Newsroom
13 September, 2026 / News / AI / Tags: north, remote, korean, workers, korea

Foreign remote contractors pass interviews for U.S. companies before North Korean operatives assume the roles, according to recent reporting tied to a July government alert
North Korea is expanding a scheme that relies on remote information technology workers based in third countries to gain access to U.S. companies. The approach allows the regime to secure legitimate work contracts and then transfer control to its own operatives, with the aim of directing earnings toward weapons programs.
The method has grown more prominent as governments have increased pressure on direct North Korean recruitment channels. Foreign workers, including individuals from Iran and Lebanon, are used to clear initial hiring barriers that might otherwise flag connections to the Democratic People’s Republic of Korea.
Foreign IT specialists are identified and approached through professional networking platforms. Once selected, these individuals complete job interviews and secure remote contracts with U.S. firms. After the positions are established and access is granted, the roles are typically handed over to North Korean operatives.
In some instances, candidates have been offered cryptocurrency payments of about $500 per month to serve as part-time interview associates. This arrangement helps create credible hiring profiles while keeping financial transfers less visible than conventional payroll systems.
The overall workflow creates an initial appearance of ordinary remote contracting. Once North Korean personnel take control, they obtain system credentials, internal knowledge, and the ability to move data or funds.
A joint advisory released in July by U.S. authorities and several partner agencies described the broader pattern. North Korean IT workers actively pursue contracts with the explicit goal of sending salaries back to agencies linked to the regime.
The alert frames the activity as more than external cyber intrusion. It identifies these workers as potential internal threats capable of extracting data, stealing cryptocurrency, and removing sensitive corporate information once they hold authorized access.
The recruitment tactic sits alongside documented North Korean cyber operations that have produced substantial cryptocurrency losses. State-affiliated actors were linked to more than $2 billion in such losses during 2025, representing a 51 percent increase from the previous year.
Insider positioning can accelerate these outcomes by expanding access beyond external targets. Compromised systems may yield credentials, private keys, or proprietary data that support further theft or fraud.
Economic figures provide additional context for the persistence of the operations. Estimates from the Bank of Korea indicate that North Korea’s gross domestic product rose 3.5 percent in 2025 despite continuing international sanctions. The resilience suggests that alternative revenue channels, including cyber-related activity and remote labor schemes, remain viable for the regime.
Companies that depend on remote contractors face heightened exposure. Standard onboarding processes that grant system access, development tools, or payment workflows can become pathways for hostile actors if identity verification and ongoing monitoring remain limited.
The shift toward third-country intermediaries reduces the likelihood that employers will immediately associate applicants with North Korea. Once contracts are in place, the subsequent handover can occur with little external visibility.
Organizations are advised to strengthen controls around remote hiring, including deeper identity checks, restricted initial access privileges, and scrutiny of payment arrangements that involve cryptocurrency. Continuous monitoring after onboarding remains essential to detect unusual activity or role changes.
As countermeasures evolve, further adaptation in recruitment methods is expected. The combination of legitimate-looking contracts, third-country intermediaries, and cryptocurrency compensation continues to present a practical route for generating funds while obtaining sensitive access inside U.S. firms.









