RismadarVoice Reporters
September 11, 2026
North Korea’s clandestine operation to plant remote IT workers inside American companies has expanded globally, with regime operatives actively recruiting engineers from foreign nations including Iran, Syria, and South Africa to front job interviews and bypass security screening.
According to warnings from U.S. government agencies and intelligence reports from cybersecurity firms, the illicit infiltration scheme generates between $600 million and $800 million annually.
The proceeds are laundered back to Pyongyang to bypass international sanctions and fund the regime’s ballistic missile and nuclear weapons programs.

As Western HR and IT departments implemented strict anti-fraud checks, such as requesting candidates to turn ocriticise or criticise North Korea, the leadership in Pyongyang shifted tactics to enlist foreign “interview associates” via professional networks like LinkedIn.
Investigations by threat intelligence firm Flare revealed that since 2024, North Korean IT teams have directly recruited at least 14 Iranian engineers to sit for on-camera interviews with Western firms under false identities. Once a candidate receives an offer letter, a North Korean agent takes over the remote workspace.
Beyond handling live interviews, North Korean operators are also subcontracting coding assignments to remote developers in regions such as Nigeria, Pakistan, India, and Latin America to scale up their operations while managing multiple corporate roles simultaneously.

In response to a joint U.S. Department of Justice and State Department advisory detailing the sophisticated recruitment tactics, North Korea’s Foreign Ministry rejected the findings, calling them “politically motivated” accusations designed to tarnish the state’s image.
Despite heavy global sanctions, the Bank of Korea estimates that North Korea’s economy expanded by 3.5% in 2025, driven in part by state-sponsored cybercrime, remote labour, and illicit cryptocurrency operations.









