HomeSecurityNorth Koreans pose as IT professionals on LinkedIn to infiltrate companies

North Koreans pose as IT professionals on LinkedIn to infiltrate companies

North Korean IT workers are applying for remote jobs using real LinkedIn accounts and impersonating other people.

North Korean IT professionals Linkedin

“ These profiles often have verified work emails and identities, which the perpetrators hope will make their fake applications appear legitimate ,” the Security Alliance (SEAL) said in a series of posts on X.

The IT worker threat is a long-running operation orchestrated by North Korea. Hackers pose as remote workers to secure jobs at Western companies using stolen or fabricated identities. The threat is also being monitored by the broader cybersecurity community as Jasper Sleet, PurpleDelta, and Wagemole.

See also: New 'ZeroDayRAT' kit allows complete compromise of iOS and Android devices

The ultimate goal of these efforts is twofold: to generate a steady stream of revenue to fund the country's weapons programs, to conduct espionage by stealing sensitive data, and, in some cases, to demand ransom to keep the information from leaking.

Last month, cybersecurity firm Silent Push described North Korea's program as a "high-volume revenue engine" for the regime, while allowing threat actors to gain administrative access to sensitive codebases and establish a presence in corporate infrastructure.

“Once their salaries are paid, North Korean IT workers move crypto through various money laundering techniques,” blockchain analysis firm Chainalysis in a report published in October 2025. “One of the ways that IT workers, as well as their money laundering partners, break the link between the source and destination of funds on-chain is through chain switching and/or token swapping. They use smart contracts such as decentralized exchanges and bridge protocols to complicate the tracing of funds.”

See also: Windows shortcuts used in Phorpiex ransomware campaign

North Koreans pose as IT professionals on LinkedIn to infiltrate companies

North Koreans pose as professionals on LinkedIn

To address the threat, people who suspect their identities are being used in fake job applications should post a warning on their social media accounts, along with listing their official communication channels.

“Always verify that accounts listed by candidates are verified by the email they provide,” Security Alliance said. “Simple checks like asking them to connect with you on LinkedIn will verify ownership and control of the account.”

It is worth noting that the Norwegian Police Security Service (PST) had also recently warned that Norwegian companies have been affected by similar malicious North Korean operations

See also: Warlock Ransomware breached SmarterTools

“Businesses have been tricked into hiring North Korean IT workers in work-from-home positions,” PST reported last week. “The income from wages North Korean workers receive through such positions likely goes to fund the country’s weapons and nuclear weapons program.”

North Koreans pose as IT professionals on LinkedIn to infiltrate companies

Alongside this operation, there is another campaign social engineering called Contagious Interview that involves the use of fake hiring processes. The perpetrators want to lure potential targets into interviews after approaching them on LinkedIn with job offers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The malicious phase of the attack begins when individuals posing as recruiters and hiring managers guide targets to complete a skills assessment that ultimately leads them to execute malicious code. In one case, threat actors reportedly asked candidates to clone a GitHub repository and run commands to install an npm package (in order to trigger the execution of malware).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS