
Someone on LinkedIn might offer you $500 a month in cryptocurrency to help them ace a remote job interview. That someone could be working for North Korea. According to a report by Cointelegraph, the DPRK has added a new layer to its already well-documented scheme of placing IT workers inside US companies: recruiting third-country contractors from places like Iran and Lebanon to handle the interview stage, then handing positions over to North Korean operatives once the contract is secured.
This matters because it shows the operation is adapting. US authorities have been aware of North Korea’s IT worker infiltration campaigns for years. A government alert issued in July warned that North Korean IT workers actively seek remote contracts with the explicit goal of sending their salaries back to state agencies. The alert also flagged them as insider threats, involved in data theft, cryptocurrency theft, and exfiltration of sensitive company information. The response from Pyongyang, apparently, was to add a human shield: outsource the interview to someone else.
The mechanics are straightforward and that’s what makes them effective. Foreign workers are scouted on LinkedIn and offered part-time crypto payments, reportedly around $500 per month, to act as “interview associates.” They pass the screening. Then the actual North Korean operative steps in to do the work. From a hiring manager’s perspective, you’ve verified a real person. You just haven’t verified the right one.
For companies, especially those hiring remote developers or IT contractors, this is a serious problem. Standard background checks and video interviews are no longer enough if the person you’re screening isn’t the person who will have access to your systems. And the access matters. Once inside, these operatives have been linked to data exfiltration and crypto theft, not just a paycheck going overseas.
The financial scale of this is not trivial. Cointelegraph previously reported, citing CrowdStrike data, that North Korean state-affiliated hackers were responsible for more than $2 billion in crypto losses in 2025 alone, a 51% year-on-year increase. The Bank of Korea estimates the DPRK’s GDP grew 3.5% in 2025 despite global sanctions. That growth doesn’t come from legitimate trade. It comes from operations exactly like this one.
The crypto angle is significant on two levels. First, crypto is how these workers get paid without triggering the kind of financial surveillance that would flag a wire transfer from Tehran or Beirut to Pyongyang. Second, crypto companies and Web3 firms are disproportionately targeted because they tend to hire remotely, move fast, and rely heavily on contractor relationships. Consensys, for example, was previously reported to have unknowingly outsourced developer work to North Korean nationals.
So what should companies actually do? There’s no single fix, but the risk profile for remote tech hiring has changed. Firms should consider:
- Live, unscripted technical interviews that are hard to proxy
- Identity verification that goes beyond a LinkedIn profile or a single video call
- Ongoing behavioral monitoring for contractors with access to sensitive systems or wallets
- Treating unusual payment requests, especially in crypto, as a red flag during onboarding
None of this is foolproof. But the old assumption that a passed interview means a vetted employee is no longer safe to make. North Korea has made a business out of exploiting exactly that assumption, and it’s getting better at it.