North Korean Hackers Pay $500 a Month to Hire Interview Stand-Ins, Then Take Over Jobs

OdailyOdaily

Original | Odaily News (@OdailyChina)

Author | Wenser (@wenser 2010)

Remember the North Korean hacker who got into the MetaMask wallet through outsourcing?

And the North Korean hacker who was phished by a fake DeFi company and exposed to the public?

Like the security firms that proactively phish, North Korean hackers are also upgrading their "attack methods," from initial technical vulnerabilities to later social engineering attacks, and then to outsourcing project infiltration and remote onboarding at crypto projects. Recently, their infiltration tactics have taken a new twist: first hire someone to pass a crypto company interview, then swap in themselves to take the job, lie low, and eventually steal crypto assets and sensitive information through internal technical attacks.

A month later, the war between security firms and North Korean hackers has seen new developments, and a new type of scam has surfaced.

 

"A Roundabout Route": Hackers Hire Interview Stand-Ins, Then Take Over the Position, All to "Serve the Motherland"

First, let's review the "track record" of North Korean hackers: According to security firm CrowdStrike, in 2025, cryptocurrency losses caused by North Korean state-linked hackers and threat actors exceeded $2 billion, a 51% year-over-year increase; the Bank of Korea estimates that despite global joint sanctions, North Korea's GDP growth rate in 2025 still reached as high as 3.5%.

What is certain is that North Korean hackers, as a "national team," have made an important contribution to its economic growth.

On July 31 this year, the U.S. State Department and the FBI, together with 11 countries including Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom, issued a security report titled "Alert on North Korean IT Workers".

The report contains a wealth of information, with key points including the following:

First, North Korea relies on a network of technical developers deployed domestically and overseas to operate externally, sending these technicians to obtain fake identities, work remotely to earn money, and ultimately transfer salary income back to North Korean government agency accounts. The funds are ultimately used for the development and advancement of North Korea's nuclear weapons and ballistic missile programs.

Second, regarding the specific work of North Korean hackers, these technical developers typically obtain jobs and corresponding salary income by impersonating the identities of citizens of other countries on online employment, procurement, and contracting platforms operated by overseas private companies.

Third, in addition, North Korean technical service personnel not only earn normal employee salaries but also pose an extremely high insider threat to the business information and business assets of the companies they join. A considerable number of them take the opportunity to participate in data theft, cryptocurrency theft, and sensitive information theft.

Finally, in terms of specific implementation methods, the preparatory activities and operational techniques of North Korean hackers are becoming increasingly sophisticated, even including the use of AI models and applications to create fake identities and conduct illegal activities globally.

It is worth noting that the most important point mentioned in this report is that, building on previous "in-person interviews," North Korean hackers have recently upgraded their "workflow"—

  • Now, they often recruit technical workers from certain third countries (such as Iran, Lebanon, etc.) in advance through recruitment websites like LinkedIn;
  • Then, North Korean hackers ask some technical developers to work part-time as "interview assistants," paying them $500 per month in cryptocurrency to help them get hired at target companies.
  • Finally, the North Korean hackers take their place, joining the target company as a team member, thereby achieving technical infiltration, earning the salary for the corresponding position while waiting for opportunities to steal sensitive information and data, cryptocurrency assets, technical code, and other business assets.

Undoubtedly, in the ever-escalating security offensive and defensive battle, North Korean hackers are also gradually upgrading their "SOP (workflow)," and their ultimate goal, naturally, is to send funds back to their home country.

 

North Korean Hacker Infiltration Self-Check Checklist: From Employee Personal Information to Daily Expression Habits

At present, the methods of North Korean hackers are difficult to guard against, but there are still traces to follow. Below are some signal indicators that companies need to be vigilant about and self-check:

For companies operating online platforms, special attention should be paid to the following aspects:

  • Employees frequently change registration information (account names, contact information, payment bank accounts, etc.).
  • The name on the employee's identity document does not match the name on the registered payment account.
  • Multiple payment accounts are created using the same identity document.
  • Identity verification documents are suspected to be forged or generated/tampered with using image editing software or AI image generation tools.
  • Multiple technical accounts send access requests from the same IP address.
  • A single account initiates access requests from multiple IP addresses within a short period.
  • Accounts remain logged in for abnormally long periods.
  • Cumulative working hours or related work metrics are abnormal (e.g., excessive online time, excessively high work efficiency, excessive workload).
  • Recruitment website users fabricate fake reviews for themselves to improve their work site ratings, etc.

For companies recruiting employees or conducting interviews and hiring outsourced workers, paying attention to the following details can help avoid internal infiltration by North Korean hackers in a timely manner:

  • The interviewee's personal profile contains errors or unnatural expressions (suspected machine translation), and they claim not to be proficient in the native language of their identity information (considering the prevalence of AI translation services, extra attention can only be paid to their language expression).
  • Forged details are exposed during video conferences, such as photos not matching identity information; the video conference screen is AI-generated or assisted by a third party, and language expression and movements/facial expressions are unnatural.
  • The interviewed employee refuses to participate in video conferences or refuses to show their face.
  • The labor compensation quote is lower than the normal general market price.
  • It is shown that their personal technical account is operated by multiple people (usually indicating that such hacker activities are often carried out in teams, and the actual interaction partner may change over time).
  • They request payment in cryptocurrency and refuse to provide complete bank account and payment account information.

This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.

Recommended

After Google Open-Sourced a Fruit Fly's Brain, It Learned to Play Games and Trade Crypto...BTCC Daily (9.14) | “Final” CLARITY Act Draft Released, September Fed Hike Odds Rise to 87%Arc Mainnet Countdown: Notable Launchpads and Platform Tokens in the EcosystemBTCC Weekly Highlights (Sep. 8–14): Oil Returns Above $100 as AI Safety Debate Hits Tech StocksFrom Mockery to Reality: Crypto Forced to Grow Up