securityonline.info 17 Sept 2026, 06:29 UTC

North Korean IT Worker Scheme Uses Proxy Candidates to Infiltrate Firms

North Korean IT Worker Scheme Uses Proxy Candidates to Infiltrate Firms
CyberSIXT Evidence Panel Source marked as original reporting

SECURITY researchers at Silent Push have identified a recruitment scheme designed to place a suspected North Korean IT worker in Western technology companies through proxy candidates. The operation was advertised in a public Discord community, with a promoter offering applicants 35% of their earnings while retaining 65%.

Recruits were instructed to appear in video interviews while the remote operator supplied answers through messaging services and, during coding tests, potentially controlled their computers to complete tasks. The scheme targeted applicants in the United States, European Union and Latin America, including Brazil, Mexico, Argentina, Colombia and Chile. The promoter claimed that developer contracts could pay between $130,000 and $180,000 a year and that several contracts could be managed simultaneously.

Silent Push attributed the activity with high confidence to a North Korean IT worker, citing the use of Astrill VPN, behaviour during a video call, language and infrastructure indicators, and financial-routing patterns. Once employed, such workers may gain access to company repositories and customer data; the article says operators can steal source code or databases and threaten disclosure for ransom, although it does not provide evidence that this particular operation had compromised an employer.

It also warns that payments could create sanctions risks under US Office of Foreign Assets Control rules. Silent Push and a US State Department advisory recommend verifying applicants’ identities and physical locations. Suggested controls include live identity checks, checking network locations, banning remote control during interviews, monitoring unexpected VPN use and ensuring tax records match the applicant’s stated location.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline