North Korean operatives are paying recruits up to $500 a month across Nigeria, South Africa, India, and Iran as part of a sprawling international scheme to plant fraudulent IT workers inside American companies, according to recent findings by blockchain analytics firm Elliptic and reported by international news outlets in late 2024 and early 2025. The operation leverages overseas proxies to bypass U.S. employment verification protocols, funneling foreign wages back to Pyongyang to evade international economic sanctions.
How the North Korean IT Worker Infiltration Operates Abroad
According to investigations detailed by Elliptic, North Korean state-sponsored actors establish physical proxy stations in countries including Nigeria, South Africa, India, and Iran. These local recruits are paid monthly stipends averaging around $500 to host remote-access computer equipment, set up bank accounts, and complete identity verification checks. By using local citizens as front figures, North Korean operatives successfully mask their true geographic locations, making it appear as though job applicants are residing within Western jurisdictions while applying for remote software engineering roles.
U.S. federal authorities, including the Department of Justice and the FBI, have repeatedly issued joint advisories warning private companies about these illicit hiring schemes. According to U.S. government notices, North Korean IT workers frequently use stolen or forged identities—often buying Personally Identifiable Information (PII) belonging to U.S. citizens—to secure remote positions at Fortune 500 companies, media conglomerates, and financial institutions. Once hired, these workers collect substantial salaries in U.S. dollars, which investigators state are subsequently funneled back to fund North Korea’s weapons of mass destruction programs.
Global Scope and Regional Recruitment Hubs
The geographic spread of the recruitment network highlights the global reach of North Korean sanctions-evasion tactics. In African nations like Nigeria and South Africa, economic pressures and high unemployment rates among tech workers have created vulnerabilities exploited by foreign operatives offering steady remote-access management fees. Similar dynamics have been identified in South Asia and the Middle East, where local intermediaries manage networks of laptops and virtual private network (VPN) relays.
Security researchers note that these proxy setups are designed to defeat modern corporate “know-your-employee” and remote-onboarding safeguards. When a U.S. company requests a video interview or background check, the proxy setup in countries like India or Iran uses specialized software to reroute video feeds or utilizes complicit local individuals who match stolen resume profiles. This multi-layered deception allows operators to maintain long-term employment agreements without ever stepping foot in the United States.
Implications for U.S. Corporate Security and Compliance
The exposure of these proxy networks places intense pressure on corporate human resources and IT security departments to overhaul remote-hiring verification procedures. Government warnings emphasize that companies employing remote software developers must implement rigorous identity checks, including hardware-based multi-factor authentication, live biometric verification, and deep audits of tax and banking details to ensure salaries are paid directly to verified domestic accounts rather than international intermediaries.
As international law enforcement agencies continue to track the financial trails linked to these operations, regulatory bodies are expected to increase scrutiny on remote employment platforms and third-party recruitment agencies. Companies that fail to vet remote contractors adequately risk not only operational data breaches and intellectual property theft but also potential violations of U.S. sanctions laws governing financial transactions with North Korean entities.