Key Points
- Pyongyang is enlisting IT professionals across Nigeria, South Africa, Iran, and India to facilitate the placement of fraudulent workers within American corporations
- International “interview proxies” receive approximately $500 monthly compensation, often through cryptocurrency channels
- North Korean agents assume control of positions after employment agreements are finalized, channeling income to the regime
- This operation reportedly produces between $600 million and $800 million each year for North Korea
- North Korean cybercrime activities, encompassing cryptocurrency theft, surpassed $2 billion in damages during 2025
Pyongyang has significantly scaled up an established operation designed to embed fraudulent IT professionals within American and international technology corporations. This initiative now depends on intermediaries located in third-party nations to assist North Korean agents in clearing job interviews and evading verification protocols.
Based on an NBC News investigation published September 11, 2026, which references US government sources and cybersecurity analysts, this network has expanded to incorporate collaborators throughout Nigeria, South Africa, Iran, India, and various Latin American regions.
The operational framework is relatively simple. North Korean IT professionals submit applications for remote technology positions at international firms. After employment terms are finalized, a North Korean agent generally assumes the actual work responsibilities. Compensation is subsequently transferred back to Pyongyang.
These funds are suspected to support sanctioned initiatives, particularly North Korea’s weapons manufacturing programs.
Recruitment Tactics for Collaborators
Cybersecurity organization Flare discovered that North Korean handlers are identifying developers through professional networking sites like LinkedIn. Certain recruits receive offers of approximately $500 monthly to serve as “interview proxies,” appearing via video during employment screenings while impersonating the genuine candidate.
In one communication examined by security analysts, a North Korean handler informed a prospective collaborator: “You’re from a country that is under sanctions. If you’re still interested in the role, I need to confirm whether you’re comfortable working under someone else’s identity.”
Nations such as Iran are being specifically targeted because local software developers experience restricted access to global employment opportunities due to existing sanctions, increasing their receptiveness to such proposals.
Security research organizations Kudelski Security and DTEX have both verified that developers throughout South Africa, Syria, Iran, Nigeria, Pakistan, and Latin American territories have been contacted through this infrastructure.
Magnitude of the Network
United Nations estimates indicate North Korea’s remote IT workforce schemes generate as much as $600 million annually. A US-coordinated sanctions oversight evaluation estimated the amount reached $800 million during 2024.
More comprehensive US intelligence evaluations place North Korea’s aggregate annual revenue from cyber operations, encompassing IT workforce schemes and cryptocurrency theft, at no less than $1 billion.
During May 2026, cybersecurity firm CrowdStrike documented that North Korean state-sponsored threat actors accounted for over $2 billion in cryptocurrency losses throughout 2025, representing a 51% increase compared to the previous year.
The Bank of Korea estimated North Korea’s GDP expanded approximately 3.5% in 2025, notwithstanding continuing international sanctions.
In July 2026, the US State Department and Department of Justice released a collaborative advisory with international partner agencies, indicating North Korea was employing “increasingly sophisticated” methods to enlist individuals beyond its borders to conceal operative identities.
Blockchain company Consensys previously acknowledged it had inadvertently contracted developer services to a North Korean operative.


