North Korea’s New Playbook: Paying Third-Country IT Workers 500 USD a Month to Win the Interview, Then Sending in the Operatives
North Korea has evolved its worker-infiltration scheme again. Faced with tightening Western defenses against its fake-IT-worker operations, the DPRK is now recruiting remote workers from third countries, including Iran and Lebanon, to pass job interviews at US companies, according to an NBC News report published Friday. Once the contracts are secured, the positions are usually handed over to North Korean operatives.
The adaptation highlights how quickly Pyongyang iterates. For years, the scheme depended on North Koreans using stolen or fabricated Western identities to land remote developer, analyst and support roles. As US and allied governments improved detection, hiring platforms tightened verification, and employers grew suspicious of telltale patterns, the DPRK simply outsourced the hardest part: getting through the door with a face and passport that check out.
What the new scheme looks like
According to the report, foreign IT workers are scouted on LinkedIn, with some offered 500 USD monthly in cryptocurrency to work part-time as interview associates. Their job is not to do the work. It is to win the contract. Video calls, identity documents, employment history and references all belong to a genuine third-country national who has no obvious connection to North Korea. Only after the contract is signed does the handoff happen, with North Korean operatives taking over the day-to-day role.
An alert issued in July by the US government and several foreign agencies described the threat in blunt terms. North Korean IT workers seek out contracts with the intent of remitting their salaries to their parent North Korean agencies, the alert said, adding that they also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information.
In other words, the scheme has two revenue streams and one catastrophic failure mode. The revenue streams are salaries, which flow to Pyongyang through laundering channels, and opportunistic theft, ranging from proprietary code and credentials to outright cryptocurrency heists. The failure mode for the employer is that a hostile intelligence service holds an authenticated insider position inside its network.
The crypto connection runs deeper than salaries
The crypto industry has been the most targeted sector for these operations, and the numbers explain why. Cointelegraph reported in May, citing cybersecurity firm CrowdStrike, that North Korean state-affiliated hackers and threat actors were responsible for more than 2 billion USD in crypto losses in 2025, a 51 percent year-on-year increase.
The economics are difficult for sanctioned states to ignore. According to the Bank of Korea, North Korea’s GDP increased by an estimated 3.5 percent in 2025 despite global sanctions, a growth figure analysts have repeatedly linked to cyber operations and overseas worker remittances. For a country with limited export markets, stolen cryptocurrency and laundered salaries represent hard currency at sovereign scale.
The industry’s own hiring patterns made it vulnerable. Crypto startups hire remotely at high speed, pay in stablecoins, compete fiercely for engineering talent, and often skip the background-check rigor of traditional finance. A contractor who interviews well, accepts payment in USDT and never asks about benefits is not a red flag in a sector where that describes half the payroll. The Consensys case, in which the Ethereum-software company unknowingly outsourced developer work to a North Korean operative, showed that even mature, security-conscious firms are not immune.
Why the third-country pivot matters
The earlier iteration of the scheme failed primarily at the identity layer. Deepfake video interviews, reused passport scans, VPN slip-ups revealing timezones in Northeast Asia, and payment trails flowing through the same laundering clusters gave investigators repeatable detection signatures. Screening vendors built products around those signals.
A genuine Iranian or Lebanese worker produces none of them. The documents are real, the face matches, the accent matches the claimed biography, and the reference checks pass because the references are real people. The detection burden shifts from spotting a forged identity to noticing that the person who showed up to the interview is not the person doing the work afterward, a handoff that is nearly invisible in fully remote arrangements.
That is what makes the NBC report consequential beyond its details. The defensive playbook the industry built, identity verification, liveness checks, earnings-tax monitoring, crypto-payment forensics, addresses the previous generation of the threat. The current generation starts with a clean identity and only becomes North Korean after onboarding completes.
What companies can actually do
The defenses that still work against the handoff model are behavioral and operational rather than documentary. Companies can require live check-ins with camera on at random intervals, not just during hiring. They can monitor for sudden changes in working hours, typing cadence, code style, or connection geography after onboarding. They can restrict production access for the first months of any remote contract and use just-in-time credentials instead of standing privileges. They can watch payment destinations for changes to new wallets or accounts shortly after a contractor starts.
None of this is foolproof, and all of it adds friction that crypto firms, in particular, have been reluctant to impose. But the arithmetic is sobering: for 500 USD a month and a convincing LinkedIn profile, an adversary can rent a credible face. The cost of a single compromised repository, seed-phrase store or treasury key is exponentially higher.
The July government alert ended on a point that now reads as the whole story: the workers are not merely stealing paychecks. They are inside the perimeter. As long as Pyongyang can hire the interview, the industry cannot fully trust the hire.
paying third country workers 500 a month in crypto just to pass the interview loop is wild tradecraft. HR is cooked
^ scary part is the face and passport actually check out because its a real person. detection tools lose to a genuine hire from beirut
500 a month to win the interview then hand the job to pyongyang. the incentive structure is grimly efficient
^ true, so detection shifts to the first weeks of actual output. watch the commits not the interview
enjoy the camera checks and location pings for every remote dev now. privacy dies one incident at a time
References and passports checking out is exactly what HR kept telling us was safe. The hard part of security was never the tech.