julho 29, 2026

North Korean Spies Infiltrate Hundreds of Remote Jobs

0
dprk-north-korea-it-workers-missile-nuclear-1248201209

Cybersecurity firm CrowdStrike has revealed that North Korean operatives posing as remote IT workers have successfully infiltrated hundreds of Western companies over the past year to generate billions of dollars for the regime’s nuclear weapons program.

A 220% Surge in Remote Worker Infiltration

According to CrowdStrike’s latest threat-hunting report, researchers identified more than 320 incidents of fraudulent employment over the last 12 months. This represents a staggering 220% increase compared to the previous year, highlighting a rapidly growing threat vector where North Korean agents secure remote developer roles at unsuspecting Western enterprises.

While the exact number of active North Korean IT workers currently embedded within U.S. companies remains unconfirmed, industry experts estimate that the figure could reach into the thousands.

How “Famous Chollima” Funds the Regime

The sophisticated scheme relies on highly coordinated deception. Operatives use fabricated resumes, false identities, and falsified employment histories to secure remote positions. Once hired, these workers achieve two primary objectives: generating steady revenue for North Korea’s heavily sanctioned weapons programs and gaining internal access to corporate networks to steal sensitive data for subsequent extortion.

Deepfakes and Generative AI in the Hiring Loop

CrowdStrike tracks this specific cluster of North Korean IT activity under the moniker “Famous Chollima.” The group increasingly leverages generative AI tools to craft convincing resumes and cover letters. More concerningly, these actors utilize real-time AI video modification and deepfake technology to alter their appearance during live remote video interviews, bypassing standard visual checks.

Evasion Tactics and the “Kim Jong Un” Test

Despite strict international sanctions legally prohibiting U.S. entities from employing North Korean nationals, these operatives continue to bypass hiring security. To counter this, cybersecurity experts urge organizations to implement rigorous identity verification protocols during the onboarding phase.

In the cryptocurrency sector, some firms have reportedly adopted unorthodox vetting methods. Recruiters have asked remote applicants to verbally criticize North Korean leader Kim Jong Un during live interviews. Because these state-sponsored workers operate under intense internal surveillance, complying with such a request is virtually impossible, effectively exposing the fraudulent candidate.

Federal Crackdowns on Domestic “Laptop Farms”

The U.S. Department of Justice (DOJ) is actively targeting the infrastructure supporting these operations. Federal prosecutors are focusing on domestic facilitators who manage “laptop farms”—physical setups inside the United States housing racks of active laptops. These devices allow North Korean workers located overseas to connect remotely and appear as though they are working from a domestic U.S. IP address.

The scale of this identity theft was highlighted in a June indictment, which revealed that a single North Korean operation compromised the identities of 80 U.S. citizens to secure remote employment at more than 100 American companies between 2021 and 2024.

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *