EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Report says North Korea is recruiting foreign talent to infiltrate U.S. companies

2026-09-13 04:12:20
Bookmark

New trends in North Korea's cyber and financial theft: Relying on remote employees from third countries to infiltrate U.S. companies

According to NBC, North Korea's cyber attacks and financial theft activities are increasingly relying on remote workers located in third countries. The plan involves recruiting foreign IT practitioners-reportedly including people from Iran and Lebanon-to assist North Korea-linked actors infiltrate U.S. companies and transfer funds back to North Korea to support its weapons programs.

This focus on "outsourcing" digital labor stems from an alert issued in July by the U.S. government and several foreign agencies. The alert warned that IT workers in North Korea are actively seeking contracts aimed at remitting salaries back to their superiors in North Korea. The alert also noted that these workers pose a potential "insider threat" and may be involved in operations such as data theft and cryptocurrency theft.

Core Points

  • In a July warning, the United States and partner agencies pointed out that IT workers associated with North Korea used employment contracts to remit salaries to relevant North Korean agencies.
  • NBC reported that North Korea is recruiting remote workers from third countries, reportedly including Iran and Lebanon, to pass interviews and work at U.S. companies.
  • After receiving contracts, North Korean agents usually take over these positions.
  • The reported tactic extends to the field of cryptocurrency theft, with some candidates being offered cryptocurrency as remuneration for part-time work.
  • Wider reports have linked North Korea's cyber operations to huge cryptocurrency losses, highlighting the persistence of such operations.

Contract-based penetration strategy raises U.S. vigilance

The July alert cited by NBC characterized North Korea's practices as something that transcends typical hacking attacks. The alert emphasized that IT workers associated with North Korea tried to gain access to target systems through normal commercial channels-that is, seeking contracts and using employment relationships to access internal systems.

According to the alert, the workers "sought to sign contracts with the intention of remitting their salaries back to their superiors in North Korea." The alert also described them as posing an internal threat to the company and participating in data breaches, cryptocurrency theft and sensitive information theft. This combination suggests a multi-stage approach: first obtaining positions legally or semi-legally, and then transforming that access into monetized results and compromised data.

Remote employment in third countries has become an emerging tactic

NBC reported that as governments work to respond to North Korea's efforts, the strategy has shifted to recruiting remote IT staff from outside North Korea. Reports said North Korea-linked actors were trying to recruit people who could pass preliminary screening and remote job interviews, and NBC specifically mentioned LinkedIn as a platform for searching for such people.

Once a work contract is awarded, NBC said a transfer of control usually occurs then, with the role taken over by North Korean agents. For companies that hire contractors, especially those operating internationally, this is an important nuance: the risks come not only from external malware or credential theft, but also from subsequent risks caused by legitimate access to the development environment, internal documents or payment-related workflows that contractors gain after they join the company.

NBC also reported that some foreign recruiters are being offered to be paid in cryptocurrency-about $500 a month in at least one case-in exchange for part-time jobs known as "interview assistants." This detail is important to compliance teams: it suggests that intermediary recruitment and payment solutions may be used to normalize cryptocurrency transfers in other common recruitment processes.

The themes of the July alert-remittance intent, insider threat potential and links to cryptocurrency theft-appear to be consistent with the practical recruitment pipeline NBC describes. If implemented as described, the plan reduces friction costs for North Korean actors by integrating operations into legitimate commercial operations while creating paths for data leaks and value transfers.

Cryptocurrency losses related to North Korean activities remain huge

The recruitment/penetration perspective is part of a larger pattern recurring in cybersecurity reporting. Cointelegraph previously quoted CrowdStrike's data to report that North Korean state-affiliated hackers caused more than US$2 billion in cryptocurrency losses in 2025, an estimated year-on-year increase of 51%.

Although the NBC report focuses on hiring and internal visits, the continued large scale of cryptocurrency losses-based on data cited by CrowdStrike-suggests that monetization channels, including cryptocurrency-related theft, remain a core target. In practice, internal positioning and data access can accelerate theft by expanding the target set: not just wallets and exchanges, but also internal systems that may contain credentials, private keys, payment rails, or proprietary information that can be used for further attacks.

This is important for cryptocurrency investors and market participants, as large-scale thefts and subsequent money-laundering attempts can affect confidence in compliance and custody systems and increase regulatory pressure on the entire industry. Even if theft is limited to specific victims, ecosystem-level narratives often revolve around repeat offenders and persistent attack methods.

Limited signs of economic slowdown under pressure from sanctions

In addition to online narratives, economic reports suggest that sanctions have not prevented North Korea from maintaining levels of activity domestically. Previously, Cointelegraph quoted data from the Bank of South Korea as pointing out that despite global sanctions, North Korea's GDP grew by 3.5% in 2025.

This estimate does not prove that North Korea's recruitment plans directly led to macroeconomic results-but it provides context and explains why such actions remain attractive to North Korea. If the country's economy had not collapsed due to sanctions, actors might still have the resources and motivation to invest in complex infiltration strategies that require cross-border coordination.

From a risk management perspective, this means that defensive measures must be continuous. If North Korea is able to adjust its recruitment strategy-moving to remote workers from third countries and using cryptocurrency as compensation for part-time roles-then security teams should anticipate how these threats are further integrated into normal business processes.

Corporate Follow-up Focus

As the details of the NBC report and the July alert indicate, contract-based internal risks associated with cryptocurrency remittances are a key issue. The most pressing issue for employers and suppliers is how to test these plans in practice. Companies should track warning signs during contractor onboarding-especially when it involves unusually quick access to sensitive systems, cryptocurrency-focused payment arrangements, or patterns consistent with internal takeovers after initial screening-while cybersecurity and compliance teams should closely monitor the development of recruitment methods related to North Korea.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP