extort their employers once discovered. 

DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organisations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do. Furthermore, DPRK workers often use stolen identity documents, VPNs, and proxy services to mask their true identity and location, meaning other methods must be used to help verify if an employee is who they say they are.

While DPRK workers have historically sought employment in IT-related roles, this has since expanded to include a wide variety of remote roles outside of IT. So far in 2026, Huntress has supported investigations where a total of five individuals were identified as likely DPRK workers employed in partner organisations. The individuals were employed across a variety of roles, including IT, sales and marketing, and the medical profession. For three of the workers, Huntress obtained and reviewed suspected fraudulent identification documents during the course of the investigation that helped to determine they were unlikely to be legitimate individuals. For another worker, Huntress identified a photo that had been stolen from a legitimate GitHub account where the face had been altered.

Due to the challenge of detecting this type of threat, we are detailing these incidents and our subsequent discoveries that may help others identify suspicious activity related to DPRK workers in their environments. 

February 2026: Multiple DPRK workers in the healthcare industry

Beginning in February 2026, Huntress was alerted by an Australian partner who suspected that three employees were North Korean workers impersonating Chinese individuals.

The partner was initially suspicious of the employees for several reasons, including their use of infrastructure that had previously been associated with DPRK workers. For example, the accounts were repeatedly authenticating via Astrill VPN, which has been publicly documented as being used in remote IT worker campaigns.

In an effort to help the partner investigate these users and determine whether or not they were legitimate, Huntress analysed six months of Unified Audit Logs, inspected events across Exchange, SharePoint, sign-ins, and other Microsoft 365 workloads, and looked into all relevant Huntress Identity Threat Detection and Response (ITDR) authentications. In particular, researchers looked at infrastructure used by the individuals including IP addresses, ASNs, geographic access patterns, and more.

We verified three suspicious accounts authenticating with several IP addresses identified to be Astrill VPN nodes. We then confirmed that they were also using IPRoyal Proxy, a legitimate commercial proxy service provider that sells access to IP addresses through which customers can route their internet traffic; as well as WorkTitans B.V., a bulletproof-hosting operation that appears to have been raided by the Fiscal Information and Investigation Service of the Netherlands (FIOD).

Extensive VPN and proxy infrastructure usage across all three accounts deviated from typical end-user behavior, suggesting attempts to hide each individual's real geolocations.

The use of a VPN by itself is not a reliable indicator of compromise, and often presents false positives due to their legitimate uses; therefore we also profiled activity across the three users to corroborate when they were active. In all cases, less than 50 percent of activity observed occurred during expected business hours, and peak activity was observed at exactly midnight UTC. Although this overlaps with business hours in both Australia and China, it is worth noting this also corresponds to 9am in North Korea.

During the investigation Huntress came across documents in two of the workers' OneDrive accounts that shared a common naming convention. The documents included photos of: a resident identity card, a People's Republic of China passport, and an electricity bill, all of which appear to have been used to prove their residential address and identity during their onboarding process. While the documents appeared legitimate at first glance with valid information, in addition to a similar naming convention between two separate individuals' documents, Huntress found overlaps that suggest they were fraudulently created by the same person. These include:

  • The exact angle of photography used on the document

  • The passport place of issue (both were issued in Shenzhen)

  • The passport date of issue (only one day apart)

  • The validity dates on each resident identity card (both were valid for the exact same period of time)

  • The issuing authority on each resident identity card (both were issued by Songgang Police Station)

  • The documents' recentness (all identity documents including the passport, energy bill, and resident identity card were all issued within 2 weeks of one another and on the same month that Huntress investigated the incident)

  • The residential address for each individual (both individuals lived on the same street)

  • The electricity bill layout (both documents contained visible typos and a layout that mirrors fake State Grid Corporation of China energy bill templates available online)

The metadata on all document photos: 

  • Showed a device time offset of UTC +03:00

  • Registered that an iPhone 15 Pro Max back triple camera 6.765mm f/1.78 was used to take the photos

  • Had an original creation time close to one another (for example both individual's passport photos were taken just 8 minutes apart)

Although both individuals had unique photos showing the rear of their resident identity card, it also appears likely that both individuals accidentally used a photo of the same resident identity card rear based on some visible damage consistent across both photos.

Figure 1: Rear of resident identity card for person 1 (left) and rear of resident identity card for person 2 (right) showing the validity period and issuing police station (in addition to some damage visible across both cards).

