Unlock the DPRK IT
Worker Playbook

Developed by Erin Whitmore, Managing Director of Executive Risk and Strategic Intelligence at CYPFER and former CIA Case Officer.

Remote IT hiring is no longer just a talent strategy. Instead, it is a security boundary. State-backed actors have used remote employment models to gain access to corporate environments, often through candidates who appear highly qualified. 
 
The DPRK IT Worker Playbook replaces informal interview instincts with defined validation and escalation controls. It helps organizations identify elevated risk before credentials are issued, systems are accessed, or intellectual property is exposed. 
 
While not designed to be HR guidance, this is a structured detection and escalation framework for use by technical and non-technical interviewers alike. 

What You Gain?

Structured Interview Protocols

  • Practical identity validation, capability verification, environmental consistency checks, and authenticity testing that traditional interviews miss. 

Pre-Onboarding Safeguards

  • Clear controls implemented before access is granted, including device validation and authentication integrity considerations. 

Risk Scoring & Escalation Standards

  • Defined red flags, documentation guidance, and escalation thresholds that replace instinct with structured decision-making​.

U.S. government warnings are explicit: DPRK IT workers are targeting Western companies as a revenue and access stream. This is deliberate state tradecraft. If you are not running structured validation on remote hires, you are authorizing adversary access to your code, capital, and credentials.

Why It Matters

Indicators associated with illicit remote worker schemes are often invisible in standard screening processes. Without structured controls, organizations increase their exposure to: 

  • Intellectual property loss 
  • Persistent insider access 
  • Operational disruption 
  • Sanctions and compliance risk 
  • Reputational harm 

 
Once access is granted, you are managing exposure. Prevention happens before the risk is ever introduced into your environment. 

The DPRK IT Worker Playbook is available by request. 
 
If your organization hires remote technical talent, your interview process should reflect today’s threat environment. 

Request your copy and strengthen your hiring controls before credentials are issued.

Unlock the DPRK

Having technical issues? Click here to get help.

Meet our Speaker

Evgueni Erchov

Associate Vice President, Adversary Intelligence & Strategy

Evgueni Erchov is the Associate Vice President, Adversary Intelligence & Strategy at CYPFER, where he leads CYPFER’s global intelligence team in uncovering emerging threats, analyzing adversary tactics, and delivering actionable intelligence to strengthen cybersecurity resilience.

Fort de 25 ans d'expérience, il se spécialise dans le renseignement sur les menaces cyber, la défense contre le ransomware, les enquêtes sur la criminalité informatique et l’analyse blockchain. Son expertise aide les organisations à garder une longueur d'avance sur les menaces émergentes et à implémenter les bonnes pratiques pour atténuer les risques.

L'expérience d'Evgueni couvre à la fois le secteur public fédéral et le secteur privé, où il a travaillé dans les domaines de la sécurité informatique, du développement d'applications, de la forensique numérique et des opérations cyber. Il est titulaire de plusieurs certifications reconnues dans le secteur, telles que CISSP, Digital Media Collector (DMC) et Digital Forensics Examiner (DFE) de la DCITA, ITILv3, Cyber Operations Planner de l'armée des États-Unis (ACOP) et Project Management Professional (PMP).

Evgueni a un Bachelor of science en systèmes et technologies d'information de l'Institut de génie physique de Moscou et un MBA avec spécialisation en gestion informatique de l'université George Washington. Il fait actuellement une thèse de doctorat en data mining et intelligence artificielle à l'université George Mason.

At CYPFER, Evgueni plays a critical role in ensuring clients stay ahead of ransomware and evolving cyber threats. His leadership in threat intelligence, real-time research, and advanced defense strategies directly contributes to CYPFER’s recovery-first approach. By analyzing and anticipating cyber risks, he helps organizations minimize downtime, secure critical assets, and achieve Cyber Certainty™, ensuring resilience in the face of today’s ever-changing threat landscape.