---
title: DPRK IT Workers Tied to FAMOUS CHOLLIMA Use Astrill VPN and IPRoyal Proxy - Capstone Technologies Group
description: DPRK workers use Astrill VPN and IPRoyal Proxy to hide remote work locations. Huntress identified five suspected North Korean nationals in 2026 across IT,…
canonical_url: https://captechgroup.com/threat-intelligence-center/dprk-it-workers-tied-to-famous-chollima-use-astril-3b770c
language: en-GB
date: 2026-08-28T18:10:31Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center/dprk-it-workers-tied-to-famous-chollima-use-astril-3b770c. Schema.org structured data included at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
markdown-tokens: 4599
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center/dprk-it-workers-tied-to-famous-chollima-use-astril-3b770c. Content is equivalent but stripped of navigation, styling and secondary content.
> **Structured data** as JSON-LD may be found at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


North Korean nationals apply for remote positions at Western companies using stolen or fabricated identities, get hired through normal recruiting channels, and funnel their salaries back to the DPRK regime to generate revenue while evading international sanctions. The activity cluster is tracked publicly as **FAMOUS CHOLLIMA**, and Huntress has been pulled into several of these cases inside partner environments. Public reporting also documents these workers exfiltrating data, deploying malware, or extorting employers once their cover is blown. The activity described here was documented by [Huntress](https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation "Source: Huntress").

What makes this different from a conventional intrusion is that nobody breaks in. There is no exploited CVE, no phished credential, no gap in your perimeter. Your HR team issues the offer letter, your IT team ships the laptop, and your identity provider creates the account with full, legitimate permissions attached.

In many cases the person on the other end genuinely performs the work they were hired to do, which removes the performance signal that would normally prompt a manager to ask questions. That means the detection burden shifts to hiring, identity verification, and behavioral telemetry instead of endpoint alerts.

> So far in 2026, Huntress has supported investigations where a total of five individuals were identified as likely DPRK workers employed in partner organisations.

Those five were spread across IT, sales and marketing, and the medical profession, so the assumption that this is only a developer-hiring problem no longer holds. Three of them presented identification documents that investigators later assessed as fraudulent. A fourth used a profile photo lifted from a legitimate GitHub account with the face digitally altered.

Hiding the worker's real location is the operational core of the scheme, and it relies on commodity infrastructure. Huntress observed repeated authentications through **Astrill VPN** nodes, traffic routed via **IPRoyal Proxy**, and connections tied to WorkTitans B.V., a bulletproof-hosting operation reportedly raided by the Netherlands FIOD. To your sign-in logs, the employee looks like they are sitting where they said they were.

## Astrill VPN, IPRoyal Proxy and the Remote Access Toolkit

The three suspected workers at the Australian healthcare partner authenticated repeatedly through **Astrill VPN** nodes, a service publicly documented in earlier remote IT worker campaigns. Huntress also tied those same accounts to **IPRoyal Proxy**, a commercial service that resells routable IP addresses, and to **WorkTitans B.V.**, a bulletproof hosting operation reportedly raided by the Dutch Fiscal Information and Investigation Service. Layering a commercial VPN over a residential proxy over bulletproof infrastructure is what made the pattern stand out, since ordinary staff do not chain three anonymisation layers to check email.

Infrastructure alone proves nothing, so the investigation profiled six months of Unified Audit Logs across Exchange, SharePoint and sign-in workloads. Across all three accounts, less than 50 percent of activity fell inside expected business hours, and peak activity landed at exactly midnight UTC. That timestamp overlaps working hours in both Australia and China, which is convenient cover, and it also corresponds to 9am in North Korea.

The financial services case shows the access layer these workers actually use on a company laptop. Instead of installing AnyDesk or TeamViewer, which would surface in software inventory, the operator attached a **PiKVM V4 Mini**, a Raspberry Pi based KVM over IP appliance. It grants full keyboard, video and mouse control through a browser at the hardware level, before the operating system boots and without any agent to detect. For your asset management program, this means a laptop can be fully driven by a third party while the endpoint build looks untouched.

