The researchers at Crowdstrike, the security giant, says they have seen hundreds of cases where the North Koreans as workers in information technology leak from the companies’ remote to generating funds, which represents a sharp increase during previous years.
per The latest report to hunting threats at CroldstrikeThe company has set more than 320 accidents over the past 12 months, an increase of 220 % over the previous year, as the North Koreans obtained a fraudulent work in western companies that operate remotely as developers.
The scheme depends on North Koreans who use false identities, resuming, and the date of work to earn jobs and earn money for the system, as well as allowing workers to steal data from the companies they work for and blackmail later. The goal is to generate money for the approved nuclear weapons program from North Korea, which has been made so far Billions of dollars in the regime yet.
The number of people working in North Korea is not known for the unknown American companies, but some of them estimated the number in the thousands.
According to Croldstrike, the North Korea IT workers, which the famous “Chollima” company calls the name of the designation of piracy groups, depends on the AI Tolidi and other tools that operate with the same Amnesty International to formulate and modify CVs or “Deepfake” during remote interviews.
while The plan is not newThe North Koreans are increasingly successful in obtaining jobs, despite the sanctions laws that prevent American companies from employing North Korea workers.
Croldstrike said in its report that one of the ways to prevent the employment of workers who are punished for is the implementation of the best identification operations during the recruitment stage. Techcrunch heard stories about some companies that focus on encryption asking potential employees to say critical things about the North Korean leader, Kim Jong Un, in an attempt to get rid of potential spies. Possible North Korean employees are often monitored and wiped, making any such demand impossible and are likely to get out of the fraudulent factor.
Over the past year, the US Department of Justice sought to disable these operations by following the US -based facilitator who help Run and operate the chart For North Korean presidents. These operations included Targeting individuals who run “laptop farm” operationsWhich includes shelves from open laptops that North Koreans use to do their work as if they were physically present in the United States.
Representatives of the prosecution said In the indictment in June The North Korea operation stole the identities of 80 individuals in the United States between 2021 and 2024 for remote work in more than 100 American companies.
https://techcrunch.com/wp-content/uploads/2025/08/dprk-north-korea-it-workers-missile-nuclear-1248201209.jpg?resize=1200,801
Source link