Appendix C: References and Further Reading¶
The sources below are cited throughout this handbook and are grouped here by type for quick lookup.
Standards and Frameworks¶
- NIST SP 800-207, Zero Trust Architecture
- NIST SP 800-46 Rev. 2, Guide to Enterprise Telework, Remote Access, and BYOD Security
- NIST Special Publication 800-53 Revision 5
- NIST SP 800-61 Revision 3, "Incident Response Recommendations and Considerations for Cybersecurity Risk Management," April 2025
- NIST Special Publication 800-63A, Digital Identity Guidelines
- NIST Special Publication 800-63 Digital Identity Guidelines project page
- EUR-Lex consolidated text of the GDPR
- GDPR Article 10
- MITRE ATT&CK
- MITRE ATT&CK Group G0032
- MITRE ATT&CK Group G0082
- AADAPT cybersecurity framework for cryptocurrency
- AADAPT GitHub repository
- MITRE news release introducing the AADAPT framework
- CISA, "Insider Threat Mitigation Guide"
- CISA, "Assembling a Multi-Disciplinary Insider Threat Management Team"
- NCSC Insider Threat Program Maturity Framework
- National Insider Threat Task Force (NITTF)
- SANS Institute Security Policy Project
- OFAC North Korea Sanctions Program
- UN Security Council 1718 Sanctions Committee resolutions
Incidents and Case Studies¶
- KnowBe4, "How a North Korean Fake IT Worker Tried to Infiltrate Us," July 2024
- KnowBe4, North Korean fake IT worker FAQ
- KnowBe4 blog
- Kraken, "How We Identified a North Korean Hacker"
- SecurityWeek, "KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware"
- The Record, Christina Chapman "laptop farm" case
- BleepingComputer, US woman sentenced for running a laptop farm for North Koreans
- DOJ, "Justice Department Announces Coordinated Nationwide Actions to Combat North Korean Remote IT Worker Fraud"
- DOJ, multi-defendant indictment covering 64 U.S. companies
- Treasury OFAC designations of July 2024 on DPRK IT worker facilitator networks (GlobalSecurity.org)
- ZachXBT
Tools and Documentation¶
- Cybersecurity and Infrastructure Security Agency (CISA)
- CISA Advisory AA21-048A
- CISA/FBI/Treasury Advisory AA22-108A
- Internet Crime Complaint Center (IC3)
- FBI IC3 PSA I-051622-PSA, May 2022
- FBI/IC3 follow-up guidance, PSA231018
- IC3 PSA250123, North Korean IT Workers Conducting Data Extortion
- IC3 PSA250723-4, North Korean IT Worker Threats to U.S. Businesses
- State Department, "Guidance on the Democratic People's Republic of Korea Information Technology Workers," May 2022
- State Department, "Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers," 2026
- May 2022 State/Treasury/FBI joint advisory (mirrored copy)
- May 2022 US Treasury, State Department, and FBI advisory (OFAC document)
- OFAC sanctions list search tool
- Department of Justice press releases
- US Treasury press releases
- Rewards for Justice DPRK IT worker program
- Google Cloud/Mandiant, "Staying a Step Ahead: Mitigating the DPRK IT Worker Threat"
- Google Threat Intelligence Group, DPRK IT workers expanding scope and scale, 2025
- Google Cloud/Mandiant, M-Trends 2026
- CrowdStrike adversary profile: Famous Chollima
- CrowdStrike Global Threat Report
- CrowdStrike 2025 Global Threat Report findings blog
- Unit 42, "Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers," 2024
- Elastic Security Labs
- Microsoft Threat Intelligence, "Jasper Sleet: North Korean remote IT workers' evolving tactics to infiltrate organizations"
- Spur research on remote worker fraud detection
- IPinfo, impossible travel detection and IP data accuracy
- Center for Development of Security Excellence (CDSE)
Further Reading¶
- ASIS International, "Recruitment Red Flags: Spotting DPRK IT Remote Workers"
- FTC guidance on using consumer reports for employment decisions
- Skadden analysis of North Korean remote IT worker risk, June 2026
- Toku's employer vs. contractor misclassification risk analysis in crypto
- National Student Clearinghouse's DegreeVerify