The registry evidence was specific. `HKLM\SYSTEM\CurrentControlSet\Enum\USB` recorded `VID_1D6B&PID_0104&MI_04` with a FriendlyName of *PiKVM Composite Device* and a first install date of 2026-07-31 21:58:06Z. Windows Security Event ID 6416 logged the same connection, and the Realtek Audio Universal Service recorded Windows switching audio output to the PiKVM.

Forensics reconstructed how the laptop reached the operator. On 2026-07-31 at 04:16 UTC the machine connected to a GL.iNet travel router, hours after it had apparently already been delivered. By 16:51 UTC it was on a BGW320-500 residential router behind a wireless network named "Pickle\_Rick". At 20:14 UTC the user completed an Entra self-service password reset and searched for the Windows 10 group policy editor. At 21:10 UTC a USB-to-UART serial console adapter appeared, at 21:12 UTC the PiKVM, and at 21:26 UTC the host moved to ethernet and never touched wireless again, consistent with becoming a fixed rack asset in a laptop farm.

Video presence was handled with hardware too. A **Guermok USB3 Video** capture card (`VID_345F&PID_2130&MI_00`, installed 2026-08-04) registered as a webcam, letting any streamed video feed Zoom as camera input. Around it sit the supporting artifacts:

- Searches for online audio tests and visits to `mictests[.]com`, `webcammictest[.]com` and `onlinemictest[.]com`
- A visit to `ip[.]me` minutes before joining a Zoom call, checking what location the meeting would show
- A file uploaded by an unknown party to SendGB and downloaded minutes later into `C:\asset`, which reverse image search matched to an altered photo from a legitimate GitHub profile
- Chrome extensions for tab video and audio recording, Zoom chat export, English translation and pronunciation assistance
- Recurring Zoom invites with embedded passwords published to Codeshare, plus VDO.Ninja push and screenshare URLs recovered from Chrome cache

Identity documents followed the same production line. Two passports were issued in Shenzhen one day apart, two resident identity cards carried identical validity periods from Songgang Police Station, both individuals listed the same street, and every photo carried a UTC +03:00 device offset and an iPhone 15 Pro Max back triple camera signature.

## Business Consequences: Payroll Fraud, Sanctions Exposure and Data Theft

Huntress identified five likely DPRK workers inside partner organisations so far in 2026, employed in IT, sales and marketing, and the medical profession. That role spread matters for how you calculate exposure, because the access attached to a marketing hire looks nothing like the access attached to a clinical or infrastructure role. Whatever the position, the first loss is straightforward: every pay cycle before detection is salary, benefits, and equipment sent to someone who does not exist as described.

Equipment is part of that figure. In the financial services case, a corporate laptop was shipped, moved again through a travel router, and ended up as a fixed ethernet-connected asset at a residential address, most likely a laptop farm. If that describes any of your remote hires, you have written off the hardware and you are funding its hosting.

The second harm is regulatory. Wages paid to these workers are routed back to the North Korean regime, which is the entire point of the scheme and the reason it operates around international sanctions. Sanctions exposure attaches to the payment, and being deceived during hiring does not automatically resolve your position with regulators. In the August financial services case, altered identity documents appear to have been used to complete an I-9 Employment Eligibility Verification form, so your HR file now contains a federal employment record built on falsified evidence.

There is a downstream complication if the person came through a staffing firm or contractor. The vetting failure sits with the third party, but the network access, the payroll relationship in many arrangements, and the notification duty sit with you. The same fraudulent document package can be recycled across several of that agency's clients, so one confirmed placement is worth raising with the supplier rather than treating as an isolated hire.

The third harm is security, and it is the one that outlasts the employment. Public reporting cited by Huntress documents these workers exfiltrating data, deploying malware, and extorting their employers once discovered. Termination is the trigger. The moment you remove access from someone who has spent weeks or months copying repositories, customer records, or credential stores, you are negotiating with an insider who already holds the material.

