← All briefs
high September 6, 2026

DPRK Remote Worker Investigation: KVM over IP Hardware, Spoofed Video Input and Commercial Proxy Infrastructure on a Company Issued Endpoint

Source report →

Huntress investigated a suspected North Korean remote worker who had been hired into a legitimate remote role using a stolen or fabricated identity. The company-managed endpoint was moved through a travel-router and residential-network setup before settling on a wired connection, consistent with a workstation being staged for persistent remote operation. Forensic review subsequently identified a USB-to-UART serial console adapter, an IP-based keyboard, video, and mouse appliance, and a USB video capture device connected to the host. The KVM appliance provided remote keyboard, mouse, and screen access without relying on software installed on the endpoint, while the capture device appeared to conferencing software as a webcam capable of supplying an externally sourced video feed.

Network tradecraft relied on commercial anonymisation services rather than attacker-built infrastructure. Astrill VPN and IPRoyal Proxy were used to present exit addresses consistent with the worker’s claimed identity and location. The operator verified the public-facing address through an IP lookup service shortly before joining a scheduled conference call, and validated microphone and webcam functionality through browser-based test sites. Account activity was concentrated around midnight UTC, aligning more closely with East Asian working hours than with the schedule expected for the claimed role. Additional suspicious activity included a self-service password reset followed closely by a search for the Group Policy Editor, and the entry of personal webmail using naming conventions previously associated with documented North Korean remote-worker cases.

Supporting tradecraft relied heavily on free third-party services rather than dedicated infrastructure. Encrypted peer-to-peer transfer and general file-sharing platforms were used to move identity documents, while a public code-sharing service hosted recurring conference invitations containing embedded passwords. Browser extensions for tab recording, translation, and pronunciation assistance further supported day-to-day operation of the claimed persona. The onboarding documents themselves contained several inconsistencies, including a device time offset three hours ahead of UTC, images captured with the same handset across multiple documents, and creation timestamps only minutes apart. Other artifacts included digitally overlaid signatures, repeated character substitutions, and utility bills referencing a United States provider inside documents written in another language, collectively undermining the authenticity of the identity presented during onboarding.

Detections (6)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • PiKVM Remote Access Hardware Connected
  • KVM over IP and Video Capture Devices Connected to Same Host
  • Virtual Camera Registered as a System Video Input Device
  • Peer to Peer WebRTC Media Relay Service Contacted
  • Multiple Corporate Endpoints Egressing From One Non Corporate Address