Inside the DPRK “IT Worker” Playbook and What Your Company Should Do Now

This post distills recent public reporting on a North Korean (DPRK) remote-worker scheme into the concrete legal, sanctions, and insider-risk steps counsel should drive right now.
Quick Overview
A recent investigation by on-chain analyst ZachXBT reveals how a small North Korean (DPRK) team utilized over 30 fabricated identities, complete with government-issued IDs and purchased Upwork/LinkedIn accounts, to secure developer roles, manage work through Google tools, and receive payment via cryptocurrency.
The workflow—fake personas, rented devices, remote-access tools, and crypto payouts—mirrors tactics flagged in recent U.S. government advisories, and investigators have linked one of the team’s wallets to the $680K Favrr exploit (June 2025).
This is not just a cybersecurity problem. Under OFAC’s strict liability framework, a company can face civil penalties for paying sanctioned persons, even if it is unaware of the payment. That means DPRK “IT worker” schemes carry overlapping sanctions, AML, and insider-risk exposure. Companies hiring remote contractors, especially those paying in digital assets, should take this as a cue to tighten identity verification, sanctions screening, and remote-access controls before onboarding and at every payment cycle.
What happened? A DPKT IT worker’s device was reportedly compromised

An unnamed source reportedly compromised a DPRK IT worker’s device, exporting Google Drive and Chrome profiles plus screenshots showing how a five-person cell coordinated schedules, budgets, and interview prep, mainly in English, with purchases of SSNs, Upwork/LinkedIn accounts, phone numbers, AI tools, device rentals, and VPNs/proxies, as outlined in the original investigation and contemporaneous coverage.

The workflow described:
Acquire freelance accounts → buy/rent hardware → use remote-access software (e.g., AnyDesk) to perform work for unsuspecting teams.

Hidden Hires: Legal & Sanctions Risks from DPRK Remote IT Worker Schemes

The weekly reports from 2025 detail day-to-day activity across each team member, including tasks completed, hours logged, and a running list of “issues/mistakes.” They even include self-notes, e.g., “I can’t understand job requirement…” and “Solution/fix: Put enough effort in heart,” which offer a candid window into how the group evaluated performance and set goals, consistent with the referenced investigation.
The expense ledgers provide a complementary view of operational needs and procurement. Line items show purchases of SSNs, Upwork and LinkedIn accounts, phone numbers, AI subscriptions, proxies/VPNs, the “Octo browser,” and various verification services, again mirroring what the investigation describes.

Calendars and accompanying scripts round out the operational picture. The materials include interview talking points customized to specific personas, such as “Henry Zhang,” and scheduling trackers that map outreach and meeting cadence.

Finally, the workflow relies on remote-access software, reportedly AnyDesk, which is often run on rented or newly purchased machines. This pattern aligns with tactics, techniques, and procedures flagged by federal advisories.
Following the Money: The On-Chain Tie-In

Investigators flagged wallet 0x78e1a4781d184e7ce6a124dd96e765e2bea96f2c as a payment hub for the cell and closely linked on-chain to the Favrr exploit, with additional DPRK workers allegedly mapped from that nexus.
Treat these findings as high-confidence risk signals for screening and controls, even while recognizing that they are investigative linkages, not formal government attributions. What you should consider:
- Wallet nexus can teach us (0x78e1…):
- Use a cited address and any associated clusters as immediate red flags in your sanctions/AML screening.
- Consider address reuse, shared spend patterns, and interaction with known risky services (e.g., mixers) as aggravating factors.
- Keep in mind this is an investigative tie, so document that your actions are risk-based rather than nationality-based.
- Operational implications:
- Implement pre-payment and post-payment wallet screening; maintain deny-/watchlists for flagged addresses
- Require contractors to (1) use KYC’d payout rails, (2) attest that they control the address provided, and (3) notify you before any address change.
- Segregate the treasury (separate hot wallets per vendor/program), prohibit unapproved intermediaries, and log transaction hashes, timestamps, and the blockchain for every disbursement.
- If exposure is detected:
- Preserve evidence (tx hashes, block heights, wallet paths, communications), pause transactions, and evaluate whether funds constitute “blocked property.”
- Coordinate through counsel on reporting and any voluntary self-disclosure, and document the risk assessment and remediation steps taken.
Make on-chain checks a standard control, not an ad hoc response, embed wallet screening into vendor onboarding and every payment run, and review historical flows for contact with flagged clusters. The earlier you operationalize these steps, the easier it will be to defend decisions with regulators and mitigate risk.
Legal & Compliance Exposure: What’s at Stake and Why It Matters