Figure 1: Rear of resident identity card for person 1 (left) and rear of resident identity card for person 2 (right) showing the validity period and issuing police station (in addition to some damage visible across both cards). it's possible that this was an oversight by whomever facilitated photographing these identity documents, it seems unlikely that both individuals involved would have had such coincidence and overlaps between one another.

Further, the electricity bills for both individuals appear to have been based off of a cheap template available online, and contained elements that if noticed should raise red flags even if the format of a legitimate foreign electricity bill wasn't known. For example in both cases, the words "clutter" and "hassle" were changed to "dlutter" and "hassic," possibly due to a translation issue if optical character resolution was used to turn a picture into an editable template. Both contained links to Arizona Public Service websites that have nothing to do with the State Grid Corporation of China.

Figure 3: Word anomalies in electricity bill for person 2

Figure 2: Word anomalies in electricity bill for person 1

Figure 3: Word anomalies in electricity bill for person 2

Figure 3: Word anomalies in electricity bill for person 2

Despite the likelihood of passports and resident identity cards being fraudulent, there's still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed. For example, one of the individuals shared the exact same name as someone else who works in the healthcare industry that had multiple pictures available online; however, their identity documents look nothing like this person. There's always the potential that multiple people in the same industry could share the exact same full name; however, given the other indicators of identity theft observed, this is worth highlighting.

Due to the various breadcrumbs potentially tying these accounts to DPRK-linked activity, we reported our findings to the partner organisation and strongly recommended that they engage incident response services.

August 2026: DPRK worker in the financial services industry

In August 2026, Huntress was alerted by a partner who had been notified of a potential North Korean worker in their environment from a third-party security vendor. Because the suspected worker had only recently been onboarded into the company, a Huntress agent had not yet been installed on their device.

Upon installation of the agent and further review, Huntress identified multiple suspicious, low-prevelence physical devices connected to the host, which matched indicators that had been previously tied to DPRK workers. 

The first was the presence of PiKVM, which is an open-source, Raspberry Pi-based KVM-over-IP device. This device enables remote control of the connected computer through a web browser at the hardware level–meaning that they have remote access even before the operating system boots, and without the need to install remote access software. Multiple intelligence reports have pointed to remote DPRK IT workers using PiKVM devices for remote access.

On the host, we found that the Realtek Audio Universal Service logged events on July 31, approximately seven days before Huntress was deployed, which showed Windows switching the audio output to a PiKVM V4 Mini, as well as Windows Security Event Logs (specifically Event ID 6416) showing the system connected to a PiKVM V4 Mini. 

We also inspected USB device information via the Windows Registry and found further evidence of the PiKVM installations first starting on July 31:

VID_1D6B&PID_0104&MI_04 [2026-07-31 21:58:06Z]

S/N: 6&9f4824e&0&0004 [2026-08-06 00:20:21Z]

Properties Key LastWrite: 2026-07-31 21:58:06Z

   FriendlyName    : PiKVM Composite Device       

   First InstallDate     : 2026-07-31 21:58:06Z

   InstallDate           : 2026-07-31 21:58:06Z

   Last Arrival          : 2026-08-06 00:20:20Z

Given the activity pre-dated Huntress deployment, forensic artifacts painted a timeline of activity that likely occurred prior to the PiKVM being connected.

July 24

  • The system was built by the managed service provider and account access was tested. At this time the system was tied to the managed service provider's guest wireless network.

July 27

  • The user account received initial logon emails and authenticated to a number of cloud-based services used by the company. This may indicate that the device was built and shipped by the MSP on the 24, before arriving at its destination on the 27.

July 31

  • 2026-07-31T04:16:00 UTC: The laptop was first connected to a GL.iNet travel router. Whilst connecting to a travel router may not be inherently suspicious, in this case it is unusual as the previous activity seems to indicate the device had already been shipped and arrived at its destination. This raises a question on why the device was connected to a travel router for many hours, and it may indicate that the device was being transported, yet again, to a new location whilst having a requirement to remain connected to the internet.

  • 2026-07-31T16:51:24 UTC: The computer was first connected to a BGW320-500 router on a residential wireless network called "Pickle_Rick". The use of a residential router strongly suggests the device had made it to an individual's home by this point in time.

  • 2026-07-31T20:14:20 UTC: The user completed an Entra self-service password reset and then searched for the Windows 10 group policy editor.

