North Korea Recruits Foreign Talent to Infiltrate US Firms as Lazarus Group Widens Crypto Attacks

North Korea has expanded a covert campaign to place information-technology staff inside American firms by recruiting people in third countries to help hide the true origin of job applicants, according to US officials and cybersecurity researchers.

The effort previously relied heavily on stolen US identities and domestic facilitators who received company laptops and routed remote connections from abroad. It now increasingly uses workers in Iran, Lebanon, Syria, South Africa, Saudi Arabia and other countries.

Those recruits appear on camera for interviews and sometimes make in-person contact with employers.

Once a contract is secured, a North Korean operative typically takes over the position.

Threat intelligence firm Flare found that North Korean teams have approached at least 14 Iranian engineers since 2024; two of those individuals later received formal offer letters from US companies after completing interviews on behalf of the hidden applicants.

Operators scout talent on LinkedIn and offer roughly $500 a month in cryptocurrency for part-time work as “interview associates.”

Similar outreach has been documented in Nigeria, India, Pakistan and parts of Latin America.

Officials estimate that thousands of applicants target hundreds of U.S. companies each year.

The scheme generates hundreds of millions of dollars annually; United Nations and US assessments have placed recent yearly revenue in the $600 million to $800 million range. Salaries are remitted to Pyongyang and used to finance sanctioned weapons programs.

A July 2026 joint warning from the State Department, Justice Department and partner governments described the tactics as increasingly sophisticated and global.

The same state apparatus that runs the employment fraud also operates Lazarus Group, the loosely grouped North Korean hacking organization responsible for some of the largest cryptocurrency thefts on record.

Lazarus and related clusters have repeatedly targeted exchanges, blockchain bridges and decentralized-finance protocols through social engineering, supply-chain compromises and stolen credentials.

Major incidents include the 2022 theft of more than $600 million from the Ronin Network that served the Axie Infinity game and the $100 million Harmony Horizon bridge attack the same year.

In February 2025, actors attributed to Lazarus drained about $1.5 billion in Ethereum from Bybit by compromising a third-party wallet provider—the largest single crypto theft to date.

Blockchain analytics firms and CrowdStrike later reported that North Korean-linked actors stole more than $2 billion in digital assets in 2025, a 51 percent jump from the previous year, bringing cumulative thefts well above $6 billion.

Additional 2026 breaches of Drift Protocol and KelpDAO added hundreds of millions more.

In some cases the two campaigns overlap: fraudulent remote workers have used insider access to steal cryptocurrency or sensitive data from the firms that hired them. Both streams serve the same purpose—raising hard currency for a heavily sanctioned regime while evading traditional financial controls.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend