
North Korea Uses Third-Country IT Workers to Penetrate US Firms

North Korea Uses Third-Country IT Workers to Penetrate US Firms
WEEX View
- The immediate variable for markets and crypto firms is whether U.S. and allied agencies escalate screening, sanctions, or compliance guidance around remote hiring, contractors, payroll flows, and outsourced development access.
- Crypto-linked businesses should watch whether this threat model is framed less as a conventional cyberattack and more as an insider-risk channel that can expose wallets, codebases, customer data, and internal systems before any exploit is visible on-chain.
- Another key point is enforcement scope. If third-country intermediaries, recruiters, or payment rails come under greater scrutiny, companies relying on distributed technical hiring may face tighter onboarding, identity verification, and access-control requirements.
North Korea is infiltrating U.S. companies through remote IT personnel recruited from third countries including Iran and Lebanon, with roles reportedly handed off to North Korean operators after interviews and salaries sent back to North Korean institutions.
The reported scheme relies on remote IT personnel based in third countries who secure jobs with U.S. companies and then transfer the work to North Korean personnel. According to the account, the arrangement is designed to generate funds for North Korea’s weapons programs while giving operators access to corporate systems from inside the organization.
In July, the U.S. government and several foreign agencies issued alerts warning that North Korean IT workers were seeking contracts and remitting their wages to North Korean institutions. Those alerts described the activity as an internal threat that could lead to data leaks, cryptocurrency theft, and exposure of sensitive information.
The report also said some third-country workers are recruited through LinkedIn to serve part-time as “interview assistants,” receiving $500 a month in cryptocurrency. That detail points to a wider support network around hiring, identity presentation, and payroll routing rather than a single direct-employment tactic.
Cybersecurity firm CrowdStrike said cryptocurrency losses attributed to state-linked North Korean hackers and threat actors will exceed $2 billion by 2025, representing a 51% year-on-year increase. While the current case centers on employment infiltration rather than a specific exploit, the warning places the activity within a broader pattern of North Korea-linked efforts to extract funds through cyber operations.
Why It Matters
This development matters because it shifts part of the North Korea cyber threat from perimeter defense to workforce trust and vendor management. For crypto companies, exchanges, infrastructure providers, and other firms handling digital assets, the risk is not limited to external attacks; it can begin with routine hiring, contractor onboarding, and privileged internal access.
It also broadens the policy and compliance angle. If authorities treat remote hiring networks as a sanctions, national security, and financial-crime issue, firms may need stricter checks on identity, geography, payroll destinations, and access permissions across globally distributed teams.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreSolana Rolls Out Second Rent Cut Under SIMD-0437
Anza said the second phase of Solana's SIMD-0437 rent reduction has gone live on the mainnet test version, lowering the per-byte rent-exemption parameter to 5,080 lamports and bringing the cumulative decrease to about 27%.
Iran Says Oman Meeting Will Discuss New Hormuz Passage
Iran said a September 14 meeting in Oman will focus on a new maritime passage in the Strait of Hormuz, while stressing that any reopening of the strait still depends on US commitments under an earlier memorandum.
South Korea Crypto Framework Review May Slip to 2027
South Korean Democratic Party members said work on the Digital Asset Basic Law will move forward this year, but legislative review could be pushed into the first half of 2027 as parliament faces audits and budget deliberations.
Brazil Crypto Rules Raise Licensing Bar for Exchanges
Brazil's new central bank rules for virtual asset service providers impose capital, auditing, AML and reporting requirements that could sharply reduce the number of crypto exchanges able to remain in the market.