The patterns described above aren’t just a security concern; they translate directly into sanctions, payments, and insider-risk exposure. Below is a concise checklist for counsel and compliance leaders to frame the risk and prioritize controls.
- Sanctions risk (strict liability): OFAC enforces DPRK sanctions on a strict liability basis, meaning civil penalties can apply even without knowledge or intent. Recent enforcement actions and prosecutions, along with high-profile “laptop-farm” cases, underscore how quickly an unwitting hiring or payment can create liability.
- Crypto payment duties: If digital assets impact your workflows, you must comply with OFAC’s virtual currency requirements: screening, blocking, reporting, record-keeping, and, when appropriate, voluntary self-disclosures. These obligations apply regardless of whether payments are made directly or routed through intermediaries.
- Insider risk & IP loss: Remote-access misuse (e.g., AnyDesk/RDP), lateral movement, and data exfiltration are persistent threats. Federal advisories highlight that these tactics often exploit weak device controls, unmanaged endpoints, and permissive access, thereby elevating both operational and legal exposure.
Treat these as enterprise risks, not one-off incidents. Align legal, security, and HR on a shared playbook for sanctions-safe hiring and contractor management, codify crypto payment controls, and tighten remote-access governance. The earlier you operationalize these safeguards, the smaller your enforcement and breach footprint will be.
Immediate, Defensible Controls You Can Deploy Now

Here’s how you can translate the risks above into concrete, audit-ready actions. The controls below are designed for legal, compliance, and security teams to implement quickly while aligning with federal guidance and industry best practices.
- Contracting & policy:
- Ban account sharing and subcontracting without written consent
- Require verified identity and location (government-ID + liveness, verified phone), and a bank account in the contractor’s name
- Prohibit unapproved remote-access tools
- Mandate managed endpoints/VDI and least-privilege access.
- Align these terms with the remote-worker PSA and the Treasury/CISA advisory to ensure defensibility
- Screening & monitoring:
- Sanctions-screen names, entities, emails, and, if relevant, wallet addresses pre-onboarding and per-payment
- Enforce geolocation checks
- Detect AnyDesk/TeamViewer/RDP on non-managed devices
- Flag patterns, such as multiple personas on a single device, are consistent with the PSA’s recommendations
- When red flags appear:
- Preserve evidence (logs, chats, invoices, wallet paths)
- Pause access and payments
- If crypto becomes “blocked property,” follow OFAC blocking/reporting requirements and consider a voluntary self-disclosure
- Coordinate with DOJ/FBI/OFAC through counsel to manage notifications and remediation
- Treat this as a living control set. Document each step, assign ownership across Legal, Compliance, Security, and HR, and test routinely. Clear policies, repeatable screening, and decisive incident playbooks are what make these controls enforceable—and persuasive to regulators.
Treat this as a living control set. Document each step, assign ownership across Legal, Compliance, Security, and HR, and test routinely. Clear policies, repeatable screening, and decisive incident playbooks are what make these controls enforceable—and persuasive to regulators.
How Hodder Law can help
While no policy can guarantee you’ll never encounter a bad actor, we can help you reduce the likelihood and impact of high-risk hires and payments by building audit-ready, regulator-aligned controls from day one:
- Company Formation with sanctions attestations, vendor-oversight clauses, and banking safeguards.
- AML Compliance tailored to contractor and crypto payment flows.
- OFAC Compliance programs for screening, blocking, reporting, and voluntary self-disclosures.
- Money Transmitter Licensing analysis and application support where payouts may trigger MTL/MSB rules.
Our role is to help you hire and pay with defensible procedures, respond decisively when red flags emerge, and document your decisions for regulators.
Sources & further reading
- Read ZachXBT’s investigative thread and coverage of the Favrr wallet cluster.
- DOJ 2025 actions against DPRK remote-worker schemes; FBI IC3 PSA (July 2025)
- OFAC: Strict-liability framework
- OFAC Virtual Currency Guidance (screening, blocking, reporting)
- CISA/FBI/Treasury publications on DPRK cyber/contractor risks
This post summarizes public reporting and government guidance. Allegations regarding specific identities/wallets are attributed to the cited investigators and should be independently verified before any employment or payment decisions are made.
