Crypto: North Korea recruits abroad to infiltrate the US
North Korea is recruiting foreign developers paid in crypto to conduct interviews and infiltrate US companies.

$500 a month in crypto to attend job interviews under a false identity. North Korea is expanding its efforts to infiltrate US companies by recruiting real foreign developers, particularly in Iran, Syria and Lebanon. Their role: convince recruiters, pass technical tests and secure the contract. After that, North Korean operators can take over. Technology companies are not the only targets: crypto exchanges, financial institutions and even defense contractors have appeared in investigators’ findings.
Foreigners take interviews on their behalf
For several years, North Korea’s model relied primarily on regime-linked IT workers posing as American or European developers. Fake resumes, stolen identities, VPNs and remotely accessed computers helped maintain the illusion.
The system is evolving.
Evidence gathered by Flare shows that Pyongyang is now recruiting workers based in third countries to clear the most difficult hurdle: the human interview.
This change comes as companies are becoming better at detecting North Korean IT workers. Bref Crypto recently documented how Lazarus-linked hackers have already stolen at least $6.75 billion in crypto and moved more than $30 million worth of Bitcoin through Hyperliquid.
A connection coming from a suspicious VPN or an unusual time-zone discrepancy can be detected. Someone who genuinely speaks English, is proficient in C# or React and answers technical questions correctly is much harder to screen out.
That is precisely where foreign recruits come in.
Once the contract has been secured, the work can be taken over by another operator based elsewhere.
The interview is therefore no longer used only to determine whether a candidate is qualified. It has itself become an attack surface.
$500 in crypto to pose as the candidate
The report published by cybersecurity firm Flare provides a much clearer view of this organization.
Documents recovered from systems attributed to North Korean IT workers show recruitment campaigns targeting, among others, Iran, Syria, Lebanon and Saudi Arabia.
The recruits are not chosen at random.
The operators seek genuine developers who can answer technical questions and are comfortable enough speaking English to convince a Western recruiter.
In one case detailed by Flare Research in its investigation into North Korea’s international recruitment, an operator maintained the LinkedIn profile of a fake American developer named “Jack Long.” An Iranian engineer would then take his place when companies called.
The North Korean operator sent more than 100 applications every day under this identity.
The Iranian conducted the interviews.
Another document even resembles a genuine job offer: $500 a month to work part-time as an “Interview Associate,” with a trial period and paid leave.
Pay could then rise to $2,700 after placement. Other documents mention more than $5,000 a month for certain US assignments.
Payment could be made in crypto.
The operation starts to look almost like an underground recruitment agency.
Crypto exchanges are directly targeted
Why does crypto appear so frequently in these operations?
First, because it facilitates certain cross-border payments. Compensation can be sent quickly to a wallet without requiring a conventional US bank account in the name of the actual operator.
Second, because crypto companies themselves are particularly attractive targets.
Flare says it found indications of deliberate targeting of cryptocurrency exchanges, financial institutions and US defense contractors.
The appeal is not difficult to understand.
A developer employed by an exchange may sometimes access sensitive code, internal infrastructure, deployment procedures or systems that interact with wallets.
That does not mean an employee can simply transfer customers’ crypto.
But they can become an initial entry point for a much more complex attack.
The North Korean threat is no longer treated solely as a matter of cybercrime. Bref Crypto reported in June that the G7 now explicitly links North Korean cryptocurrency thefts to the financing of its nuclear and ballistic programs.
In 2025, Chainalysis estimates that groups linked to Pyongyang stole $2.02 billion in crypto, a 51% increase year over year.
A single hack, the Bybit attack, accounted for around $1.5 billion.
IT recruitment is another arm of the same clandestine digital economy.
Laptop farms have already generated millions
The operation does not run solely from Pyongyang.
To convince a US company that an employee is actually located in the United States, operators have used laptop farms for several years.
The principle is fairly simple.
A company supposedly hires a developer based in New York, Boston or elsewhere. It sends the employee a company laptop.
Except that the computer is received by an accomplice.
The accomplice installs it at home, activates the necessary tools and then allows the actual worker abroad to access it remotely.
To the company’s systems, the connection appears to come from a computer physically installed in the United States.
The fraud can last for months.
In April 2026, the US Department of Justice convicted two US nationals for participating in a scheme that placed North Korean workers in more than 100 US companies. At least 80 identities had been used.
The revenue generated exceeded $5 million.
The FBI has also warned that these intermediaries can open financial accounts, create profiles on recruitment platforms, install remote-control software or forward the machines overseas.