  • 2026-07-31T21:10:05 UTC: The computer was connected to a USB-to-UART serial console adapter.

  • 2026-07-31T21:12:31 UTC: The computer was connected to a PiKVM V4 Mini. The timing of this is suspicious as it indicates that just hours after the computer arrived at a residential address it was connected to a device that allowed it to be controlled remotely over the internet.

  • 2026-07-31T21:26:54 UTC: The computer was connected to an ethernet internet connection, never again connecting to a wireless network. This potentially indicates that the laptop had become a fixed rack asset in a laptop farm. Approximately 10 minutes later the PiKVM was initialised and connected a number of devices to the system.

While the activity leading up to the PiKVM being connected provided initial context, the activity that proceeded it gave more insight into actions taken by the user that are either notable or suspicious:

  • 2026-07-31T21:49:34 UTC: The user searched for online audio tests and began testing audio output to validate their audio worked.

  • 2026-07-31T21:58:06 UTC: The PiKVM audio interface was registered on the system.

  • 2026-07-31T22:00:52 UTC: The user began searching for microphone tests online before accessing mictests[.]com to validate their microphone worked.

  • 2026-07-31T22:38:01 UTC: The user entered a personal Gmail into a web form; it's worth noting this email shared a similar naming convention to other email addresses noted to have been used by DPRK workers in the past.

  • 2026-08-03T12:03:23 UTC: The user accessed ip[.]me directly to determine their public-facing IP address just minutes before joining a Zoom meeting.

The employee also retrieved an image from a file-sharing site, potentially for use on an internal communications tool, which is highly suspicious and a red flag in itself:

  • 2026-08-03T21:26:01 UTC: An unknown third party uploaded a file to a file-sharing service (SendGB) minutes before this was downloaded by the user

  • 2026-08-03T21:29:55 UTC: The user downloaded the file from SendGB and moved it to a folder they created within the root of the drive (C:\asset).

A reverse image search of this picture revealed that they had reused and tampered with a picture of somebody else.

Figure 4: Picture used by the employee (left) and the original image from a legitimate GitHub profile (right)

Figure 4: Picture used by the employee (left) and the original image from a legitimate GitHub profile (right)

We also found evidence of a Guermok USB capture card that had been connected to the user's computer. This device registered as a webcam on the machine, and enabled any video streaming through it to be sent as a webcam input in web conferencing applications such as Zoom. The Guermok device is a supporting hardware anomaly that by itself is not evidence of DPRK involvement. However, it becomes significant because it co-occurred with a PiKVM, which we saw during this incident and across others.

Both the Windows Registry and Windows Security Event Logs (again, Event ID 6416) indicated the installation of this device was a few days after the PiKVM device was installed:

VID_345F&PID_2130&MI_00 [2026-08-04 22:36:23Z]

S/N: 6&1346e323&0&0000 [2026-08-06 00:20:17Z]

Properties Key LastWrite: 2026-08-04 22:36:23Z

   FriendlyName    : Guermok USB3 Video           

   First InstallDate     : 2026-08-04 22:36:23Z

   InstallDate           : 2026-08-04 22:36:23Z

   Last Arrival          : 2026-08-06 00:20:16Z

We provided our assessment to the impacted organisation that the identity of this individual was questionable. Following our investigation, the partner confirmed their suspicions about the employee, citing their refusal to show the room they were in, and their reluctance to appear on camera.

August 2026: DPRK worker in the financial services industry

On the heels of this early August investigation, the Huntress Detection Engineering and Threat Hunting (DE&TH) team began proactively threat hunting for activity that aligned with public reporting surrounding DPRK IT workers/FAMOUS CHOLLIMA.

After reviewing hosts identified to have connected PiKVM and Guermok USB devices, the threat hunt led to the team discovering one additional case at a separate partner where the threat actor appeared to have stolen or borrowed an existing identity to fraudulently obtain employment.

The host and user, onboarded 13 days prior, appeared to be a sales/marketing employee. After a forensic review of the host, Huntress identified suspicious tools and services being used, these included:

  • Toffeeshare: An encrypted, peer-to-peer, file sharing service that was used to send through (likely fraudulent) identity documents, and a Chrome extension used to record video and audio of Chrome browser tabs. These identity documents likely belonged to a real person as all of their identification numbers validate as legitimate, but their photo had been altered to resemble the likeness of the fraudulent employee. Based on artifacts identified within the employee's browsing history, this may have been used to complete a I-9 Employment Identity Verification form. 