Think about what the specific role touched. A worker in a medical setting sits near patient data. A sales and marketing account reaches CRM exports, pipeline data, and customer contact lists. An IT hire reaches source code, credential vaults, and administrative tooling. In one case the worker completed an Entra self-service password reset and then searched for the Windows group policy editor within hours of the laptop reaching a residential address, which tells you how quickly account control and local configuration become targets.

Reputation lands last but persists longest. If your customers require supply chain assurances, personnel screening attestations, or answers to third-party risk questionnaires, a confirmed fraudulent hire changes what you can honestly sign. Regulated clients in finance and healthcare frequently require notification of personnel-related security events, and those conversations tend to reopen contract terms.

One useful detail for how these cases actually surface: the financial services partner confirmed their own suspicions after the employee refused to show the room they were in and avoided appearing on camera. Detection here often begins with a manager noticing behaviour, and the cost of that delay is measured in pay cycles and accumulated access.

## Screening and Detection Controls for Remote Hiring

Start with the endpoint sweep, because it is the fastest check you can run against staff who are already on payroll. Query `HKLM\SYSTEM\CurrentControlSet\Enum\USB` across corporate laptops for `FriendlyName` values of `PiKVM Composite Device` and `Guermok USB3 Video`, and build an alert on Windows Security Event ID 6416 where the device description contains PiKVM or Guermok. A KVM-over-IP board gives someone hardware-level control of a laptop before Windows even loads, so no remote access software has to be installed and no software inventory will show it.

Run the identity side in parallel. Pull six months of sign-in data for every remote worker and flag authentications from Astrill VPN nodes, IPRoyal Proxy ranges, and WorkTitans B.V. infrastructure, then baseline each employee's normal working window against their claimed local timezone. In environments Capstone manages, Adlumin ITDR handles that authentication baselining, surfacing accounts whose peak activity sits outside the hours their stated location would predict.

While your security team works the logs, have HR run its own duplicate check on the same population:

- Payroll bank accounts shared across two or more employee records
- Home addresses that match, sit on the same street, or repeat across recent hires
- VOIP numbers listed as personal contact numbers
- Identity documents uploaded during onboarding that share a naming convention between separate individuals

Pull the EXIF metadata on those onboarding documents. Look at the device time offset, the camera model string, and the original creation timestamps. Passport and ID photos for two unrelated hires taken minutes apart on the same phone model is the kind of overlap that only appears when one person photographed both.

Over the next hiring cycle, tighten the interview itself. Require cameras on for every round, watch for reluctance to show the room or move the camera, and verify the government ID against a live video check rather than a scanned upload. Requiring notarised identification documents for new hires raises the cost of a digitally altered face composited onto an otherwise valid document, which is what defeated visual inspection in the sales and marketing case.

Ship equipment only to an address you have independently verified, and require the recipient to unbox the laptop on camera. Then watch what the device connects to during its first week. A travel router in the connection history after delivery, a USB-to-UART serial console adapter, or a switch to permanent ethernet with no further wireless connections all suggest the machine has been re-shipped or racked somewhere other than the address on file.

Add browser and web telemetry to your detection set. The recurring signals across these cases were VDO.Ninja screenshare sessions, Toffeeshare peer-to-peer transfers of identity documents, recurring Zoom invites with embedded passwords posted to Codeshare, Chrome extensions for tab recording, translation, pronunciation, and Zoom chat export, plus repeated visits to microphone and webcam test sites before meetings. Any one of those is defensible on its own. Three or four on the same host during a probation period is worth a conversation.

Longer term, apply the same identity verification standard to staffing agencies and contract firms that you apply to direct hires, and hold source code, production systems, and payment infrastructure back until probation completes. Build a written escalation path so an HR concern about a camera-shy new starter reaches your security team as a case, not a hallway comment. Standard background checks, online searches, and direct verification of employment history remain the cheapest place to catch this.

