Executive Summary
Security researchers from ANY.RUN conducted an extensive investigation into North Korean IT worker infiltration schemes by creating a fake company to attract fraudulent job applicants. The study revealed sophisticated operations where Lazarus Group affiliates use stolen identities, AI-generated profile photos, and elaborate cover stories to secure remote positions at legitimate organizations. These fake employees then establish persistent access to corporate networks, potentially enabling data theft, intellectual property exfiltration, and deployment of malware while generating revenue for North Korean state operations. The investigation documented multiple phases of the scam including initial contact, identity verification circumvention, and operational security measures used by the infiltrators. This represents a significant evolution in state-sponsored cyber operations, blending traditional espionage with employment fraud to achieve long-term network access and financial gain for the DPRK regime.
Why This Matters Now
With remote work normalization post-pandemic, organizations face unprecedented risks from sophisticated nation-state actors exploiting hiring processes. Recent Treasury sanctions and FBI warnings highlight the urgent need for enhanced employee verification and insider threat detection capabilities.
Attack Path Analysis
Employment scam operators established fake companies to recruit legitimate workers while building trust over time. Recruited employees were gradually introduced to malicious activities disguised as normal work tasks. Internal systems were accessed using legitimate credentials from compromised employees. Attackers established persistent communication channels through normal business tools. Sensitive data including employee information, client data, and operational intelligence was systematically collected. The fake company operations caused financial losses, reputational damage, and potential regulatory violations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Scammers created legitimate-appearing company infrastructure and job postings to recruit unsuspecting employees through standard hiring processes
MITRE ATT&CK® Techniques
Phishing
Compromise Accounts: Email Accounts
Establish Accounts: Email Accounts
Acquire Infrastructure: Domains
Phishing for Information
Gather Victim Identity Information: Email Addresses
Phishing: Spearphishing via Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Security Awareness and Training
Control ID: ID.BE-5
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – ICT-Related Incident Management
Control ID: Article 13
PCI DSS 4.0 – Security Awareness Program
Control ID: 12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Employment scam research reveals social engineering vulnerabilities in IT hiring, requiring enhanced zero trust segmentation and threat detection for remote workforce verification.
Staffing/Recruiting
Fake company operations directly target staffing industry trust mechanisms, necessitating egress security controls and anomaly detection for legitimate candidate verification processes.
Financial Services
Employment fraud schemes exploit financial sector hiring practices, demanding encrypted traffic monitoring and multicloud visibility to prevent data exfiltration through infiltrated employees.
Computer Software/Engineering
Software engineering firms face insider threat risks from fake employees, requiring Kubernetes security and inline IPS protection against malicious code injection.
Sources
- Researching Employment Scamshttps://www.schneier.com/blog/archives/2026/09/researching-employment-scams.htmlVerified
- Lazarus Group IT Workers Investigation Part Two - ANY.RUN Cybersecurity Bloghttps://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/Verified
- FBI Advisory - North Korean State-Sponsored Cyber Actors Use Maturing Cryptocurrency Money-Laundering Techniqueshttps://www.fbi.gov/news/press-releases/fbi-advisory-north-korean-state-sponsored-cyber-actors-use-maturing-cryptocurrency-money-laundering-techniquesVerified
- CISA Alert - North Korean State-Sponsored Actors Likely Exploiting CVEs for Remote Code Executionhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207aVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would limit the scope and effectiveness of this employment scam attack by constraining lateral movement between cloud environments and reducing the blast radius of compromised insider access through workload segmentation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Newly onboarded employees would likely have been constrained to limited network segments and predefined application access paths, reducing their ability to immediately access sensitive systems across the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Employee access expansion would likely have been constrained by segmentation boundaries that limit privilege scope to specific workloads and prevent automatic trust inheritance across cloud environments.
Control: East-West Traffic Security
Mitigation: Cross-departmental and inter-cloud movement would likely have been significantly constrained by east-west traffic inspection and policy enforcement that blocks unauthorized communication paths between workloads.
Control: Multicloud Visibility & Control
Mitigation: Unauthorized external communications would likely have been detected and constrained through enhanced visibility into traffic flows and anomalous communication patterns across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely have been constrained by egress policies that limit outbound data flows and enforce inspection of traffic leaving cloud environments to unauthorized destinations.
While some data exposure may still occur, the overall business impact would likely be reduced through contained blast radius and limited access to critical systems and sensitive data repositories.
Impact at a Glance
Affected Business Functions
- Human Resources Recruitment
- Information Technology Operations
- Corporate Security
- Financial Operations
Estimated downtime: 7 days
Estimated loss: $250,000
Potential exposure of employee personal information, corporate credentials, intellectual property access through compromised employee accounts, and possible financial data through fraudulent employment schemes targeting job seekers and organizations
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to limit employee access to only necessary resources and prevent lateral movement between systems
- • Deploy Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns that may indicate insider threat activities
- • Enforce Egress Security & Policy Enforcement with FQDN filtering to monitor and control outbound data flows and prevent unauthorized data exfiltration
- • Utilize Threat Detection & Anomaly Response capabilities to establish behavioral baselines and alert on unusual employee activities or access patterns
- • Enable comprehensive East-West Traffic Security monitoring to detect unauthorized internal communications and data movement between workloads and services



