Analysis of suspected DPRK IT worker activity highlights a recurring set of tools, including Astrill VPN and IPRoyal Proxy, used in connection with the threat actor tracked as FAMOUS CHOLLIMA. Because these operators present themselves as legitimate remote technical staff, the infrastructure they use becomes one of the few durable signals available.