Cybersecurity experts have raised alarms over a growing threat posed by North Korean IT workers infiltrating companies across Europe, with a new report revealing an alarming rise in these espionage activities. These agents, often referred to as “IT warriors,” are using deceptive tactics to pose as legitimate remote IT workers in order to infiltrate organizations in various sectors, including defense and government.
According to a report from the Google Threat Intelligence Group (GTIG), the United States has long been the primary target for these operatives. However, recent findings suggest that their activities have now expanded across Europe, marking a significant shift in the scale and scope of their operations. Researchers have warned that North Korean agents are becoming a global threat, with a particular focus on European targets.
One particularly concerning case highlighted in the report involves a North Korean IT worker who operated under at least 12 different personas across both Europe and the US. This individual sought employment with multiple organizations, fabricating references, building rapport with recruiters, and leveraging fake identities to enhance their credibility. The report points out that such tactics were notably prevalent in countries like Germany and Portugal, where these agents targeted job opportunities in sensitive sectors such as defense.
The IT workers’ portfolios appear to be vast and varied. In the UK, for example, the operatives were involved in a wide range of technical projects, including web development, bot development, content management systems, and blockchain technology. This highlights the extensive technical expertise these workers possess, making them highly capable of infiltrating various sectors, from software development to cybersecurity.
In order to conceal their true identities, these North Korean agents have been found to falsely claim nationalities from various countries, including Italy, Japan, Singapore, Vietnam, and even Ukraine. They often rely on online platforms such as Upwork, Freelancer, and Telegram to secure positions, which further complicates efforts to track their activities.
Researchers also noted that the operatives are being aided by facilitators in several European countries, who help them bypass identity verification and fraudulently receive payments. This reveals a complex support network that enables the espionage campaign to thrive.
The report also highlighted a concerning vulnerability among companies that operate a “bring your own device” (BYOD) policy. Experts warned that personal devices used under BYOD policies often lack the traditional security and monitoring tools found on corporate-issued laptops. This leaves companies susceptible to undetected threats, with the possibility of espionage or data theft going unnoticed.
As North Korean IT workers continue to employ more sophisticated and aggressive tactics, cybersecurity experts fear that these operations may escalate. With a rapidly expanding infrastructure supporting these spies, the risk of corporate espionage, data breaches, and other cyber threats grows significantly, especially in Europe, which has now become a central focus for these operatives.