  • Chrome extensions: Various Chrome extensions for English translation assistance, recording video and audio within Chrome browser tabs, Zoom chat exporting, and English pronunciation assistance

  • Microphone and audio testing: Much like other cases, this one involved the suspected DPRK worker accessing various online services to test their microphone and webcams including webcammictest[.]com and onlinemictest[.]com

  • Codeshare: Unlike other cases, this one involved the use of an online code sharing service to make weekly Zoom meetings available, including embedded password values to access them

Figure 5: Zoom meeting invite links shared via a public codeshare

  • VDO Ninja: A free software designed to transmit audio and video as a device input to software such as OBS. In this instance, Huntress assessed that this was used for screen-capture of the host.

hxxps://vdo.ninja/?push=host<redacted>&password=<redacted>&screenshare&label=host

VDO Ninja meeting and screenshare usage recovered from Google Chrome cache

The identity documents obtained during this investigation showed that the individual shared the following details with someone whose mugshot had previously been posted online by law enforcement after their arrest:

  • Full name (first + middle + last)

  • Location of drivers license/arrest location

  • Date of birth

The mugshot differed from the obtained identity document, further strengthening the case that this was fraudulent. In addition, the signature used on both identification documents retrieved appeared to have been digitally overlaid onto the document rather than handwritten.

These key pieces of evidence supported the assumption that the identification documents, while legitimate in information, had been digitally altered to substitute the legitimate individual's face with another's, likely the suspected DPRK worker, to commit identity theft and obtain fraudulent employment at this organisation. It's also important to note that the documents both appeared as if they were either placed on a surface with various textures, or held by an individual, which closely resembles what had been observed in other cases. These could easily be mistaken for legitimate documents if not examined under scrutiny.

Investigating DPRK breadcrumbs

The threat of DPRK remote workers isn't going anywhere, due in part to the challenges of actually detecting this type of threat. Here are some DPRK red flags based on the incidents we've seen so far this year that can be used in addition to recommendations provided by global government agencies:

  • PiKVM and Guermok devices, particularly when they are both used by user accounts: Defenders can alert on Windows Security Event ID 6416 when device_description contains PiKVM or Guermok, and hunt the Windows registry path HKLM\SYSTEM\CurrentControlSet\Enum\USB, especially FriendlyName values such as PiKVM Composite Device and Guermok USB3 Video.

  • Web services and browser extensions associated with screen, audio, and video redirection or recording, microphone testing, translation, and file sharing: We saw suspicious processes associated with browser-based screen streaming, like VDO.Ninja, chrome plugins for recording tabs, and Toffeeshare for sending files. We also saw the threat actors using online microphone and webcam testing sites.

  • Sharing recurring meeting invites to public text-sharing websites: We saw the threat actors publicly sharing their recurring Zoom meetings into Codeshare, a public code sharing service. 

  • VPN/proxy Infrastructure combined with unusual geography: Defenders should monitor authentication through Astrill VPN, IPRoyal Proxy, and infrastructure associated with WorkTitans B.V.; while IPs can be useful as supporting evidence, infrastructure can be reused or produce false positives and thus they should be correlated with other evidence like access patterns and inconsistent geolocation.

  • Anomalous identity-related activity like working-hour patterns: Timezone activities alongside VPN/proxy use or other suspicious activity can be a stronger indicator. Defenders should baseline each employee's normal activity and local timezone and flag sustained access during inconsistent hours.

  • Metadata and validity of identity documents: While fake identification documents can be very challenging to detect with the naked eye, looking at their metadata and giving extra attention to any which have been recently issued can surface anomalies that raise questions on how and where the photos were taken and if they were altered. Consider also requiring any identification documents for new employees to be notarized.

The combination of endpoint, identity, browser, cloud, and authentication telemetry can help defenders flag these patterns of concern. Outside of the actual fraudulent identification documents themselves, few single indicators prove DPRK involvement, but correlated technical and identity signals can help organisations uncover suspected activity earlier and respond before access is used for data theft, malware deployment, or extortion. 

Since fraudulent workers are legitimately onboarded employees, identifying them post-hire involves manual effort and multiple points of evidence that, while individually are not indicative of malice, combined together present a much stronger picture of DPRK worker activity. Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding. When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.

For more information on identifying deepfakes, check out our _declassified episode on this topic.