Key Takeaways: Thousands of North Korean operatives using fake and stolen identities have infiltrated at least eight US companies in a few months, funneling hundreds of millions of dollars back to Pyongyang.
Key Takeaways: Thousands of North Korean operatives using fake and stolen identities have infiltrated at least eight US companies in a few months, funneling hundreds of millions of dollars back to Pyongyang.

Thousands of North Korean operatives using fake and stolen identities have infiltrated at least eight US companies in a few months, funneling hundreds of millions of dollars back to Pyongyang.
Thousands of North Korean operatives using fake and stolen identities have secured remote jobs at US companies, infiltrating at least eight firms in a few months and funneling hundreds of millions of dollars to the regime, a Wall Street Journal investigation found.
"A successful placement can provide months or even years of continuous access to internal systems, source code, intellectual property and corporate decision-making," said Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScan.
The operation relies on forged identities, fake résumés, proxy interviews and remote facilitators to convince companies the person they hired is who they claim to be. North Korean IT worker schemes generated nearly $800 million in 2024 to fund the regime's weapons-of-mass-destruction programs, according to a UN report in March. US prosecutors charged four North Korean nationals in 2025 with using false identities to obtain remote IT jobs and allegedly stealing more than $900,000 in cryptocurrency from two companies, including a US blockchain research and development firm.
The threat extends beyond malware. Once hired, operatives gain legitimate access to internal systems, source code and sensitive data, and can gradually influence engineering decisions, code reviews and approvals without ever exploiting a software vulnerability. Two US "laptop farmers" — people who hosted clusters of computers that North Koreans could remotely access — were sentenced to 18 months in prison in May for helping DPRK IT workers pose as US-based employees in schemes that generated more than $1.2 million and affected nearly 70 companies.
Researchers at BCA LTD and NorthScan built a fake crypto startup, Ballena Azul, to study the operatives' methods. Over five weeks, three suspected workers — "Jack Anderson," "Angelo Espree" and "Lucas Theo" — worked inside controlled virtual desktops, unaware their every move was tracked. The ruse exposed external servers the workers used as intermediary points before connecting to the controlled environments. Some servers were tied to distributing InvisibleFerret and BeaverTail/OtterCookie malware in prior years and remained active, while others were entirely new and absent from mainstream block lists and threat feeds, García said.
The researchers deliberately introduced technical problems — selective network outages and disappearing mouse cursors — to see which tools the workers turned to when things went wrong. The suspected workers left behind chat logs, AI conversations, crypto wallet information, VPN exit nodes and hours of live video footage.
The operatives leaned on ChatGPT for writing and coding, including to answer basic questions and complete assignments they struggled with, and preferred Google Gemini for image alteration and document forgery. They used AstrillVPN exit nodes and 2fa.cn to share two-factor authentication codes across operatives. "The biggest surprise was how much of it ran on improvisation," García said. "There was no rigid playbook, no polished corporate process behind them."
The heavy AI reliance is not unique to the Ballena Azul workers. Reuters reported Monday that another North Korean hacking group, Kimsuky, was running AI tools locally to help automate cyberattacks, analyze stolen data and produce more convincing phishing campaigns.
For companies, the cost of a single missed hire is steep. The longer operatives remain undetected, the longer they draw salaries that ultimately fund the North Korean regime. García recommends periodic background checks, in-person identity verification and blocking services like AstrillVPN. The threat is not limited to crypto — recent campaigns have expanded into pharmaceuticals, civil engineering and architecture, where both intelligence and money are plentiful.
This article is for informational purposes only and does not constitute investment advice.