EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Cryptocurrency: North Korea uses foreigners to infiltrate U.S. companies

2026-09-14 00:14:43
Bookmark

North Korea expands its "proxy interview" network for infiltrating U.S. companies

According to an NBC investigation, North Korea is upgrading its penetration system for U.S. companies. IT workers, mainly based in Iran and Lebanon, were recruited to represent North Korean operators in interviews for remote positions. According to reports, some participants will receive approximately US$500 per month in cryptocurrency. Once the contract was established, the position was then taken over by staff members associated with Pyongyang.

This mechanism adds a new level of penetration by North Korea using false identities. Previously, U.S. authorities have documented a trend of third-party intermediaries being increasingly used to circumvent recruitment regulations. Today, North Korea no longer relies solely on its own operators or forged identities, but uses real people located in third countries to complete the most difficult part of recruitment-building trust relationships.

New infiltration methods: real faces and insider threats

NBC reported that foreign IT practitioners are approached through platforms such as LinkedIn, and their task is to attend remote job interviews with U.S. companies. Some people receive about US$500 a month in cryptocurrency for participating in this part-time job. After successful entry, these account permissions will then be taken over by North Korean operators.

This pattern is similar to a previous incident that led to a North Korean developer sneaking into the Consensus sys team. In July, the company discovered that a consultant using the "Tyler Knapp" identity had been working in its system for about a month. The NBC report reveals a new trend: Pyongyang can use real personnel from third countries to break through recruitment barriers and bypass traditional cybersecurity defenses.

On July 31, an international alert issued by the United States and multiple governments confirmed this evolution. The document notes that North Korean workers are increasingly using third parties to create accounts, participate in interviews, and even meet offline with employers to build trust. Although the document does not mention specific US$500 salaries or Iran and Lebanon cases, these details stem from NBC's investigation.

The crypto industry faces the risk of huge asset losses

Such methods are not only used to obtain salaries, but also pose a serious internal security threat. An alert on July 31 warned that these lurking employees could lead to data breaches, theft of sensitive information and theft of cryptocurrency assets. Target positions cover areas such as software development, mobile applications and blockchain applications.

  • Ethereum Foundation: As early as April this year, Cointerbune reported that the foundation helped identify about 100 North Korea-related developers involved in 53 encryption projects.
  • CrowdStrike:Its 2026 Financial Threat Report pointed out that North Korea-related actors stole $2.02 billion worth of digital assets in 2025, a 51% increase from 2024. Among them, the "PRESSURE CHOLLIMA" organization is suspected of stealing as much as US$1.46 billion.
  • Chainalysis: Data also shows that US$2.02 billion was stolen in 2025. The cumulative estimate is that the total losses caused by North Korean hackers over the years are approximately US$6.75 billion.

It is worth noting that this strategy sometimes completely avoids traditional technical hacking methods. If the operator directly obtains the developer position and has internal access, there is no need to look for vulnerabilities in the smart contract. This "social engineering" approach combined with technology penetration is making crypto companies increasingly worried.

Washington cracks down on hiring infrastructure

U.S. authorities are not only focusing on infiltrators, but are also beginning to pursue those who make these infiltrators possible. In March, the U.S. Treasury Department imposed sanctions on six individuals and two entities, accusing them of participating in the North Korean IT worker network. The Office of Foreign Assets Control (OFAC) estimates that these programs will generate nearly $800 million in revenue in 2024, mainly to fund Pyongyang's weapons of mass destruction program.

In addition, the U.S. Department of Justice has uncovered so-called "laptop farms." In one case, two U.S. citizens helped North Korean workers pose as employees living in the United States. The system used the stolen identities of at least 80 people and secured jobs at more than 100 U.S. companies. The move reportedly brought in more than $5 million for the North Korean regime. These professional computers are physically stored in the United States. Through remote access, North Korean operators mistakenly believe that the developers are working in their home country.

Industry warnings and future challenges

The latest international alert recommends strengthened control measures, including strict document verification, face-to-face interviews whenever possible, monitoring frequent identity or bank account changes, and maintaining special vigilance against candidates using non-traditional payment methods such as money transfer services or cryptocurrencies.

The encryption industry has long warned of this. Earlier this year, CZ warned that 60 fake North Korean developers had been found in the crypto ecosystem. However, the current novelty is that false identities may have real "faces" during interviews. Recruiters can check and talk to candidates through cameras, mistakenly thinking that they have been identified. But a few days later, it could be someone else who connected to the system. For U.S. companies and crypto exchanges, remote recruitment has become a complete attack surface, and the security defense line needs to be restructured urgently.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP