4 Sources
[1]
North Korean spies posing as remote workers have infiltrated hundreds of companies, says CrowdStrike | TechCrunch
Researchers at security giant CrowdStrike say they have seen hundreds of cases where North Koreans posing as remote IT workers have infiltrated companies to generate money for the regime, marking a sharp increase over previous years. Per CrowdStrike's latest threat hunting report, the company has
[2]
Is Your Coworker a North Korean? Remote Scammers Infiltrate 300+ Companies
North Koreans are increasingly infiltrating US companies through remote work, with incidents rising more than 220% in the last year, according to cybersecurity vendor CrowdStrike. CrowdStrike's annual threat hunting report says North Korean IT workers infiltrated "over 320 companies in the last 12
[3]
CrowdStrike report details scale of North Korea's use of AI in remote work schemes -- 320 known cases in the last year, funding nation's weapons programs
The Democratic People's Republic of Korea is using generative AI tools to land agents jobs at tech companies to fund its weapons programs. CrowdStrike's latest Threat Report includes new information about China's increased targeting of North American telecommunications companies, Russia's
[4]
North Korean IT worker infiltrations exploded 220% over the past 12 months, with GenAI weaponized at every stage of the hiring process
Terrifying new fronts have emerged in a highly successful employment- fraud scheme in which trained North Korean operatives get jobs at companies around the globe under fake or stolen identities. The number of companies that hired North Korean software developers grew a staggering 220% during the
Share
Copy Link
CrowdStrike reports a 220% increase in North Korean IT worker infiltrations, with over 320 incidents in the past year. These operatives use AI tools to create fake identities, pass interviews, and maintain employment, funding North Korea's weapons programs.
CrowdStrike's latest threat hunting report reveals a dramatic 220% increase in North Korean IT worker infiltrations over the past 12 months. The cybersecurity firm has identified over 320 incidents where North Korean operatives obtained fraudulent employment as remote software developers in Western companies
1
.
Source: Tom's Hardware
The North Korean operatives, dubbed "Famous Chollima" by CrowdStrike, are leveraging generative AI and other AI-powered tools to enhance their infiltration efforts
1
. These tools are used to:The use of real-time deepfake technology allows a single operator to interview for the same position multiple times using different synthetic personas, increasing their chances of getting hired
2
.While the exact number of North Korean IT workers currently employed by unknowing U.S. companies is uncertain, estimates suggest it could be in the thousands
1
. The scheme has expanded beyond U.S. borders, with new "laptop farms" established in Western Europe, including Romania and Poland4
.
Source: TechCrunch
The primary goal of this operation is to generate funds for North Korea's sanctioned nuclear weapons program, which has reportedly made billions of dollars for the regime to date
1
. The UN estimates that since 2018, the scheme has generated between $250 million to $600 million per year4
.Related Stories
The U.S. Department of Justice has been actively working to disrupt these operations by targeting U.S.-based facilitators who help run the scheme
1
. In a recent case, a 50-year-old Arizona woman was sentenced to 8.5 years in prison for her role in operating a "laptop farm" that helped North Korean workers obtain 309 jobs and generate $17.9 million in revenue4
.
Source: PC Magazine
To combat this threat, CrowdStrike recommends that companies implement:
3
However, as North Korea continues to refine its tactics, the challenge of identifying and preventing these infiltrations remains significant for companies worldwide.
Summarized by
Navi
[1]
[3]
26 Apr 2025•Technology

09 Apr 2025•Technology

02 Jul 2025•Policy and Regulation
