BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

North Korean Hackers' New Tactic: Pay $500 to Hire Interview Stand-Ins, Then Show Up to Work in Person

Wenser
Odaily资深作者
@wenser2010
This article is about 2035 words, reading the full article takes about 3 minutes
Includes a recruitment red-flag self-check list.
AI Summary
Expand
  • Core Viewpoint: North Korean hackers have escalated their methods for infiltrating crypto companies, hiring third-country technical professionals to conduct interviews on their behalf before impersonating them to join target companies, stealing crypto assets and sensitive information from within. In 2025, this caused over $2 billion in losses.
  • Key Elements:
    1. CrowdStrike data shows that in 2025, crypto losses caused by North Korea state-linked hackers exceeded $2 billion, a year-over-year increase of 51%.
    2. The U.S. State Department and FBI, together with 11 countries, issued a joint alert stating that North Korean IT workers use fake identities to remotely join companies, with salaries flowing back to the North Korean government to fund nuclear weapons and ballistic missile programs.
    3. New tactic: Hackers pay $500 per month in cryptocurrency to hire technical professionals from countries such as Iran and Lebanon to assist with interviews, after which they take over and join the target company themselves.
    4. The purpose of infiltration is not limited to salaries but also includes stealing business information, crypto assets, technical code, and sensitive data.
    5. Hackers use AI models to create fake identities and fabricate fake reviews on platforms like LinkedIn to boost credibility.
    6. Self-check red flags include: identity information not matching payment accounts, multiple accounts sharing the same IP, refusing to show one's face during interviews, and requesting cryptocurrency payment for compensation.

Original | Odaily (@OdailyChina)

Author | Wenser (@wenser 2010)

Remember the North Korean hacker who infiltrated the MetaMask wallet through an outsourcing arrangement? (Recommended reading: "Close Call! An Outsourced Employee Almost Destroyed MetaMask")

And the North Korean hacker who was exposed by a fake DeFi company running a sting operation? (Recommended reading: "The Sting of the Year: Fake DeFi Lures Out Real North Korean Lazarus Hacker")

Just as security companies have taken to running proactive sting operations, North Korean hackers are also upgrading their "attack methods" — from exploiting technical vulnerabilities at the start, to social engineering attacks later, and then to infiltrating teams through outsourced projects and remote onboarding at crypto projects. Recently, their infiltration tactics have evolved once again: they first hire someone to pass interviews at crypto companies, then impersonate that person to onboard, lie low after infiltrating, and eventually steal crypto assets and sensitive information through internal technical attacks.

A month later, the war between security companies and North Korean hackers has seen new developments, and a new type of scam has surfaced.

"Indirect Approach": Hackers Hire Someone to Interview, Then Take Over the Position — All to "Serve the Motherland"

First, let's look at the North Korean hackers' "track record": Data from security firm CrowdStrike shows that in 2025, crypto losses caused by North Korea state-linked hackers and threat actors exceeded $2 billion, up 51% year-over-year; South Korea's central bank estimates that despite joint sanctions worldwide, North Korea's 2025 GDP growth rate still reached 3.5%.

What is currently certain is that North Korean hackers, as a "national team," have also contributed significantly to their country's economic growth.

On July 31 of this year, the U.S. Department of State and the FBI, together with 11 countries including Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom, issued a security report titled "Alert on North Korean IT Workers."

The report contains a substantial amount of information, with key points including the following:

First, North Korea relies on a network of technical developers deployed domestically and abroad to conduct external operations. By dispatching these technical personnel to obtain false identities and work remotely for income, they ultimately transfer their salary earnings back to North Korean government agency accounts. The related funds are ultimately used for the development and advancement of North Korea's nuclear weapons and ballistic missile programs.

Second, in terms of the specific work performed by North Korean hackers, these technical developers typically obtain jobs and corresponding salary income on online employment, procurement, and contracting platforms operated by private companies overseas by assuming the identities of nationals from other countries.

Third, in addition to earning normal employee salaries, North Korean technical service personnel also pose an extremely high internal threat to the business information and commercial assets of the companies they join. A considerable number of them take the opportunity to engage in data theft, cryptocurrency theft, and theft of sensitive information.

Finally, in terms of specific implementation methods, the preparatory activities and operational tactics of North Korean hackers are becoming increasingly sophisticated, including even the use of AI models and applications to create fake identities and conduct illegal activities on a global scale.

It is worth noting that one of the most important pieces of information mentioned in this report is that, building on their previous practice of "interviewing in person," North Korean hackers have recently upgraded their "workflow" —

  • Now, they often first recruit technical workers from third countries (such as Iran, Lebanon, etc.) through job sites like LinkedIn;
  • They then ask some of these technical developers to work part-time as "interview assistants," offering $500 per month in cryptocurrency as compensation for helping them get hired at the target company.
  • Finally, the North Korean hackers take over the position themselves, joining the target company as a member of its team, thereby achieving technical infiltration — earning the corresponding salary for the position while waiting for the opportunity to steal sensitive information and data, crypto assets, technical code, and other commercial assets.

Undoubtedly, in the ongoing escalation of security offense and defense, North Korean hackers are also gradually upgrading their "SOP (standard operating procedure)," and their ultimate goal is, of course, to send funds back to their home country.

North Korean Hacker Infiltration Self-Check List: From Employee Personal Information to Daily Communication Habits

At present, North Korean hackers' methods are hard to guard against, but they still leave traces. Below are some signal indicators that companies should be vigilant about and self-check:

For companies operating online platforms, particular attention should be paid to the following:

  • Employees frequently changing registration information (account names, contact details, receiving bank accounts, etc.).
  • The name on an employee's ID document does not match the name on the registered payment account.
  • Multiple receiving accounts created using the same identity document.
  • Identity verification documents suspected of being forged or generated/tampered with using image editing software or AI image generation tools.
  • Multiple technical accounts making access requests from the same IP address.
  • A single account initiating access requests from multiple IP addresses within a short period.
  • Accounts remaining logged in for unusually long periods.
  • Abnormal cumulative working hours or related work metrics (e.g., excessively long online time, unusually high work efficiency, excessively large workload).
  • Job site users fabricating fake reviews for themselves to boost their ratings on work platforms, etc.

For companies recruiting employees, conducting interviews, or hiring outsourced workers, paying attention to the following details can help promptly avoid internal infiltration by North Korean hackers:

  • Errors or unnatural expressions in the interviewee's personal profile (suspected machine translation), claiming to be unfamiliar with the native language in their identity information (given the prevalence of AI translation services, one can only pay closer attention to their language expression).
  • Forgery details exposed during video conferences, such as photos not matching identity information; conference video footage being AI-generated or assisted by a third party, with unnatural language expression and body language.
  • Interviewed employees refusing to participate in video conferences or refusing to show their faces.
  • Labor compensation quotes lower than normal market rates.
  • Evidence that their personal technical accounts are operated by multiple people (usually indicating that such hacker activity often operates as a team, and the actual person interacting with you may change over time).
  • Requests for compensation to be paid in cryptocurrency, refusing to provide complete bank account and payment account information.
Safety
Developer
DeFi
currency
technology
AI
Welcome to Join Odaily Official Community