Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
North Korea Expands Fake Remote-Worker Scheme to Iran, Lebanon and Beyond, Feds Seize $212,700 in Crypto

North Korea's scheme to plant fake employees inside American companies isn't slowing down. It's working with Iran, Lebanon, Syria, South Africa and Saudi Arabia to keep it running, according to NBC News.
The operation works like this: North Korean operatives use stolen or fabricated identities to land remote IT jobs at U.S. firms, then collect a paycheck that eventually gets laundered back to Pyongyang. U.S. government agencies estimate the scheme involves thousands of workers applying to hundreds of American companies and generates hundreds of millions of dollars a year, according to NBC News. A State Department sanctions monitoring assessment put the 2024 total as high as $800 million, Quartz reported.
That money doesn't stay in a bank account. U.S. authorities say it funds North Korea's illicit weapons and ballistic missile programs.
The foreign recruitment pivot
In July, the State Department and Justice Department issued a joint advisory with foreign partner agencies warning that North Korea has gotten more sophisticated, specifically by recruiting people outside the country to help "obfuscate their identities and expand their activities globally."
A report from cyber threat intelligence firm Flare found that since 2024, North Korean IT teams have directly recruited at least 14 Iranians, and at least two of them received formal job offer letters from U.S. employers after completing interview processes on North Korea's behalf. One North Korean operator's internal tracking documents, reviewed by Flare, showed he'd contacted more than 50 Iranian engineers. It's unclear how many actually took the work.
Chris d'Eon, a threat intelligence researcher at Flare, told NBC News that Iranians are attractive targets because of their economic isolation. "It's hard to do that sort of arbitrage with Western jobs and Western salaries," he said, referring to the difficulty Iranians face finding well-paid international work through normal channels.
Kudelski Security's own 2026 investigation identified developers in Iran, Syria and South Africa working with North Korean teams that recruited them through LinkedIn, Quartz reported. According to NBC News's reporting cited by Quartz, some recruits were paid in cryptocurrency, and North Korean operators offered as little as $500 a month for part-time work impersonating candidates in interviews. Beyond interview stand-ins, North Korean operatives are reportedly farming out real development work to these recruits while juggling multiple jobs simultaneously.
North Korea's Foreign Ministry has denied wrongdoing, dismissing the July advisory as a politically motivated attempt to damage the country's reputation, according to Quartz's reporting of NBC News. Pyongyang has not offered evidence disputing the specific recruitment and payment details laid out by Flare or Kudelski Security.
Beyond IT: healthcare and sales
The fraud isn't confined to tech jobs anymore. Huntress researchers have identified suspected North Korean workers moving into sales, marketing and medical roles, according to The Hacker News.
In February 2026, three employees at an Australian healthcare company were flagged as North Korean workers impersonating Chinese nationals. Investigators found they repeatedly connected through Astrill VPN and IPRoyal Proxy services, submitted fraudulent identity documents, and had passports with suspicious similarities to one another, plus word anomalies in utility bills used as proof of residence, according to Huntress's analysis cited by The Hacker News.
A separate case this year at an unnamed financial services firm turned up a PiKVM device, hardware previously linked to North Korean operations that lets remote operators control a company laptop physically shipped to a U.S.-based facilitator. The same device later had a USB capture card attached, letting an operator feed pre-recorded or manipulated video into Zoom calls as a fake webcam. Huntress investigated a third case in August 2026.
The money trail hits a courtroom
While the recruitment side expands, U.S. prosecutors are chipping away at the financial pipeline. U.S. District Judge Rudolph Contreras ordered the forfeiture of roughly $212,700 in stablecoins on Sept. 3, tied to wages North Korean IT workers earned and routed through a crypto wallet beginning with "0x81c4," according to crypto.news, which cited reporting from NK News.
The wallet received about 158,123 USDC from at least 10 addresses and 54,574 USDT from at least four more, all allegedly used to pay North Korean IT workers, prosecutors said. Contreras ruled the government had shown enough to establish wire fraud and money laundering tied to sanctions violations under the International Emergency Economic Powers Act.
That $212,700 is a fraction of the $7.74 million in crypto and digital assets the Justice Department is trying to seize in a civil forfeiture complaint filed in June 2025. Contreras declined to grant forfeiture of the remaining assets, ruling prosecutors hadn't adequately identified them in the public forfeiture notice. The case traces back to an April 2023 indictment of Sim Hyon Sop, a North Korean Foreign Trade Bank representative accused of moving IT workers' crypto earnings back to the regime.
The unresolved question is how much of the remaining $7.5 million the government can actually recover, and whether Contreras's narrower ruling signals prosecutors need tighter documentation before U.S. courts will hand over the rest.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.