25.2 C
New York
Friday, September 11, 2026

Buy now

Header Banner

North Korea looks abroad for talent in its scheme to infiltrate U.S. companies



North Korea’s surreptitious push to plant employees in U.S. companies has expanded to include remote workers from other countries, such as Iran and Lebanon, according to U.S. government and foreign agencies and several cybersecurity researchers.

The scheme, estimated to involve thousands of workers applying to hundreds of American companies, generates hundreds of millions of dollars a year; the money is then laundered and used to fund the communist regime’s illicit weapons programs, according to U.S. government agencies.

U.S. authorities and companies have taken steps to counter the ruse, which has in turn pushed North Korea to get more creative. In July, the State Department and the Department of Justice put out a joint warning with several foreign agencies noting that North Korea is employing “increasingly sophisticated” tactics, including recruiting individuals outside its own country to help “obfuscate their identities and expand their activities globally.”

Government officials say North Korean teams are more frequently using people in foreign countries to participate as candidates in job interviews and sometimes establish in-person contact, in order to obtain work contracts. Once the job is secured, a North Korean agent typically takes over.

Iran is part of a growing list of countries including Syria, Lebanon, South Africa and Saudi Arabia, that have recently been cited by researchers as countries where North Korean teams are actively enlisting people to conduct on-camera interviews with Western companies. North Korea has long relied on U.S-based facilitators to receive and run company laptops and provide local internet access, but these internationally based individuals represent an expansion of the scheme’s accomplices.

According to a report from Flare, a cyber threat intelligence company, since 2024 at least 14 Iranians have been directly recruited by North Korean IT teams and at least two Iranians received formal offer letters from U.S. employers after successfully completing interview processes on behalf of applicants from North Korean IT teams. In one instance, a North Korean operator noted on internal tracking documents reviewed by Flare, that he’d contacted more than 50 Iranian engineers. It is not clear if operators accepted the roles offered to them.

Chris d’Eon, a threat intelligence researcher at Flare and contributor to the report, said Iranians make compelling targets for the North Korean scheme.

“From the North Korean operators’ perspective, this is a place where it is hard to get work internationally at a good price. It’s hard to do that sort of arbitrage with Western jobs and Western salaries,” he said.

Mirroring Western recruitment norms, foreign targets in some cases were identified on LinkedIn, given onboarding instructions and offer letters from North Korean teams, and later paid in cryptocurrency. In some instances, recruits were offered $500 a month to serve as part-time “interview associates” and coached to use false identities, according to Flare’s analysis of leaked North Korean communications.

“North Korea and Iran are very similar in that they’re sanctioned, and almost because of those sanctions, they have had to spend the last few decades developing their own science and technology education pipeline for their nuclear programs. So, there’s a lot of really highly educated STEM people in both North Korea and Iran for the exact same reason,” d’Eon said.

North Korea’s remote work schemes have proliferated since the pandemic, placing workers at U.S. companies in order to funnel money back to the regime and, in some cases, steal sensitive information. Those workers’ salaries are used in part to evade sanctions and fund the regime’s illicit programs, including its weapons of mass destruction and ballistic missile efforts, according to U.S. government agencies. The United Nations estimates the schemes generate as much as $600 million annually, while the U.S. State Department-led sanctions monitoring assessment placed earnings for 2024 as high as $800 million.

In response, Western organizations’ HR and security teams have made efforts to equip hiring managers with tools to identify red flags and potential fraud. Candidates are sometimes prompted to wave their hand in front of their face to check for the use of AI filters or to say something negative about North Korea’s leader Kim Jong Un. Using people from other countries to perform interviews is a way around those checks.

“It’s not a technical response to a problem; it’s now moving towards a physical response to a technical problem,” said Adrian Cheek, a senior cybercrime researcher at Flare who worked on Flare’s investigation.

Research by Kudelski Security, a cybersecurity firm, also found North Korean IT workers are now delegating parts of the interview process to developers elsewhere in the world who can pose as candidates and sometimes assist in passing technical tests.

In a 2026 investigation, Kudelski Security identified developers in Iran, Syria and South Africa who had accepted proposals from North Koreans after being approached on LinkedIn.

Beyond on-camera interview roles, North Korean teams are increasingly subcontracting their work, specifically targeting developers with the necessary skillsets, as they manage multiple jobs at once and look to scale the scheme.

Nigeria, Pakistan, India and parts of Latin America are also being targeted to assist in the scheme for facilitator recruitment, according to DTEX, a security company that tracks North Korea’s cybercrime.

In response to the joint government alert on the expansion of the IT scheme issued in July, North Korea’s Foreign Ministry released a statement rejecting the advisory, calling it a “nothing but a stereotyped political accusation with a sinister purpose to tarnish the image of our state.” A ministry spokesperson added, “The DPRK will never allow any politically and ideologically motivated attempt of the U.S. and other hostile forces to use the cyber issue as the means of criticism and pressure on other countries.”

North Korea doesn’t report economic data, but the Bank of Korea estimates North Korea’s real gross domestic product grew by 3.5% in 2025, marking the third consecutive year of growth over 3% in spite of global sanctions. Earnings from cyber crime are part of that growth, including IT work salaries and cryptocurrency heists, which net at least a billion each year, according to the Office of the Director of National Intelligence.



Source link

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

0FansLike
0FollowersFollow
0SubscribersSubscribe
- Advertisement -spot_img

Latest Articles