North Korea Expands Recruitment Scheme for Cyber Operations
Article Content
- •North Korea recruits foreign workers to disguise identities in job applications.
- •The scheme generates hundreds of millions annually for North Korea's weapons programs.
- •Countries targeted for recruitment include Iran, Nigeria, South Africa, and India.
North Korea is expanding its recruitment of foreign workers to infiltrate U.S. companies, utilizing individuals from countries like Iran, Nigeria, South Africa, and India. These foreign recruits are paid approximately $500 a month to act as 'interview associates' and help North Korean operatives secure remote technology jobs under false identities. This scheme generates significant revenue for the North Korean regime, estimated to be between $600 million to $800 million annually, which is funneled into sanctioned programs, including weapons development. U.S. officials and cybersecurity researchers have noted that this operation has become increasingly sophisticated, with North Korean teams employing foreign nationals to obscure their identities during job applications. The United Nations has also highlighted the scale of these operations, indicating that North Korea's cyber activities yield at least $1 billion each year.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…