Site navigation

Warning Issued Over North Korean Threat Actors Posing as IT Workers

Graham Turner

,

streaming services dark web
The US has warned that IT workers from Pyongyang are supposedly posing as remote workers from other parts of Asia in a bid to infiltrate companies.

Three US Government agencies have warned that some North Korean threat actors are trying to obtain remote working IT roles in a bid to steal money for their nation’s government.

It has long been thought that many of the country’s online operatives are tasked with acquiring capital to fund North Korea’s weapons programme.

In a joint statement, the US State Department, US Treasury Department and the Federal Bureau of Investigation said that as well as North Korea itself, these ‘workers’ are based primarily in China and Russia, with a smaller number located in Africa and South East Asia.

The statement said: “The DPRK [North Korea] dispatches thousands of highly skilled IT workers around the world to generate revenue that contributes to its weapons of mass destruction and ballistic missile programmes, in violation of US and UN sanctions.

“These IT workers take advantage of existing demands for specific IT skills, such as software and mobile application development, to obtain freelance employment contracts from clients around the world, including in North America, Europe, and East Asia.

“Although DPRK IT workers normally engage in IT work distinct from malicious cyber activity, they have used the privileged access gained as contractors to enable the DPRK’s malicious cyber intrusions.”

In line with sanctions against the country, companies found to be hiring North Korean workers could face penalties.


Recommended


Through at least seven large-scale online attacks in 2021, North Korea amassed huge amounts of stolen cryptocurrency. Researchers have labelled threat actors from North Korea as advanced persistent threats (APTs) – arguably the most notorious of these being APT 38, also known as “Lazarus Group,” led by the DPRK’s primary intelligence agency.

Last month, it is thought that this group was behind the Axie Infinity attack, one of the biggest crypto-heists to date.

According to Sky Mavis, the company behind Axie Infinity, the FBI has claimed that North Korea-linked Lazarus Group and APT38 stole cryptocurrencies estimated to be worth over $600 million as part of the heist. The digital currency address where the stolen funds were transferred is believed to be under the control of Lazarus.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data