Shortly after, suspicious activity from the employee’s laptop triggered a SOC alert and an investigation began.
looks like what happened is the employee had their company issue laptop mailed to a “laptop mule” (someone residing within the US who would operate the laptop on their behalf). The laptop mule then installed remote access software, allowing the real worker to control the laptop remotely from North Korea.
By having the laptop physically present in the US and connecting from a US IP address, they had hoped to avoid raising suspicion.