North Korea Uses Foreign IT Workers to Infiltrate U.S. Firms

U.S. cyber agencies say North Korea used IT workers in Iran, Lebanon and elsewhere to pass interviews at U.S. firms, then replaced them with operatives who stole data and cryptocurrency.

A July alert from U.S. and allied cybersecurity agencies warned that North Korea used IT workers based in third countries, including Iran and Lebanon, to obtain jobs at U.S. companies and then replace those workers with North Korean operatives who stole corporate data and cryptocurrency.

Investigators found recruiters scouting candidates on professional networking sites and social platforms. Some recruits were offered about $500 a month in cryptocurrency to act as ‘interview associates’ who performed interview steps and onboarding tasks so a linked candidate could later assume the role.

Once contracts were secured, roles were typically taken over by North Korean operatives who worked remotely or used covert access arrangements. The alert noted salaries were often routed back to parent organizations in North Korea and that recruited workers could pose an insider risk if they retained access or shared credentials after a handover.

Cybersecurity firms tracking the campaigns reported the operators combined social engineering with technical intrusion. After gaining access, operatives exfiltrated corporate data, harvested credentials and stole cryptocurrency.

One cybersecurity firm’s analysis attributed more than $2 billion in cryptocurrency losses in 2025 to North Korean state-affiliated hackers, a 51% increase from the previous year. Economic data from the Bank of Korea estimated North Korea’s GDP rose 3.5% in 2025 despite international sanctions.

The July advisory urged companies to strengthen vetting of remote hires, enforce stricter access controls, monitor unusual data transfers and review payment flows, especially transactions involving cryptocurrency.

The advisory described a shift from direct hiring of North Korean IT staff toward a layered approach using intermediaries to obtain positions inside target firms. It identified reliance on online recruitment platforms and cryptocurrency payments as features that help conceal candidate origins and financial flows.

U.S. and allied agencies said they are investigating individual cases and working with private-sector partners to detect and disrupt recruitment networks that facilitate placement and replacement of employees for malicious purposes.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author