Unlock the DPRK IT
Worker Playbook

Developed by Erin Whitmore, Managing Director of Executive Risk and Strategic Intelligence at CYPFER and former CIA Case Officer.

Remote IT hiring is no longer just a talent strategy. Instead, it is a security boundary. State-backed actors have used remote employment models to gain access to corporate environments, often through candidates who appear highly qualified. 
 
The DPRK IT Worker Playbook replaces informal interview instincts with defined validation and escalation controls. It helps organizations identify elevated risk before credentials are issued, systems are accessed, or intellectual property is exposed. 
 
While not designed to be HR guidance, this is a structured detection and escalation framework for use by technical and non-technical interviewers alike. 

What You Gain?

Structured Interview Protocols

  • Practical identity validation, capability verification, environmental consistency checks, and authenticity testing that traditional interviews miss. 

Pre-Onboarding Safeguards

  • Clear controls implemented before access is granted, including device validation and authentication integrity considerations. 

Risk Scoring & Escalation Standards

  • Defined red flags, documentation guidance, and escalation thresholds that replace instinct with structured decision-making​.

U.S. government warnings are explicit: DPRK IT workers are targeting Western companies as a revenue and access stream. This is deliberate state tradecraft. If you are not running structured validation on remote hires, you are authorizing adversary access to your code, capital, and credentials.

Why It Matters

Indicators associated with illicit remote worker schemes are often invisible in standard screening processes. Without structured controls, organizations increase their exposure to: 

  • Intellectual property loss 
  • Persistent insider access 
  • Operational disruption 
  • Sanctions and compliance risk 
  • Reputational harm 

 
Once access is granted, you are managing exposure. Prevention happens before the risk is ever introduced into your environment. 

The DPRK IT Worker Playbook is available by request. 
 
If your organization hires remote technical talent, your interview process should reflect today’s threat environment. 

Request your copy and strengthen your hiring controls before credentials are issued.

Unlock the DPRK

Having technical issues? Click here to get help.

Meet our Speaker

Evgueni Erchov

Associate Vice President, Adversary Intelligence & Strategy

Evgueni Erchov is the Associate Vice President, Adversary Intelligence & Strategy at CYPFER, where he leads CYPFER’s global intelligence team in uncovering emerging threats, analyzing adversary tactics, and delivering actionable intelligence to strengthen cybersecurity resilience.

With over 25 years of experience, he specializes in cyber threat intelligence, ransomware defense, cybercrime investigations, and blockchain analytics. His expertise helps organizations stay ahead of emerging threats and implement best practices to mitigate cyber risks.

His background spans both federal and private sectors, where he has worked in IT security, application development, digital forensics, and cyber operations. He holds several industry-recognized certifications, including CISSP, DCITA Digital Media Collector (DMC) and Digital Forensics Examiner (DFE), ITILv3, U.S. Army Cyber Operations Planner (ACOP), and Project Management Professional (PMP).

Evgueni earned his Bachelor of Science in Information Systems and Technologies from the Moscow Engineering Physics Institute and an MBA with a concentration in IT Management from George Washington University. He is currently pursuing a Ph.D. in Data Mining and Artificial Intelligence at George Mason University.

At CYPFER, Evgueni plays a critical role in ensuring clients stay ahead of ransomware and evolving cyber threats. His leadership in threat intelligence, real-time research, and advanced defense strategies directly contributes to CYPFER’s recovery-first approach. By analyzing and anticipating cyber risks, he helps organizations minimize downtime, secure critical assets, and achieve Cyber Certainty™, ensuring resilience in the face of today’s ever-changing threat landscape.