Back to news

North Korea Recruits IT Personnel from Third Countries to Infiltrate US Companies

According to Cointelegraph citing NBC News, North Korea is recruiting remote IT personnel from third countries such as Iran and Lebanon to assist in infiltrating US companies.

These third-country nationals are primarily sourced through the LinkedIn platform, hired as part-time "interview assistants" with a salary of $500 per month in cryptocurrency. The recruitment method transforms job-seeking platforms into initial entry points for infiltrating US companies.

The specific operational path involves these foreign personnel participating in job interviews under their own identities, obtaining job offers, and then having North Korean personnel take over the actual job responsibilities, using a "identity disguise + remote takeover" method to evade US companies' hiring scrutiny and identity verification mechanisms.

In July this year, the US government, in conjunction with several foreign agencies, issued a warning stating that North Korean IT personnel undertake contracts with the aim of remitting salaries back to North Korean parent organizations, posing internal threats to hiring companies. The specific risks involve data theft, cryptocurrency theft, and sensitive information theft.

Data shows that by 2025, the total cryptocurrency losses caused by North Korean state-associated hacker organizations will exceed $2 billion, a 51% increase compared to the previous year, reflecting the rapid expansion of related infiltration and theft activities.

From the perspective of risk transmission in the cryptocurrency industry, the growing scale of fund theft by North Korean-associated hackers directly erodes the asset security of exchanges, protocol parties, and individual users, raising the overall security and compliance review costs in the industry. On the other hand, the supply chain attack methods represented by "remote IT personnel infiltration" indicate that risk exposure has extended from purely technical vulnerabilities to the recruitment and human resource management aspects of companies, objectively benefiting security compliance companies that provide identity verification, employee background checks, and internal threat monitoring services.

Source: Public Information

ABAB AI Insight

North Korea's practice of infiltrating overseas companies to generate income through identity disguise has been tracked for years—since 2022, the US Treasury, FBI, and State Department have repeatedly issued joint warnings, indicating that North Korea sends or hires overseas IT personnel to impersonate foreign identities, undertaking remote development and IT outsourcing work on platforms like Upwork and LinkedIn, and remitting the earnings back to Pyongyang through third-party accounts to support its UN-sanctioned nuclear and missile programs.

In terms of funding pathways, such infiltration activities typically present a "salary monetization + asset theft" dual-track model—on one hand, the legitimate salary obtained through identity disguise is remitted back to North Korean-associated entities via cryptocurrency or third-party payment channels, while on the other hand, internal job permissions are exploited to steal sensitive corporate data, private keys, or directly execute cryptocurrency asset theft, both of which constitute important funding sources for North Korea to evade international sanctions and acquire foreign exchange and technological resources.

This is part of the same system as previous major cryptocurrency asset theft incidents perpetrated by the North Korean-associated hacker group Lazarus Group— in 2022, Lazarus Group stole approximately $600 million in assets by attacking the Ronin cross-chain bridge of Axie Infinity, and in early 2025, it was linked to the theft of about $1.5 billion in assets from Bybit exchange; compared to previous methods primarily focused on direct attacks on smart contracts or cross-chain bridge vulnerabilities, the recently exposed "third-country IT personnel infiltration" represents a shift in North Korea's actions from purely technical attacks to more covert supply chain and human resource infiltration.

Essentially, this is a restructuring of the industrial chain— as exchanges and protocol parties continue to increase their investments in smart contract security and cross-chain bridge protection, the difficulty of purely technical attacks has risen, prompting North Korean-associated actions to shift towards recruitment and employment, which has previously been a relatively weak regulatory attack surface. By moving the attack point from "code vulnerabilities" to "identity and human resource review gaps," they achieve the goal of bypassing existing corporate security defenses and directly obtaining access rights from within.

ABAB News · Cognitive Laws

  1. You can defend against code vulnerabilities, but not against recruitment vulnerabilities.
  2. The tighter the sanctions, the more covert the underground funding pathways.
  3. The cheapest attack surface is always people.

Source

·ABAB News
·
5 min read
·2 hrs ago
分享: