North Korea-linked operators are increasingly using paid third-country freelancers to clear job interviews at cryptocurrency and technology companies, then taking over the roles after hiring to gain access to internal systems, source code, sensitive business data and digital assets, according to a joint alert issued by the United States and 10 allied governments.
The approach turns ordinary remote recruitment into a potential entry point for state-backed cyber operations. Rather than relying solely on phishing, malware or attacks against public-facing infrastructure, the operators seek legitimate employee access through false identities and outsourced interview help. A successful placement can provide a foothold inside a company’s technical environment while also generating salary payments that authorities say are routed to North Korean government-linked accounts.
The July 31 alert, published by the U.S. State Department and FBI alongside authorities from Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom, said the wages earned by these workers have been connected to funding for North Korea’s nuclear weapons and ballistic missile programs.
Freelancers are used to pass hiring screens
Authorities described a recruitment model in which North Korea-linked operators approach technically skilled people in third countries, including Iran and Lebanon, through professional networking and job platforms. The recruits are offered part-time “interview assistance” work, with compensation of about $500 a month in cryptocurrency, to help an applicant secure a role at a targeted company.
Once the interview process has been completed, the operator can assume the position and begin working under the identity used during recruitment. The alert said workers commonly pose as foreign nationals while applying for jobs through online hiring, procurement and contracting services operated by private companies overseas.
This method gives an operator more than a one-time opportunity to deceive a recruiter. Access obtained through employment can place the individual inside internal communication systems, software-development processes, cloud environments and operational tools. The joint alert cited cases involving theft of business information, sensitive data, source code and cryptocurrency assets.
Crypto firms are particularly exposed where remote contractors can reach wallet-management infrastructure, deployment systems or privileged development tools. Access controls can limit those risks, but identity fraud complicates a security model that assumes a verified employee or contractor is operating the account assigned to them.
Ai adds another layer to identity fraud
The governments said North Korean IT-worker operations have become more sophisticated in both preparation and execution. The alert cited the use of artificial intelligence tools to create synthetic identities and support illegal activities spanning multiple countries.
Hiring teams and job platforms were urged to watch for account details that change repeatedly, including usernames, contact information and bank payout instructions. Mismatches between a name on identity documents and the name attached to a payment account can also signal abuse, as can a single identity document used to open multiple payout accounts.
Other warnings relate to the documents themselves. Authorities said employers should examine identity records that appear forged, altered with image-editing software or constructed with AI-generated imagery. The concern extends to onboarding, where a convincing application can later be paired with payment-account changes designed to conceal who ultimately receives the salary.
Network activity can reveal another part of the operation. The alert identified cases in which multiple technical accounts connect through the same IP address, or one account connects from several IP addresses within a short period. Accounts remaining active for unusually long stretches, or showing abnormal working hours, output levels or efficiency, may indicate that more than one person is operating the same profile.
The document also warned that users may post fabricated reviews about themselves to improve their ratings on freelance and contracting platforms. That tactic can help an account acquire the appearance of a reliable work history before it targets a more sensitive position.
Video calls and payment demands offer screening clues
Recruiters were advised to scrutinize resumes and written communications containing errors or unnatural phrasing associated with machine translation. Applicants who claim a nationality but say they cannot speak the related language may also warrant closer checks.
Video interviews remain a central point of vulnerability. The joint alert highlighted calls in which an applicant’s image does not match submitted identity information, appears AI-generated or seems to involve assistance from another person. Speech and movements that do not align naturally, refusals to join a video call or show a face, and inconsistent answers can all be useful indicators.
Authorities also cited unusually low compensation demands as a potential warning sign, especially when paired with a request for payment exclusively in cryptocurrency and a refusal to provide complete banking or payment-account information. None of these signals alone proves malicious activity, but together they offer employers a basis for enhanced identity verification before granting technical access.
Crypto theft remains a major source of pressure
The employment operations are developing alongside continued cyber theft linked to North Korea. CrowdStrike said North Korea state-associated hackers and threat actors caused more than $2 billion in cryptocurrency losses during 2025, a 51% increase from the prior year.
That figure illustrates why access obtained through recruitment is a serious concern for companies handling digital assets. An insider role may allow an attacker to study internal controls, map personnel and systems, or identify weak approval processes before attempting theft. The financial damage from a breach can also extend beyond assets taken directly, as companies may face service disruptions, incident-response costs and a loss of customer confidence.
The State Department and FBI alert frames the threat as both a cybercrime and sanctions-evasion issue. Salary payments, freelance income and access to corporate assets can each create revenue channels for North Korean state-linked operations. The Bank of Korea estimated North Korea’s economy grew 3.5% in 2025 despite extensive international sanctions, underscoring the continued relevance of overseas income-generating schemes to the country’s finances.
For crypto and technology employers, the immediate task is to treat recruitment, onboarding and contractor management as part of their security perimeter. Strong identity checks, limited initial permissions, careful monitoring of account activity and separation of sensitive operational duties can reduce the damage a fraudulent hire could cause. The latest multinational warning suggests that the risk no longer begins only when an attacker targets a company’s network; it can begin when a seemingly qualified applicant asks for an interview.
Strengthen your defenses against phishing and identity fraud by reading this crypto security guide next.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
