How North Korean IT Workers Launder Crypto: A Guide to the $1.65B Scheme

How North Korean IT Workers Launder Crypto: A Guide to the $1.65B Scheme

Imagine hiring a talented developer who works remotely, delivers code on time, and asks for their salary in USDC. Sounds normal? For many companies in 2025, this was the perfect cover for a state-sponsored money laundering operation. The Democratic People's Republic of Korea (DPRK) has evolved beyond simple hacking. They now deploy armies of IT professionals globally, hiding behind stolen identities and AI tools to siphon billions into their weapons programs.

You might think crypto theft is all about dramatic exchange hacks. While those make headlines, the quiet grind of North Korean IT workers generating steady revenue is arguably more dangerous. It’s harder to detect, easier to scale, and deeply embedded in the global remote work market. If you hire remote tech talent, you need to understand how these schemes work before your next payroll run.

The Scale of the Problem

We aren't talking about petty cash here. According to the Multilateral Sanctions Monitoring Team (MSMT), an independent body including New Zealand, Australia, and the US, North Korean operations generated at least $1.65 billion from January to September 2025. This figure includes a massive $1.4 billion heist from the crypto exchange Bybit in February 2025. But that single event doesn't tell the whole story. The MSMT’s October 2025 report highlights that cryptocurrency gains reached $1.2 billion in 2024, with a significant portion coming from legitimate-looking employment rather than outright theft.

Why does this matter to you? Because these funds don't stay in digital wallets. They are systematically funneled into the unlawful development of North Korea’s weapons of mass destruction and ballistic missile programs. When you pay a suspiciously cheap remote developer in stablecoins, you might be funding a rocket launch.

How the Scheme Works

The core mechanism is surprisingly low-tech in concept but high-tech in execution. North Korean operatives apply for remote IT positions using sophisticated obfuscation techniques. They use Virtual Private Networks (VPNs) to mask their location, often routing traffic through Russia or the UAE. They employ fraudulent identity documents and, increasingly, AI-powered voice and face software to pass video interviews.

Once hired, the request comes in: "Can we pay in USDC or USDT?" These stablecoins are preferred because they hold consistent value and are easily converted via Over-the-Counter (OTC) traders. On-chain analysis shows these workers receive regular payments, often around $5,000 monthly. This consistency mimics a standard salary, making it hard for finance teams to flag as unusual compared to the erratic spikes of a ransomware payout.

Comparison of DPRK Revenue Streams
Method Revenue Type Detection Risk Scale (2024-2025)
IT Worker Salaries Steady, recurring Medium (requires HR vigilance) $1.2B+ annually
Exchange Hacks Lump sum, volatile High (public scrutiny) $38% of illicit revenue
Ransomware Variable High (law enforcement focus) Declining share

Key Players and Facilitators

No one operates in a vacuum. The scheme relies on a network of facilitators who handle the logistics. One major player is the Chinyong Information Technology Cooperation Company, designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) in July 2025. This entity helps place workers and manage their earnings.

On the ground, specific individuals act as conduits. Senior operatives like Kim Sang Man and Sim Hyon Sop oversee the consolidation of funds. They move fragmented crypto assets from hundreds of worker wallets into central accounts before converting them to fiat currency. The infrastructure supporting this often sits in jurisdictions with loose financial oversight, such as parts of the UAE and Russia. In December 2024, OFAC sanctioned a facilitator known only as 'Lu' for helping launder these proceeds, highlighting how personal networks underpin these corporate structures.

HR manager reacting to a glitchy deepfake video interview with facilitators nearby.

Red Flags for Employers

If you’re hiring remotely, how do you spot a North Korean operative? The Royal Canadian Mounted Police (RCMP) issued a detailed advisory in July 2025 listing specific warning signs. First, look at the payment method. A strong preference for cryptocurrency, especially when competitors accept bank transfers, is a major red flag. Second, check the pricing. DPRK operatives often bid 20-30% below market rates to secure contracts quickly.

Technical inconsistencies are another giveaway. You might see multiple log-ins from IP addresses associated with different countries within short timeframes. During video calls, watch for lag between audio and video, or unnatural facial movements that suggest deepfake technology. The RCMP notes that 92% of verified applications contained forged educational credentials. Always verify degrees directly with the issuing institution, not just via LinkedIn profiles.

