The North Korean IT Worker Problem Just Reached the U.S. Government
An FBI admission, an ANY.RUN sandbox sting, and the reality of North Korean IT operatives infiltrating US federal agencies, defense supply chains, and tech companies.
Quick heads up before this one starts — I’m not promising a part two here the way I did with CyberLeek. That story’s still eating most of my week, it’s basically my problem now, not just a story I cover. This one I’m breaking away for because it’s genuinely worse than the headline makes it sound, but don’t expect me circling back to it daily. One and done, probably.
Also — not explaining what North Korea is, what a VPN is, or why Lazarus Group matters. If you’re reading a threat intel piece you already know the basics. Let’s just get into the actual thing.
A North Korean Operative Worked Inside A US Federal Agency. Nobody Noticed For Months.
Todd Hemmen — FBI, deputy assistant director, Cyber Capabilities Branch — said the quiet part out loud at a conference in DC back on July 28th. A North Korean remote IT contractor got hired into a federal agency. Not a startup. Not a mid-size SaaS company with three people in HR. A federal agency. And his own words on it were basically “I’m still trying to figure out how our hiring process let this through” — which, coming from the guy whose job is to know that, is not the reassurance anyone wanted.
Here’s the thing that makes this land different than every other “DPRK IT worker” story from the last three years: this isn’t new information anymore. The Justice Department charged a Maryland man back in 2024 for helping a North Korean operative fake his way into a remote FAA contractor role. The FBI’s been issuing public alerts about this exact scheme since 2022. CrowdStrike’s own numbers say this single cluster — tracked as Famous Chollima — accounted for 47% of all state-sponsored interactive intrusions against the tech sector in the year leading up to this spring. Forty-seven percent. That’s not an edge case anymore, that’s basically the baseline threat.
And a federal agency — the org that’s supposed to have the strictest vetting on the planet — still missed it. For months.
The Sting That Actually Shows How This Works
Separate from the federal agency case — this part’s newer and honestly more interesting — three researchers (Mauro Eldritch, Heiner García, and the team at ANY.RUN) ran their own operation to see this from the inside. They deliberately hired suspected DPRK developers tied to Lazarus. Gave them what looked like normal remote-work virtual desktops.
They weren’t. They were sandboxes. Every click, every file opened, every tool launched — recorded.
What came back wasn’t subtle once you knew what to look for, but it wasn’t obvious either, and that’s the actual problem. Forged IDs that didn’t hold up under scrutiny. AI tools running in the background during interviews. VPN and VPS infrastructure stitched together to fake a US location. Real-time deepfake tech in some of the broader reporting on this cluster — live face-swapping during video calls, so the person on camera doesn’t match whoever’s actually typing.
The specific tells the researchers flagged: candidates glancing off-screen a beat too long, answers arriving with a weird delay like they’re waiting on a translation or a script, identity documents where the address, the state, and the banking info all tell slightly different stories if you actually cross-reference them instead of glancing at a PDF and moving on.
None of these, alone, means anything. A nervous candidate glances away. People type slow. That’s the whole trap — no single flag, just a pile of small ones that only look damning once you’ve already decided to look.
Can We Talk About What This Article Actually Is For A Second
So — small thing, but it bugged me enough to bring up. The piece this is all based on? It’s tagged, in tiny gray text at the very bottom, as a “contributed piece from one of our valued partners.” That partner is ANY.RUN. The same ANY.RUN whose sandbox product gets recommended four separate times in the article as the solution to the exact problem the article just spent 1,200 words describing.
That doesn’t make the underlying research fake. The investigation looks real, the IOCs are specific enough to be checked against real logs, the FBI case is corroborated by like six other outlets independently. But it’s worth just, you know, noticing the shape of this: genuine nation-state threat, real government failure, wrapped in a “here’s how to protect yourself” piece that ends with a sales link. That’s not a knock on the researchers. That’s just what cybersecurity media is now — the scarier the threat, the better the ad performs, and nobody involved really has to lie for that to be true.
The Actual Numbers, With A Disclaimer Attached
Quick disclaimer before this part, because the dollar figures floating around this story vary a lot depending who’s reporting it, and I don’t want to present any of them like they’re settled: one DOJ case put a single crypto theft at over $900,000 from four operatives. Broader reporting — the kind that’s harder to independently verify — puts total funds funneled back to Pyongyang’s weapons programs somewhere north of $800 million. That second number gets repeated a lot. I couldn’t find a primary source pinning it down cleanly, so treat it as the industry’s best guess, not a confirmed figure.
What is confirmed: hundreds of companies have unknowingly hired these operatives. Tech firms, crypto startups, and — this one’s almost funny if it weren’t so on-the-nose — at least one cybersecurity vendor hired a DPRK operative onto their own payroll without catching it.
A cybersecurity company. Got infiltrated. By the exact threat their entire industry writes newsletters about. Sit with that one.
So What Actually Stops This
Not going to pretend there’s a clever trick here, because there isn’t one. The advice from every angle on this — the FBI, the ANY.RUN researchers, the FAA case prosecutors — all converges on the same boring answer: cross-reference everything, don’t trust one signal, and don’t let “the interview went fine” be the bar for handing someone production access.
Check whether the address on the ID matches the bank details match the claimed location match the network the interview happened on. Sandbox anything a new remote hire touches before it’s live infrastructure, not after something’s already gone wrong. Treat “AI-assisted interview behavior” — the glances, the delay, the too-smooth answers — as a real category of red flag instead of just assuming the candidate’s nervous.
None of that’s exciting. None of it sells a product on its own, which is maybe why it’s buried under four callouts for a sandbox tool in the piece it came from. But it’s the actual answer, and it’s been the actual answer since 2022. The fact that a federal agency still missed it this year isn’t a sign the advice is wrong. It’s a sign almost nobody’s actually following it.
Sources: The Hacker News / ANY.RUN investigation (Aug 13, 2026), TechCrunch (Aug 11, 2026), Cybernews (Aug 2026), TheStreet (Aug 17, 2026), NBC News/Nisos investigation (2026), Ogletree FBI guidance summary, DOJ 2024 Maryland FAA contractor case filings.