North Korean (DPRK) state hackers are employing new tactics to infiltrate tech and crypto firms in the United States. A report from NBC reveals that this cyber operation recruits freelance IT workers from third countries, including Iran and Lebanon, via LinkedIn.
Paying $500 for Stand-In Faces
Job offers distributed across the professional network target foreign IT talent for specific roles as interview associates. Candidates willing to lend their identities are offered $500 per month, paid entirely in cryptocurrency. Their sole task is to rely on their personal technical skills to pass the job interview process at target companies.
The handover phase occurs immediately after recruitment concludes. As soon as an official employment contract is signed under the third-party worker’s name, the applicant steps away. The entire position and remote work access are directly handed over to waiting North Korean cyber operators.
Dual Mission of Theft and State Revenue
A joint advisory from the US government and several international agencies tracked the movements of these cyber operatives once they secured legitimate employee status. The covert North Korean IT workers carry out three simultaneous tasks: exfiltrating sensitive company data, compromising internal crypto assets, and funneling their monthly salaries directly to DPRK government agencies.
A report from cybersecurity firm CrowdStrike detailed the activities of this state-affiliated hacking group, holding them responsible for more than $2 billion in stolen crypto throughout 2025. The digital heist figure marks a 51% (YoY) surge in industry losses.
The influx of cyber funds has helped sustain the country’s real-world economy. Data from the Bank of Korea shows North Korea’s gross domestic product (GDP) grew 3.5% in 2025, expanding despite heavy global economic sanctions.
This LinkedIn infiltration proves that the weakest security link for crypto companies often stems not from smart contract code, but right at the HR department’s interview table.
Dilansir dari Cointelegraph.
Also read: Brevo SSO Flaw Compromises 138 Client Accounts - But Main Target Was 347,000 Trezor Users
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




