North Korea Infiltrates US Firms Through Remote Workers and Crypto
North Korea is using remote workers from third countries to infiltrate US firms and route funds back to the country in support of its weapons programs, a new report says.
The scheme involves recruiting foreign IT workers, including those based in Iran and Lebanon, who are then used to gain access to internal systems and data. Once contracts are obtained, North Korean operatives often take over the positions, posing an insider threat to companies.
The tactic is part of a broader pattern that has repeatedly surfaced in cybersecurity reporting, with North Korea's cyber operations linked to large crypto losses. In fact, a previous report estimated that North Korea was responsible for more than $2 billion in crypto losses in 2025, a 51% increase year-on-year.
The use of remote workers and cryptocurrency compensation is seen as an attempt by North Korea to reduce friction for its actors while still creating pathways to exfiltrate data and move value. This has significant implications for compliance teams and cybersecurity professionals, who must closely monitor how these schemes develop and adapt their defensive measures accordingly.