US officials say North Korean cyber teams are using people in foreign countries to participate in job interviews, establish in-person contact with employers and help operatives secure remote technology jobs under false identities.
The operation involves North Korean IT workers applying for jobs at foreign companies, securing contracts and sending earnings back to Pyongyang, according to US government agencies, cybersecurity firms and researchers.
The money is believed to support North Korea’s sanctioned programmes, including weapons development.
A September 11, 2026 report by NBC News, citing US officials and cybersecurity researchers, said the scheme has expanded beyond the United States to involve foreign facilitators in countries including South Africa, Nigeria, Iran, India and other emerging technology markets
The United Nations estimates that North Korea’s remote IT worker schemes generate up to $600 million annually, while a US-led sanctions monitoring assessment placed earnings from the operation as high as $800 million in 2024.
Broader US intelligence assessments estimate that North Korea earns at least $1 billion annually from cyber activities, including IT worker schemes and cryptocurrency theft.
Researchers say North Korean teams are using people in other countries to participate in online job interviews, establish contact with employers and help applicants bypass recruitment checks.
According to cybersecurity firm Kudelski Security, developers in countries including South Africa, Iran and Syria have been approached by North Korean-linked operators after being identified through platforms such as LinkedIn.
Security company DTEX also reported that North Korean teams have targeted Nigeria, Pakistan, India and parts of Latin America to recruit facilitators who can assist with interviews and other stages of the hiring process.
In some cases, foreign recruits are paid to act as “interview associates”, appearing on camera during job interviews while pretending to be the actual applicants.
Researchers said some facilitators received about $500 per month and were coached on how to maintain false identities.
US authorities and companies have taken steps to stop the scheme, but those measures have pushed North Korean operators to adopt more sophisticated methods.
In July, the US State Department and Department of Justice, alongside several foreign agencies, issued a joint warning that North Korea was using “increasingly sophisticated” tactics, including recruiting individuals outside its borders to help “obfuscate their identities and expand their activities globally.”
Flare, a cybersecurity intelligence company, found that North Korean teams were recruiting foreign developers to help candidates pass recruitment processes.
In one message reviewed by researchers, a North Korean operator told a potential recruit: “You’re from a country that is under sanctions. If you’re still interested in the role, I need to confirm whether you’re comfortable working under someone else’s identity.”
Chris d’Eon, a threat intelligence researcher at Flare and contributor to the report, said countries such as Iran have become attractive targets because sanctions limit access to international technology opportunities.
“From the North Korean operators’ perspective, this is a place where it is hard to get work internationally at a good price. It’s hard to do that sort of arbitrage with Western jobs and Western salaries,” he said.
The same strategy is now expanding to other regions, including Africa, as North Korean-linked groups seek skilled developers who can help them access global technology jobs while hiding their identities.
