The United States and ten of its allies have issued a joint statement warning companies, countries and other entities that a network of skilled operatives are disguising themselves online and working remotely to earn money for the North Korean regime. The group helps fund North Korea’s nuclear weapons and ballistic missile programs and includes hackers that steal data, sensitive information and large amounts of cryptocurrency from unsuspecting companies all over the world. “North Korean IT workers impersonate nationals of other countries to obtain work and income through online platforms operated by private companies for employment, procurement, and contracting of services,” it said.
The statement, which was issued by the U.S., South Korea, Japan, Canada, Australia, New Zealand, the United Kingdom, France, Germany, Italy and the Netherlands, explained how the regime uses such workers, living inside and outside North Korea, to evade targeted sanctions. It also warned countries against hosting them: “According to UN Security Council Resolution 2397, all UN Member States must repatriate to North Korea all North Korean nationals earning income in that Member State’s jurisdiction, subject to limited exceptions,” it noted.
The statement explains how North Korea has increasingly taken advantage of the remote work culture that was accelerated during COVID-19 as well as recent advances in Artificial Intelligence: “North Korean IT workers employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally.
It offers an extensive explanation of the network’s use of identity theft, forgery, third party facilitators and fraudulent and evasive banking techniques and to carry out the scheme. The statement also includes a long list of characteristics that companies offering online positions can look for in applications and applicants to identify a covert worker. Companies operating online platforms are encouraged to be on alert for frequent changes to registered information, mismatched or duplicate information and IP address discrepancies and to be on the lookout for AI generated image and document forgeries.
Hiring managers should look for employees who refuse to attend video conferences or appear with manipulated images; offers to work at unusually low rates, requests to be paid in cryptocurrency or evidence that a single account is being manipulated by different people at different times of the day.
“We urge all countries, companies, and other entities to deepen their understanding of North Korean IT worker schemes and implement measures to counter the tactics listed,” it said. “Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures … and detecting suspicious accounts.”
The U.S. and its allies have consistently called attention to the threat and remain committed to countering North Korea’s nuclear and missile programs.