North Korea has expanded a long-running scheme to place fake IT workers inside U.S. and global tech companies. This operation now relies on recruits in third countries to help North Korean operatives pass job interviews and bypass identity checks.
According to recent reports from U.S. officials and cybersecurity researchers, the scheme has evolved to include facilitators in countries like Nigeria, South Africa, Iran, India, and parts of Latin America.
The methodology is strikingly straightforward: North Korean IT workers apply for remote tech jobs at foreign companies. Once a contract is secured, a North Korean operative typically takes over the role, with the salary then sent back to Pyongyang. This money is believed to fund sanctioned programs, including North Korea’s weapons development efforts.
How Facilitators Are Recruited
Cybersecurity firm Flare has identified that North Korean operatives are actively scouting developers on platforms like LinkedIn. Some recruits are offered around $500 per month to act as “interview associates,” appearing on camera during job interviews while posing as the actual applicants.
In one message reviewed by researchers, a North Korean operator told a potential recruit, “You’re from a country that is under sanctions. If you’re still interested in the role, I need to confirm whether you’re comfortable working under someone else’s identity.” This tactic draws in individuals from countries like Iran, where local developers face limited access to international work due to their own sanctions, making them more open to such arrangements.
Cybersecurity firms Kudelski Security and DTEX have confirmed that developers in South Africa, Syria, Iran, Nigeria, Pakistan, and parts of Latin America have been approached through this network.
Scale of the Operation
The United Nations estimates that North Korea’s remote IT worker schemes generate between $600 million and $800 million annually. Broader U.S. intelligence assessments place North Korea’s total annual earnings from cyber activities—including IT worker schemes and cryptocurrency theft—at a minimum of $1 billion.
In May 2026, cybersecurity company CrowdStrike reported that North Korean state-affiliated hackers were responsible for more than $2 billion in cryptocurrency losses in 2025, marking a staggering 51% year-on-year increase. Notably, North Korea’s GDP grew an estimated 3.5% in 2025, despite ongoing international sanctions.
In July 2026, the U.S. State Department and Department of Justice issued a joint warning alongside foreign agencies, stating that North Korea was employing “increasingly sophisticated” tactics to recruit individuals outside its borders to help hide the identities of its operatives.
Blockchain firm Consensys previously disclosed it had unknowingly outsourced developer work to a North Korean operative, underscoring the real risks posed by these infiltration tactics.