  • Payment Preference: Insistence on USDC/USDT over fiat.
  • Pricing Strategy: Bids significantly lower than market average.
  • Identity Verification: Difficulty providing real-time biometric verification.
  • Work History: Gaps or unverifiable claims in professional background.

The Impact on Businesses

The damage isn't just financial; it's operational. Companies report losing access to sensitive data when these workers disappear after receiving final payments. A cybersecurity firm reported to Chainalysis in June 2025 that a startup lost approximately $280,000 over six months to a single DPRK worker who used AI deepfakes during meetings. Once the crypto hits the worker's wallet, recovery is nearly impossible without law enforcement intervention.

The Canadian Anti-Fraud Centre reports an average loss of $47,000 per incident involving fraudulent IT workers, with 78% of cases involving cryptocurrency payments as of Q3 2025. Beyond the direct cost, there’s the risk of compliance violations. Hiring a sanctioned individual unknowingly can expose your company to regulatory penalties under OFAC guidelines.

Cartoon wallet running from a detective while fueling a rocket launch.

Countermeasures and Verification

So, what can you actually do? Avoiding crypto payments for remote contractors is the simplest step. If you must use digital assets, implement strict Know Your Customer (KYC) protocols. Conduct interviews using multiple communication methods simultaneously-ask them to turn on their camera while also sending a real-time photo via email. This makes it harder for deepfake software to maintain consistency across platforms.

Background checks need to go deeper than a quick search. Verify educational credentials directly with universities. Use blockchain analytics tools to trace where previous crypto payments went. Mandiant, a leading cybersecurity firm, estimates that implementing these measures requires 4-6 weeks of specialized training for HR and security personnel. However, the payoff is significant: companies adopting these protocols saw a 63% reduction in successful infiltration attempts according to a Treasury Department analysis.

Future Outlook

Is this threat going away? Probably not soon, but it is evolving. Governments are tightening the net. The Financial Action Task Force (FATF) updated its guidance in June 2025 specifically addressing virtual asset service providers and the DPRK threat. The US State Department now offers rewards of up to $15 million for actionable information on these schemes.

Technology is also catching up. The Treasury Department’s FinCEN is developing a prototype system expected to launch in early 2026 that identifies DPRK-linked wallet clusters with 89% accuracy. Industry analysts predict a 25-30% decrease in successful infiltrations by late 2026. Yet, North Korea’s adaptability suggests they will find new ways to exploit gaps in international regulation. As long as remote work remains global and crypto transactions remain pseudonymous, this cat-and-mouse game will continue.

Why do North Korean IT workers prefer cryptocurrency?

They prefer stablecoins like USDC and USDT because these assets allow for easy conversion to fiat currency through Over-the-Counter (OTC) traders. This bypasses traditional banking channels that might flag transactions linked to sanctioned entities, providing a layer of anonymity and liquidity.

What is the biggest red flag when hiring remote developers?

A strong insistence on being paid in cryptocurrency, combined with bids that are 20-30% lower than the market rate, is a major indicator. Additionally, difficulties in maintaining consistent biometric responses during multi-platform video interviews often point to the use of AI deepfake technology.

How much money have North Korean IT workers generated recently?

According to the Multilateral Sanctions Monitoring Team, these operations generated at least $1.65 billion between January and September 2025. This includes both steady salaries from IT jobs and larger sums from cyber heists like the $1.4 billion Bybit breach.

Can companies recover funds if they hire a North Korean operative?

Recovery is difficult and rare. Once funds are moved through multiple wallets and converted via OTC traders, tracing becomes complex. Most losses are absorbed by the company unless law enforcement seizes assets during a broader investigation, as seen in recent DOJ civil forfeiture complaints.

Are all remote crypto-paying workers suspects?

No. Many legitimate freelancers prefer crypto for speed and lower fees. The key is context. If a candidate refuses standard KYC checks, uses generic email domains, or has unverifiable past employment, the risk increases. Standard due diligence applies regardless of payment method.