Unlock the DPRK IT
Worker Playbook

Developed by Erin Whitmore, Managing Director of Executive Risk and Strategic Intelligence at CYPFER and former CIA Case Officer.

Remote IT hiring is no longer just a talent strategy. Instead, it is a security boundary. State-backed actors have used remote employment models to gain access to corporate environments, often through candidates who appear highly qualified. 
 
The DPRK IT Worker Playbook replaces informal interview instincts with defined validation and escalation controls. It helps organizations identify elevated risk before credentials are issued, systems are accessed, or intellectual property is exposed. 
 
While not designed to be HR guidance, this is a structured detection and escalation framework for use by technical and non-technical interviewers alike. 

What You Gain?

Structured Interview Protocols

  • Practical identity validation, capability verification, environmental consistency checks, and authenticity testing that traditional interviews miss. 

Pre-Onboarding Safeguards

  • Clear controls implemented before access is granted, including device validation and authentication integrity considerations. 

Risk Scoring & Escalation Standards

  • Defined red flags, documentation guidance, and escalation thresholds that replace instinct with structured decision-making​.

U.S. government warnings are explicit: DPRK IT workers are targeting Western companies as a revenue and access stream. This is deliberate state tradecraft. If you are not running structured validation on remote hires, you are authorizing adversary access to your code, capital, and credentials.

Why It Matters

Indicators associated with illicit remote worker schemes are often invisible in standard screening processes. Without structured controls, organizations increase their exposure to: 

  • Intellectual property loss 
  • Persistent insider access 
  • Operational disruption 
  • Sanctions and compliance risk 
  • Reputational harm 

 
Once access is granted, you are managing exposure. Prevention happens before the risk is ever introduced into your environment. 

The DPRK IT Worker Playbook is available by request. 
 
If your organization hires remote technical talent, your interview process should reflect today’s threat environment. 

Request your copy and strengthen your hiring controls before credentials are issued.

Unlock the DPRK

Having technical issues? Click here to get help.

Meet our Speaker

Evgueni Erchov

Associate Vice President, Adversary Intelligence & Strategy

Evgueni Erchov is the Associate Vice President, Adversary Intelligence & Strategy at CYPFER, where he leads CYPFER’s global intelligence team in uncovering emerging threats, analyzing adversary tactics, and delivering actionable intelligence to strengthen cybersecurity resilience.

Hij heeft ruim 25 jaar ervaring en is gespecialiseerd in cyber threat intelligence, bescherming tegen ransomware, cybercrimeonderzoeken en blockchainanalyse. Met zijn expertise helpt hij organisaties om nieuwe bedreigingen het hoofd te bieden en best practices te implementeren om cyberrisico's te verkleinen.

Eerder werkte hij zowel voor de overheid als in het bedrijfsleven, in onder meer IT-beveiliging, app-development, digitaal forensisch onderzoek en cyberoperaties. Hij heeft verschillende certificeringen, waaronder CISSP, DCITA Digital Media Collector (DMC) en Digital Forensics Examiner (DFE), ITILv3, U.S. Army Cyber Operations Planner (ACOP) en Project Management Professional (PMP).

Evgueni heeft een Bachelor of Science in Information Systems and Technologies van de Nationale Nucleaire-onderzoeksuniversiteit in Moskou, en een MBA in IT Management van de George Washington-universiteit in Washington. Momenteel doet hij een PhD in Data Mining & Artificial Intelligence bij de George Mason-universiteit in Virginia (VS).

At CYPFER, Evgueni plays a critical role in ensuring clients stay ahead of ransomware and evolving cyber threats. His leadership in threat intelligence, real-time research, and advanced defense strategies directly contributes to CYPFER’s recovery-first approach. By analyzing and anticipating cyber risks, he helps organizations minimize downtime, secure critical assets, and achieve Cyber Certainty™, ensuring resilience in the face of today’s ever-changing threat landscape.