Unlock the DPRK IT
Worker Playbook

Developed by Erin Whitmore, Managing Director of Executive Risk and Strategic Intelligence at CYPFER and former CIA Case Officer.

Remote IT hiring is no longer just a talent strategy. Instead, it is a security boundary. State-backed actors have used remote employment models to gain access to corporate environments, often through candidates who appear highly qualified. 
 
The DPRK IT Worker Playbook replaces informal interview instincts with defined validation and escalation controls. It helps organizations identify elevated risk before credentials are issued, systems are accessed, or intellectual property is exposed. 
 
While not designed to be HR guidance, this is a structured detection and escalation framework for use by technical and non-technical interviewers alike. 

What You Gain?

Structured Interview Protocols

  • Practical identity validation, capability verification, environmental consistency checks, and authenticity testing that traditional interviews miss. 

Pre-Onboarding Safeguards

  • Clear controls implemented before access is granted, including device validation and authentication integrity considerations. 

Risk Scoring & Escalation Standards

  • Defined red flags, documentation guidance, and escalation thresholds that replace instinct with structured decision-making​.

U.S. government warnings are explicit: DPRK IT workers are targeting Western companies as a revenue and access stream. This is deliberate state tradecraft. If you are not running structured validation on remote hires, you are authorizing adversary access to your code, capital, and credentials.

Why It Matters

Indicators associated with illicit remote worker schemes are often invisible in standard screening processes. Without structured controls, organizations increase their exposure to: 

  • Intellectual property loss 
  • Persistent insider access 
  • Operational disruption 
  • Sanctions and compliance risk 
  • Reputational harm 

 
Once access is granted, you are managing exposure. Prevention happens before the risk is ever introduced into your environment. 

The DPRK IT Worker Playbook is available by request. 
 
If your organization hires remote technical talent, your interview process should reflect today’s threat environment. 

Request your copy and strengthen your hiring controls before credentials are issued.

Unlock the DPRK

Having technical issues? Click here to get help.

Meet our Speaker

Evgueni Erchov

Associate Vice President, Adversary Intelligence & Strategy

Evgueni Erchov is the Associate Vice President, Adversary Intelligence & Strategy at CYPFER, where he leads CYPFER’s global intelligence team in uncovering emerging threats, analyzing adversary tactics, and delivering actionable intelligence to strengthen cybersecurity resilience.

Er bringt über 25 Jahre Erfahrung mit und hat sich auf Cyber-Threat-Intelligence, Ransomware-Verteidigung, Cyberkriminalität-Untersuchungen und Blockchain-Analysen spezialisiert. Sein Fachwissen hilft Organisationen dabei, sich auf neue Bedrohungen vorzubereiten und Cyberrisiken durch die Anwendung bewährter Praktiken zu minimieren.

Er hat zuvor sowohl in bundesstaatlichen als auch privaten Sektoren in den Bereichen IT-Sicherheit, Anwendungsentwicklung, digitale Forensik und Cyber-Operationen gearbeitet. Darüber hinaus besitzt er mehrere in der Branche anerkannte Zertifizierungen, darunter CISSP, DCITA Digital Media Collector (DMC) und Digital Forensics Examiner (DFE), ITILv3, U.S. Army Cyber Operations Planner (ACOP), und Project Management Professional (PMP).

Evgueni hat einen Bachelor of Science in Informationssysteme und -technologien vom Moskauer Institut für Technische Physik und einen MBA mit Schwerpunkt IT-Management von der George Washington University. Er promoviert momentan an der George Mason University in Data-Mining und Künstliche Intelligenz.

At CYPFER, Evgueni plays a critical role in ensuring clients stay ahead of ransomware and evolving cyber threats. His leadership in threat intelligence, real-time research, and advanced defense strategies directly contributes to CYPFER’s recovery-first approach. By analyzing and anticipating cyber risks, he helps organizations minimize downtime, secure critical assets, and achieve Cyber Certainty™, ensuring resilience in the face of today’s ever-changing threat landscape.