Bref Crypto had already reported that South Korea partnered with Chainalysis to strengthen investigations into North Korean crypto networks.
The problem now extends far beyond wallet monitoring.
Nearly $800 million from IT workers in 2024
How much does this activity actually generate for North Korea?
The estimates are considerable.
In March 2026, the US Treasury sanctioned six individuals and two entities accused of facilitating the operations of North Korean IT workers.
Washington estimates that these activities generated nearly $800 million in 2024.
The US Treasury directly links this revenue to the financing of North Korea’s weapons of mass destruction programs.
Not all of this revenue comes from crypto theft.
That is precisely what makes the model effective.
A spectacular hack can generate several hundred million dollars, but it requires exceptional access, months of preparation and immediately exposes the wallets used.
A fake developer follows a much more discreet model.
They can receive a perfectly ordinary salary every month from a perfectly legitimate company.
$5,000 here.
$8,000 there.
Several jobs at the same time.
Then some of the money is redirected through third-party accounts, payment platforms or cryptocurrencies.
At scale, the total becomes considerable.
North Korea is thus turning the global remote-work market into a source of foreign currency.
No need to break a blockchain.
Sometimes all it takes is successfully completing a Zoom interview.
An employee can also become an internal threat
The salary, however, is only part of the risk.
Once hired, the fake employee possesses something an external hacker would generally seek to obtain: legitimate access.
Company account.
Email.
Slack.
GitHub.
Internal documentation.
Corporate VPN.
Code repositories.
Sometimes production environments.
US and international warnings have emphasized this development. North Korean IT workers may exfiltrate data, steal sensitive information or engage in extortion after being dismissed.
The FBI had already warned in 2025 that some workers copied proprietary data or threatened to publish it when a company discovered the fraud.
The line between a fake employee and a cyberattacker then becomes very thin.
This issue is particularly sensitive in crypto.
A company may have the best hardware wallets on the market while giving an inadequately identified developer access to critical code.
The same logic applies to a financial company or defense group.
Security therefore no longer begins solely with the firewall or the private key.
It begins with recruitment.
Bref Crypto had already observed a similar phenomenon with the rise of scams using AI, deepfakes and synthetic identities in the crypto ecosystem.
The resume itself is now also a potential attack vector.
LinkedIn becomes part of the infrastructure
The use of LinkedIn makes the case even more troubling.
The professional network is specifically designed to connect companies with international talent.
North Korean operators are exploiting that same infrastructure.
Flare found in the history of some systems searches targeting Iranian, Syrian and Lebanese developers. The operators appear to select profiles according to their technical skills, command of English and ability to appear credible during an interview.
In several cases, the recruits reportedly knew they were working under an identity that was not their own.
This does not necessarily mean they knew the full scope of the operation or that they knew they were working indirectly for Pyongyang.
The distinction matters.
There may be several levels of complicity: some intermediaries may be fully aware of the fraud, while others may simply accept questionable work for a client whose true identity they do not know.
The operators can specifically take advantage of markets where skilled developers struggle to gain direct access to Western companies.
Sanctions, banking restrictions and visa difficulties then become recruitment tools.
Genuine technical expertise is paired with a fictitious identity.
The candidate exists.
The resume exists.
The developer knows how to code.
Only the person officially hired does not really exist.
A multinational fraud scheme
For a long time, the image of the North Korean IT worker was relatively simple: a developer based in China or Russia, hidden behind a VPN and a fake American identity.
That picture is becoming outdated.
The system described in 2026 now looks more like a global fraud supply chain.
A North Korean operator may manage the identity.
An Iranian developer may conduct the interview.
An American accomplice may host the laptop.
A third-party account may receive the salary.
Cryptocurrency may be used to pay an intermediary.
Then the actual operator connects to the company.
Each link in the chain does not necessarily know all the others.
That is what makes dismantling the scheme difficult.
US authorities are beginning to secure convictions, seize funds and sanction facilitators. The response is nevertheless forcing operators to change their methods again.
Turning to foreign developers appears to be an adaptation to controls deployed against fake North Korean profiles.
And that is probably the most important part of this story.
North Korea is no longer simply trying to better conceal its own workers.
It is outsourcing part of the deception.
For US companies—and especially crypto firms—the response can therefore no longer be limited to checking an IP address or requesting identification.
They must now verify that the person conducting the interview, the person whose documents are submitted and the person connecting to the network several weeks later are genuinely the same individual.
Crypto makes it possible to trace billions of dollars after a hack.
It does not automatically reveal who is behind a webcam during a job interview.
Pyongyang appears to have fully understood that difference.