Remote Workforce Assurance · Monadnock Cyber — Intelligence and Analysis
North Korean operatives hold remote engineering jobs at US companies under stolen identities. They pass background checks, do the work, and send the salary to Pyongyang. Remote Workforce Assurance finds them.
The problem
The scheme runs through Americans who host company laptops in their homes. Every location check you run comes back clean, because the device really is where it should be.
A managed laptop on a US residential connection, logging in on schedule, shipping code that works.
An operator in China, Russia, or Southeast Asia driving that laptop through a remote-control box plugged into it, earning a salary for a sanctioned weapons program.
Collection
No single signal proves anything. The pattern does. We combine five families of evidence from your endpoints, identity logs, and hiring records.
Personas with no history: no breach exposure, reused profile photos, employers that do not exist.
Unapproved remote-access tools, offshore VPN clients, and the USB signatures of remote-control hardware.
Connections through infrastructure tied to known operations, and home connections shared by laptops from several employers.
Working hours that track Asian time zones and connection delays that do not fit a US worker.
Last-minute shipping changes, refused identity checks, and sudden leave when scrutiny starts.
Analysis
We grade every finding on a five-level ladder and state our confidence using intelligence community standards. We say exactly what the evidence supports, and nothing more.
One unusual signal. Logged and watched.
The worker is not who, or where, they claimed to be.
The infrastructure and methods match known North Korean operations.
Evidence matches published government and industry indicators. Stated with a confidence level.
A law enforcement determination. We prepare your referral; the government makes the call.
Engagements
A sweep of your current remote staff and contractors, including staffing-firm placements, with a graded written assessment and remediation plan.
We design and deploy the controls, our detection platform runs continuously, and we deliver a quarterly assessment. Not a 24x7 monitoring contract.
Remote-workforce and sanctions exposure at an acquisition target, delivered as a diligence memo for the deal team.
Remote Workforce Assurance investigates accounts, devices, and infrastructure. It does not score candidates or make employment decisions, and it is not legal advice. Findings about sanctions exposure go to your counsel.
Next step
Thirty minutes to scope it. Bring the size of your remote bench, how they were hired, and what you already collect from their endpoints — that is enough to tell you whether an assessment is worth running.