ThreatCluster

Amazon Identifies North Korean IT Worker via Keystroke Tracking

First seen 19 Dec 2025, 10:00 UTC CybersecuritynewsGbhackers 24

Article Content

Browse articles
ThreatCluster

Amazon detected a North Korean infiltrator posing as a U.S.-based IT worker by monitoring keystroke activity. The worker's commands were delayed, taking over 110 milliseconds to reach Amazon's headquarters, indicating unauthorized access to a corporate laptop. This incident highlights the effectiveness of keystroke analysis in identifying potential cyber threats.