## What to Do If You Suspect a Fraudulent Hire

Suspicion is not confirmation, and the sequence you follow determines whether you end up with an evidence package or a hunch. Preserve the endpoint image and export the relevant identity and cloud logs before you touch the account, because terminating access first often triggers device wipes, mailbox purges, and the loss of browser artifacts. In the financial services case, the useful material sat in browsing history, cache, and a folder the user created at the root of the drive at `C:\asset`, all of which lives on a machine you may never physically recover.

When you do cut access, cut it all at once. Revoke passwords, refresh tokens, session cookies, VPN certificates, and any SaaS or repository access in a single coordinated action, since a staggered shutdown leaves a working path open while the individual is watching the account close.

Treat every system, repository, and shared drive the person touched as compromised until you have reviewed it. These are legitimately onboarded staff with legitimate permissions, so the question is not whether access happened but what was copied or changed while it did.

Bring in legal counsel before you make any statement, internal or external. Paying wages to a sanctioned regime carries reporting obligations that vary by jurisdiction, and counsel should guide your referral to the FBI and IC3 as well as the wording of any notice to clients or regulators.

The partner in that August investigation confirmed their own suspicions after the worker refused to show the room they were in and avoided appearing on camera. Verification of remote hires belongs to HR and security jointly, reviewed like any other access decision.

<!-- AI:SCHEMA: Schema.org description of canonical page in JSON-LD format -->
<!-- AI:SCHEMA:BEGIN format=jsonld scope=page -->

```json
{
    "@context": "http:\/\/schema.org",
    "@graph": [
        {
            "@type": "Article",
            "author": {
                "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
            },
            "dateModified": "2026-08-28T18:10:31Z",
            "datePublished": "2026-08-28T18:10:31Z",
            "description": "DPRK workers use Astrill VPN and IPRoyal Proxy to hide remote work locations. Huntress identified five suspected North Korean nationals in 2026 across IT,…",
            "headline": "DPRK IT Workers Tied to FAMOUS CHOLLIMA Use Astrill VPN and IPRoyal Proxy",
            "image": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "inLanguage": "en-GB",
            "mainEntityOfPage": {
                "@type": "WebPage",
                "url": "https:\/\/captechgroup.com\/threat-intelligence-center\/dprk-it-workers-tied-to-famous-chollima-use-astril-3b770c"
            },
            "publisher": {
                "@id": "https:\/\/captechgroup.com\/#defaultPublisher"
            },
            "url": "https:\/\/captechgroup.com\/threat-intelligence-center\/dprk-it-workers-tied-to-famous-chollima-use-astril-3b770c"
        },
        {
            "@type": "Person",
            "name": "Brian",
            "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultLogo",
            "@type": "ImageObject",
            "url": "https:\/\/captechgroup.com\/images\/hotlink-ok\/logo-light.jpg",
            "width": 1300,
            "height": 300
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPublisher",
            "@type": "Organization",
            "url": "https:\/\/captechgroup.com\/",
            "logo": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "name": "Capstone Technologies Group",
            "location": {
                "@id": "https:\/\/captechgroup.com\/#defaultPlace"
            }
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPlace",
            "@type": "Place",
            "address": {
                "@id": "https:\/\/captechgroup.com\/#defaultAddress"
            },
            "openingHoursSpecification": [
                {
                    "@type": "OpeningHoursSpecification",
                    "dayOfWeek": [
                        "monday",
                        "tuesday",
                        "wednesday",
                        "thursday",
                        "friday"
                    ],
                    "opens": "09:00",
                    "closes": "17:00"
                }
            ]
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultAddress",
            "@type": "PostalAddress",
            "addressLocality": "Springfield",
            "addressRegion": "Ohio",
            "postalCode": "45504-1583",
            "streetAddress": "2071 N Bechtle Ave, Box 143",
            "addressCountry": "US"
        }
    ]
}
```

<!-- AI:SCHEMA:END -->

