North Korea Uses Third-Country Remote Workers to Infiltrate US Firms
North Korea is increasingly using third-country remote workers to infiltrate US companies and channel funds towards its weapons programs, according to a report. This tactic involves recruiting foreign-based job seekers through mainstream platforms like LinkedIn, who are then positioned to move contracts and access before being replaced by North Korean operatives.
The July warning issued by the U.S. government and multiple foreign agencies highlights the threat not just as external hacking but as a multi-stage infiltration risk that includes insider behavior. The alert describes how these workers can function as insider threats, implicated in data exfiltration and cryptocurrency theft, as well as sensitive information.
The report notes that North Korea's approach has shifted towards leveraging remote workers outside the DPRK to gain entry into companies that may not otherwise connect the threat to North Korea. This tactic allows them to create an initial foothold that looks normal from an outside hiring perspective, then transition to the underlying actors with access to systems, credentials, or internal knowledge.
Some foreign workers were recruited after being scouted on LinkedIn, while others were allegedly offered cryptocurrency payments to perform part-time 'interview associate' tasks. The recruitment pipeline may be designed to blend into existing work structures while still using mechanisms that are harder to trace than conventional payroll.