North Korea Expands Cyber Espionage by Recruiting Foreign Workers for U.S. Companies
North Korea targets Iran, Lebanon, and others to infiltrate U.S. firms, generating millions through cybercrime and sanctions evasion.
POLICY WIRE — Washington, D.C. — North Korea has broadened its covert strategy of embedding employees in U.S. businesses by enlisting remote workers from countries like Iran and Lebanon, according to U.S. government agencies and cybersecurity experts.
The operation, which involves thousands of applicants vying for roles at hundreds of American firms, generates hundreds of millions of dollars annually. This revenue is laundered to support the regime’s weapons programs, as reported by U.S. officials. In response, North Korea has increasingly turned to foreign nationals to mask its involvement and extend its reach globally.
📄 POLICY WIRE WHITEPAPER PUBLISHED: PAKISTAN’S NATIONAL SECURITY POLICY PRIORITIES
A report from Flare, a cyber threat intelligence firm, revealed that at least 14 Iranians have been directly recruited by North Korean IT teams since 2024, with some receiving formal job offers after completing interviews on behalf of North Korean candidates. The scheme leverages global recruitment platforms and uses cryptocurrency payments to obscure financial trails. Officials warn that this evolving tactic poses a growing challenge to U.S. corporate and national security.
Reporting by Policy-Wire (PW)





