North Korea recruits foreign proxies to bypass US corporate hiring checks
The regime is paying 'interview associates' in sanctioned nations to pose as candidates and secure remote IT roles.
North Korea has expanded its campaign to infiltrate U.S. companies by recruiting foreign nationals to act as proxies during job interviews. This shift allows the regime to bypass increasingly stringent security screenings and plant remote IT workers within Western organizations.
According to reporting from NBC News, North Korean teams are recruiting individuals in countries such as Iran, Lebanon, Syria, South Africa, and Saudi Arabia. These recruits, termed "interview associates," are paid to conduct on-camera interviews with Western employers while using false identities. Some associates are offered as much as $500 per month for these part-time roles. Once the proxy successfully secures a job offer, North Korean agents take over the position to generate revenue and potentially access sensitive corporate data.
The shift to human proxies
For years, the Democratic People's Republic of Korea (DPRK) relied on "laptop farmers"—U.S.-based proxies who provided the necessary hardware and local internet access to mask the origin of remote workers. However, as U.S. companies implemented more rigorous verification methods, the regime's technical obfuscation began to fail. Employers started requiring candidates to perform physical actions, such as waving their hands to detect AI filters, or asking provocative questions about the North Korean leadership to flush out state agents.
In response, the regime transitioned from technical workarounds to human ones. Adrian Cheek, a senior cybercrime researcher at Flare, noted that the strategy is no longer a technical response to a problem, but is "moving towards a physical response to a technical problem."
Funding weapons programs
This evolution in infiltration tactics represents a significant challenge for HR and security teams, as human proxies are far more difficult to detect than software-based masks. The financial incentive for the regime is immense. A sanctions monitoring assessment led by the U.S. State Department estimated that these remote worker schemes could earn the North Korean government as much as $800 million in 2024.
These funds are critical for the regime's survival under heavy international pressure. The revenue generated from these fraudulent IT roles is used to evade global sanctions and directly finance the DPRK's illicit ballistic missile and weapons of mass destruction programs.
Future risks
Security experts warn that the use of third-party nationals makes the attribution of these attacks more complex. As the regime continues to refine its recruitment network in sanctioned nations, the risk of intellectual property theft and financial fraud within the U.S. tech sector is expected to rise. Companies are now urged to move beyond standard video calls and implement more robust identity verification to prevent state-sponsored infiltration.