North Korean Hackers' New Tactics: Paying $500 for Job Interviews, Then Physically Replacing Employees

By: www.odaily.news|2026/09/17 07:34:58

Original | Odaily Planet Daily ( @OdailyChina )

Author | Wenser ( @wenser2010 )

Do you remember the North Korean hacker who accessed the MetaMask wallet through outsourcing?

And that North Korean hacker who was exposed by a fake DeFi company phishing operation?

Like security companies that actively conduct phishing operations, North Korean hackers are also upgrading their "attack methods". Initially, they exploited technical vulnerabilities, then moved to social engineering attacks, and later to outsourcing projects and remote onboarding for crypto projects. Recently, their infiltration methods have taken on a new twist: they first hire individuals to interview through crypto companies, then they themselves replace those individuals to join the company, lying in wait to eventually launch internal technical attacks to steal crypto assets and sensitive information.

A month later, the war between security companies and North Korean hackers has seen new developments, with a new type of scam emerging.

"Curveball Tactics": Hackers Hire Interviewees to Take Over Positions, Ultimately for "Serving the Motherland"

First, let's take a look at the "achievements" of North Korean hackers: Data from security company CrowdStrike shows that in 2025, North Korean state-affiliated hackers and threat actors caused over $2 billion in cryptocurrency losses, a 51% increase year-on-year; the Bank of Korea estimates that despite facing global sanctions, North Korea's GDP growth rate in 2025 will still reach 3.5%.

It is now confirmed that North Korean hackers, as a "national team", have also contributed significantly to the country's economic growth.

On July 31 this year, the U.S. State Department and the FBI, in conjunction with Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the UK, issued a security report titled "Alert on North Korean IT Workers".

The report contains a wealth of information, key points include:

Firstly, North Korea relies on a network of technical developers deployed both domestically and abroad to operate externally, sending these technicians to obtain false identities and work remotely to earn money, ultimately transferring their earnings back to North Korean government accounts. The funds are eventually used to develop and advance North Korea's nuclear weapons and ballistic missile programs.

Secondly, from the specific work content of North Korean hackers, these technical developers typically obtain jobs and corresponding salaries on online employment, procurement, and contracting platforms operated by private companies overseas by impersonating citizens of other countries.

Furthermore, in addition to earning normal employee salaries, North Korean technical service personnel pose a significant internal threat to the business information and assets of the companies they join. A considerable number of them take this opportunity to engage in data theft, cryptocurrency theft, and sensitive information theft.

Finally, regarding specific implementation methods, the preparatory activities and operational techniques of North Korean hackers are becoming increasingly complex, even including the use of AI models and applications to create fake identities and conduct illegal activities globally.

It is worth mentioning that the most important piece of information mentioned in this report is that, based on previous "in-person interviews", North Korean hackers have recently upgraded their "workflow" ------

  • They often recruit technical workers from third countries (such as Iran, Lebanon, etc.) through job sites like LinkedIn in advance;
  • Subsequently, North Korean hackers will ask some technical developers to work part-time as "interview assistants", offering $500 in cryptocurrency per month to assist them in joining the target company.
  • Finally, North Korean hackers replace these individuals, entering the target company as part of the team, thereby achieving technical infiltration while earning the corresponding salary, and waiting for the opportunity to steal sensitive information and data, cryptocurrency assets, and technical codes as commercial assets.

Undoubtedly, in the ongoing upgrade of the security offensive and defensive battle, North Korean hackers are also gradually upgrading their "SOP (Standard Operating Procedure)", and their ultimate goal is naturally to transfer funds back to their home country.

North Korean Hackers' Self-Inspection Checklist: From Employee Personal Information to Daily Expression Habits

Currently, the methods used by North Korean hackers are difficult to guard against, but they still leave traces. Here are some signal indicators that companies need to be vigilant about and self-check:

For companies operating online platforms, special attention should be paid to the following aspects:

  • Employees frequently change registration information (account names, contact information, receiving bank accounts, etc.).
  • The name of the employee's ID holder does not match the name on the registered payment account.
  • Multiple receiving accounts created using the same identity document.
  • Identity verification documents appear to be forged or generated/altered using image editing software or AI tools.
  • Multiple technical accounts sending access requests from the same IP address.
  • A single account initiating access requests from multiple IP addresses in a short period.
  • Accounts remaining logged in for unusually long periods.
  • Cumulative working hours or related work metrics are abnormal (e.g., excessively long online time, overly high work efficiency, excessive workload).
  • Users on job sites writing false reviews to boost their work site ratings, etc.

For companies hiring employees or conducting interviews and outsourcing, paying attention to the following details can help avoid internal infiltration by North Korean hackers in a timely manner:

  • Interviewees' personal profiles contain errors or unnatural expressions (suspected machine translation), claiming they are not proficient in the language of their identity information (considering the prevalence of AI translation services, attention should be paid to their language expression).
  • Exposing forged details during video conferences, such as mismatched photos and identity information; the conference video may be AI-generated or coordinated by a third party, with unnatural language expression and gestures.
  • Interview employees refusing to participate in video conferences or show their faces.
  • Labor compensation offers below the normal general market price.
  • Showing that their personal technical accounts are operated by multiple people (usually indicating that such hacker activities often operate in teams, with real interactive subjects possibly changing over time).
  • Requesting payment in cryptocurrency and refusing to provide complete bank account and payment account information.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]