North Korea has expanded its scheme to infiltrate American companies by recruiting IT workers from other countries to clear job interviews, after which North Korean operatives quietly assume the roles, according to a new report.
A New Twist on an Old Scheme
For years, cybersecurity researchers have tracked how the Democratic People's Republic of Korea (DPRK) plants its citizens inside Western firms, often posing as remote software developers to funnel salaries back to the regime. The latest evolution involves leaning on third-country nationals whose language skills and clean backgrounds make them better suited to passing rigorous interview processes.
Once these foreign recruits secure a position, the actual work and system access are frequently handed off to North Korean personnel operating behind the scenes. This layered approach helps the operatives sidestep red flags that companies have learned to watch for, such as suspicious accents, inconsistent identities, or geographic mismatches.
Behind a legitimate-looking hire can sit an operative funneling both wages and stolen data straight to a sanctioned regime.
Why It Matters for Crypto and Beyond
The tactic poses a heightened risk to cryptocurrency and blockchain firms, which have long been prime targets for North Korean actors seeking both steady income and opportunities to steal digital assets. Placing insiders within these organizations can give the regime access to sensitive systems, private keys, and proprietary code.
The infiltration effort serves a dual purpose for Pyongyang: generating hard currency to support its sanctioned economy while positioning agents to carry out espionage or theft from within. Salaries earned through these fraudulent hires are believed to help fund the country's weapons programs.
Companies are being urged to tighten their vetting and monitoring practices, particularly for remote roles. Suggested safeguards include:
- Verifying identities through multiple independent checks
- Watching for outsourcing of tasks to unknown third parties
- Monitoring for unusual access patterns after onboarding
As the schemes grow more sophisticated, employers face mounting pressure to distinguish genuine international talent from carefully disguised state-backed operatives.
