Insights into Suspected DPRK Workers

Imported from official source

Cybersecurity Classified by Officially

North Korean (DPRK) remote IT workers (sometimes referred to as FAMOUS CHOMILLA) continue to pose a prolific threat to global organisations. DPRK-aligned operatives use fake or stolen identities to get hired at companies before sending their wages back to North Korea's regime, stealing data, or planting malware.

Throughout 2026, Huntress has helped a number of organizations validate suspicions that they've hired North Korean nationals posing as legitimate workers.

Detecting DPRK remote workers is inherently challenging for defenders because the workers have been hired by organisations just like a normal employee. They're not compromising legitimate accounts and oftentimes use VPNs and proxy services to mask their true locations. Public reporting has given defenders a better idea on certain indicators and activity associated with these threat actors once they are hired into an organisation; however, it's important to understand their wider modus operandi and how they can be identified during the hiring process to prevent them from gaining employment altogether.

After being alerted by organizations who were already suspicious that they had DPRK workers in their environments, Huntress helped verify that the workers in question weren't legitimate by tracking down several indicators that were tied to previous DPRK-linked incidents. Huntress also identified another case through proactive threat hunting that indicated a DPRK worker was likely present in a different environment.

We are releasing our investigations, correlations, and findings in this blog to help other defenders uncover potential FAMOUS CHOMILLA intrusions. 

Acknowledgements: Special thanks to Dray Agha, Casey Smith, Dave Kleinatland, Matt Kiely, Rich Mozeleski, Michael Tigges, Josh Allman, Anton Ovrutsky, Michael Brown, Harlan Carvey, and Lindsey Welch for their contributions to this investigation and writeup.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.