TREE NEWS reports: North Korea is using remote IT workers from third countries including Iran and Lebanon to infiltrate US companies, with North Korean personnel typically taking over the position once the interview is passed. US authorities and foreign agencies warned in July of the insider threat, and some third-country IT workers recruited via LinkedIn are paid $500 in crypto monthly as interview helpers. CrowdStrike data puts crypto losses from North Korea-linked hackers in 2025 at over $2 billion, up 51% year on year.
North Korea Uses Third-Country IT Staff to Land US Jobs, CrowdStrike Puts 2025 Crypto Losses Above $2B
The notable shift here is operational: North Korea is no longer relying solely on its own nationals to pass hiring screens, but on third-country intermediaries paid in crypto — a pipeline that turns routine remote hiring into a state-sponsored access vector. The CrowdStrike figure matters less as a tally than as a signal that crypto remains the preferred monetization channel for those intrusions. For crypto and RWA firms, which often hire globally and hold irreversible assets, the insider risk is the exposure worth watching. Whether the third-country recruitment model scales faster than screening practices adapt is the open question.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.