North Korea’s cyber and financial theft efforts are increasingly relying on remote workers based in third countries, according to a report published by NBC. The scheme reportedly involves recruiting foreign IT workers—such as people located in Iran and Lebanon—to help North Korean-linked actors infiltrate US companies and route funds back to the DPRK in support of its weapons programs.
The renewed focus on “outsourced” digital labor comes after a July alert issued by the US government and multiple foreign agencies, warning that North Korean IT workers actively seek contracts with the aim of remitting salaries to parent agencies in North Korea. The alert also described these workers as potential insider threats, including roles in data exfiltration and cryptocurrency theft.
Key takeaways
- US and partner agencies warned in July that DPRK-linked IT workers use employment contracts to funnel pay back to North Korean agencies.
- NBC reports North Korea is using remote workers from third countries—reportedly including Iran and Lebanon—to pass job interviews and gain access to US firms.
- After contracts are obtained, NBC says North Korean operatives often take over the positions.
- The reported tactics extend to cryptocurrency theft, with some candidates allegedly being offered crypto compensation for part-time work.
- Broader reporting ties North Korea’s cyber operations to large crypto losses, underscoring how persistent these campaigns can be.
A US warning highlights contract-driven infiltration
The July alert cited by NBC frames the DPRK’s approach as more than typical hacking. Instead, it emphasizes how North Korean-linked IT workers attempt to gain entry through normal business channels—seeking contracts and leveraging employment relationships to access internal systems.
According to the alert, these workers “seek out contracts with the intent of remitting their salaries to their parent North Korean agencies.” It also describes them as posing an insider threat to companies, with participation in data exfiltration and cryptocurrency theft, as well as the theft of sensitive information. That combination points to a multi-stage method: gain a role legitimately or semi-legitimately, then convert that access into monetizable outcomes and compromised data.
Third-country remote staffing as a growing tactic
NBC reports that as governments have moved to counter DPRK efforts, the strategy has shifted toward recruiting remote IT workers from outside North Korea. The report says foreign workers are scouted—NBC specifically mentions LinkedIn—as North Korean-linked actors attempt to recruit people who can pass initial screening and interviews for remote positions.
Once those work contracts are obtained, NBC says the remote workers are typically followed by a transfer of control, with the roles then “usually” taken over by North Korean operatives. For firms hiring contractors—particularly those operating across borders—this is an important nuance: the risk is not only external malware or credential theft. It also includes what happens after a contractor is onboarded and gains legitimate access to development environments, internal documentation, or payment-related workflows.
NBC also reports that some of the foreign recruits were offered cryptocurrency—about $500 monthly in at least one case—in exchange for part-time work, described as “interview associates.” That detail matters for compliance teams: it suggests intermediated recruitment and payment schemes may be used to normalize crypto transfers in otherwise ordinary hiring processes.
The July alert’s themes—remittance intent, insider-threat potential, and links to crypto theft—appear consistent with what NBC portrays as a practical hiring pipeline. If implemented as described, the scheme reduces friction for DPRK actors by blending into legitimate commercial operations while still creating pathways to exfiltrate data and move value.
Crypto losses connected to DPRK activity remain substantial
The hiring/infiltration angle is part of a broader pattern that has repeatedly surfaced in cybersecurity reporting. Cointelegraph previously reported in May, citing CrowdStrike, that North Korean state-affiliated hackers were responsible for more than $2 billion in crypto losses in 2025—an estimated 51% increase year-on-year.
While the NBC report focuses on recruitment and insider access, the continued magnitude of crypto losses—per the CrowdStrike-cited figure—suggests that monetization channels (including cryptocurrency-related theft) remain a central goal. In practice, insider positioning and data access can accelerate theft by expanding the target set: not only wallets and exchanges, but also internal systems that may contain credentials, private keys, payment rails, or proprietary information that can be leveraged for further attacks.
For crypto investors and market participants, this matters because large-scale theft and follow-on laundering attempts can affect confidence in compliance and custody systems, and they can increase perceived regulatory pressure on the broader industry. Even when theft is confined to specific victims, the ecosystem-level narrative tends to build around repeat offenders and persistent attack methods.
Sanctions pressures, but limited signs of economic slowdown
Alongside the cyber narrative, economic reporting suggests sanctions have not prevented North Korea from sustaining activity at home. Cointelegraph previously noted, citing the Bank of Korea, that North Korea’s GDP increased 3.5% in 2025 despite global sanctions.
That estimate doesn’t prove the cyber recruitment scheme directly caused macro outcomes—but it provides context for why such operations may remain attractive to the DPRK. If the country’s economy is not collapsing under sanctions, then actors may have continued resources and incentives to invest in complex infiltration strategies that require coordination across borders and jurisdictions.
From a risk-management perspective, this implies that defensive measures must be ongoing. If North Korea can adjust recruitment tactics—shifting to remote third-country workers and using crypto compensation for part-time roles—then security teams should expect further evolution in how these threats blend into normal business processes.
What companies should watch next
As the details reported by NBC and the July alert suggest contract-based insider risk tied to crypto remittances, the most urgent question for employers and vendors is how these schemes will be detected in practice. Firms should track warning signals around contractor onboarding—especially scenarios involving unusually fast access to sensitive systems, crypto-focused payment arrangements, or patterns consistent with insider takeover after initial screening—while cybersecurity and compliance teams closely monitor how DPRK-linked recruiting methods develop.






