North Korea Infiltrates US Companies Using Foreign IT Workers
In brief
- North Korea recruits foreign IT workers from Iran and Lebanon to pass US job interviews
- North Korean operatives take over positions to steal data and cryptocurrency
- Foreign workers recruited on LinkedIn offered $500 monthly in cryptocurrency payments
- North Korean hackers stole over $2 billion in crypto in 2025, up 51% year-on-year
- US government and allied agencies issued July alert on infiltration tactic
The infiltration playbook
North Korea has turned increasingly to third-country IT workers to pass job interviews, according to the alert. Foreign IT workers were scouted on LinkedIn, with some offered $500 monthly in cryptocurrency to work part-time as interview associates. Once a contract is secured, the position is typically transferred to a North Korean operative.
The strategy allows the regime to bypass hiring scrutiny and establish a foothold inside target organizations. It's a low-cost, distributed approach that exploits both labor-market gaps and the remote-work infrastructure many US firms now rely on.
Insider threats and crypto theft
North Korean IT workers seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. Once inside, they pose insider threats involving data exfiltration, cryptocurrency theft, and theft of sensitive information.
The scale is substantial. North Korean state-affiliated hackers and threat actors were responsible for more than $2 billion in crypto losses in 2025, a 51% year-on-year increase, according to cybersecurity company CrowdStrike. The regime appears to view cryptocurrency theft as a critical revenue stream.
Economic resilience under sanctions
Despite global sanctions, the Bank of Korea estimates North Korea's GDP increased 3.5% in 2025. The combination of cyber theft, remote-work infiltration, and third-country labor arbitrage appears to be helping the regime maintain economic growth while funding its weapons development program.
The alert underscores a growing vulnerability in how US companies vet and monitor remote employees, particularly in technical roles with access to sensitive systems or financial infrastructure.


