North Korea’s surreptitious push to plant employees in U.S. companies has expanded to include remote workers from other countries, such as Iran and Lebanon, according to U.S. government and foreign agencies and several cybersecurity researchers. The scheme, estimated to involve thousands of workers applying to hundreds of American companies, generates hundreds of millions of dollars a year; the money is then laundered and used to fund the communist regime’s illicit weapons programs, according to U.S. government agencies. U.S. authorities and companies have taken steps to counter the ruse, which has in turn pushed North Korea to get more creative.
In July, the State Department and the Department of Justice put out a joint warning with several foreign agencies noting that North Korea is employing “increasingly sophisticated” tactics, including recruiting individuals outside its own country to help “obfuscate their identities and expand their activities globally.” Government officials say North Korean teams are more frequently using people in foreign countries to participate as candidates in job interviews and sometimes establish in-person contact, in order to obtain work contracts. Once the job is secured, a North Korean agent typically takes over. Iran is part of a growing list of countries including Syria, Lebanon, South Africa and Saudi Arabia, that have recently been cited by researchers as countries where North Korean teams are actively enlisting people to conduct on-camera interviews with Western companies.
North Korea has long relied on U.S-based facilitators to receive and run company laptops and provide local internet access, but these internationally based individuals represent an expansion of the scheme’s accomplices. According to a report from Flare, a cyber threat intelligence company, since 2024 at least 14 Iranians have been directly recruited by North Korean IT teams and at least two Iranians received formal offer letters from U.S. employers after successfully completing interview processes on behalf of applicants from North Korean IT teams. In one instance, a North Korean operator noted on internal tracking documents reviewed by Flare, that he’d contacted more than 50 Iranian engineers.
It is not clear if operators accepted the roles offered to them. Chris d’Eon, a threat intelligence researcher at Flare and contributor to the report, said Iranians make compelling targets for the North Korean scheme. It’s hard to do that sort of arbitrage with Western jobs and Western salaries,” he said.
Mirroring Western recruitment norms, foreign targets in some cases were identified on LinkedIn, given onboarding instructions and offer letters from North Korean teams, and later paid in cryptocurrency. In some instances, recruits were offered $500 a month to serve as part-time “interview associates” and coached to use false identities, according to Flare’s analysis of leaked North Korean communications. So, there’s a lot of really highly educated STEM people in both North Korea and Iran for the exact same reason,” d’Eon said.
North Korea’s remote work schemes have proliferated since the pandemic, placing workers at U.S. companies in order to funnel money back to the regime and, in some cases, steal sensitive information. Those workers’ salaries are used in part to evade sanctions and fund the regime’s illicit programs, including its weapons of mass destruction and ballistic missile efforts, according to U.S. government agencies. The United Nations estimates the schemes generate as much as $600 million annually, while the U.S.
Extract — continue reading at the source.