The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency, according to a new investigation published by researchers Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and the threat intelligence platform ANY.RUN. The joint effort deliberately hired suspected DPRK developers linked to the Lazarus Group and monitored their activity in controlled sandbox environments, exposing how operatives use forged identities, remote-access tools, and AI-assisted workflows to bypass hiring processes and gain legitimate access to corporate systems. The investigation, dubbed "Famous Chollima," shows that companies face a reversed security threat model: attackers who don't break in from the outside but instead apply for jobs, pass interviews, and receive trusted credentials.
The researchers' honeypot operation captured operatives using manipulated IDs, stolen identities, conflicting personal information, and financial details that didn't match the person being hired. Warning signs appeared throughout the hiring process rather than in a single obvious giveaway. Identity details such as addresses, states, documents, or banking information contradicted each other across submissions. Interview behavior revealed dependence on off-screen assistance, with candidates showing repeated glances away from the camera, delayed responses, and reliance on live translation and AI tools. Location mismatches emerged when network activity didn't align with where candidates claimed to live or work. The investigation uncovered specific infrastructure used by the suspected operatives, including nine IPv4 addresses tied to DPRK-operated VPS servers and AstrillVPN exit nodes, plus three cryptocurrency wallet addresses.
According to the researchers, the strongest indicators emerged from small inconsistencies across the hiring process rather than any single red flag. The report finds that document manipulation showed unusual metadata, visual inconsistencies, or evidence that an ID had been altered with AI. None of these signals proves malicious intent on its own, the authors write, but when several appear together, they should trigger deeper verification before the candidate receives company access. Roles with access to source code, cloud infrastructure, production systems, or financial assets should receive a higher level of scrutiny from the start, the investigation notes.
The report explains that fraudulent workers rarely reveal themselves through one obvious sign. Instead, clues surface across identity documents, interviews, location data, infrastructure, and activity after onboarding. The researchers used specially configured ANY.RUN Sandbox environments to observe the operatives' activity without exposing real corporate systems, gaining visibility into the files they opened, tools they used, and network connections they made. This approach gave them evidence that would have been difficult to assess from identity checks alone. Security teams can cross-check the uncovered infrastructure against historical logs, EDR telemetry, proxy records, and DNS data to see whether the same infrastructure has already appeared inside their organization. A match shouldn't be treated as proof of DPRK activity on its own, the report cautions, but it can be a strong reason to look deeper when combined with other suspicious signals.
The report recommends that CISOs make sure identity checks use several independent signals before access is approved. The candidate's documents, location, interview behavior, employment history, and financial details should tell a consistent story. Security teams should have access to interactive sandboxes when suspicious files, links, scripts, or tools appear around employee activity, allowing them to safely examine how the activity behaves and gather stronger evidence before deciding whether escalation or containment is necessary. Investigation findings should become part of ongoing detection rather than being checked once and forgotten, the authors advise, so security teams can spot the same or related infrastructure if it appears elsewhere in the environment. For CISOs, the priority is clear: verify identity more deeply, give security teams the right solutions to validate suspicious activity, check known infrastructure against the environment, and turn confirmed findings into ongoing detection. Organizations that assume technical controls alone will catch insider threats may discover their blind spot only after credentials have already been issued and systems accessed. The shift from perimeter defense to identity verification isn't optional anymore when the adversary's entry point is a job application rather than a phishing email.

