Canada, allies express renewed concern over North Korean IT worker scheme
Joint alert says scheme is used by regime to finance weapons of mass destruction
Canada and multiple allies released an alert on Friday detailing a North Korean scheme to fund its weapons of mass destruction program.
According to the joint statement released by Global Affairs Canada (GAC) and its counterparts in Japan, the U.S., the U.K. and a half-dozen other countries, North Korea has continuously deployed a network of remote IT workers to defraud businesses and transfer revenues toward the proliferation of nuclear weapons.
The individuals within the network impersonate workers from other countries to obtain work and income with private companies, then remit their salaries to their parent North Korean agencies, the statement said.
Those funds are then used to expand North Korea's nuclear weapons arsenal, according to the Financial Action Task Force (FATF), an independent, intergovernmental anti-money laundering and counterterrorist financing watchdog.
The FATF has put North Korea on its "black list" as a high-risk jurisdiction, meaning the organization calls on all countries to deploy such countermeasures as terminating relationships with North Korean banks and limiting business relationships and transactions with North Korean nationals.
WATCH | North Korea shows off new missiles:Following a 2017 United Nations resolution, all member countries are required to repatriate any North Korean nationals earning income within their borders back to North Korea, with few exceptions.
Canada, along with France, Germany, Italy, Japan, South Korea, the Netherlands, New Zealand, the U.K. and the U.S., urged countries and companies to better understand North Korea's scheme and to deploy effective countermeasures against the illicit network.
It's not the first time Canada has issued an advisory about the risks posed by North Korea's IT worker scheme.
"Our countries have repeatedly issued information to warn the international community and private sector of the threat posed by North Korean IT workers," the joint statement reads. "We continue to actively monitor and counter the North Korean IT worker threat."
How does the scheme work?
The North Korean workers deployed to carry out the regime's plot are typically highly skilled in IT-related work and look for jobs and contracts in areas like web page development, mobile applications, software and blockchain applications, the statement says.
They often obtain work in foreign countries by falsifying their nationality or identity through a few common methods.
The scheme is also "increasingly likely" to involve proxy agents from third countries, according to the alert.
That might mean using their identification documents to forge online accounts, but it can go so far as to have the proxy participate in job interviews and establish in-person contact to create a false sense of trust with the company.
GAC and its counterparts said the workers in the network generally reside in North Korea, China and Russia, as well as in Southeast Asian and African countries, using third-party proxies, VPNs and other tools to conceal the fact they are working from abroad.
The schemes may also involve "laptop farms," which make use of company-provided laptops that are then accessed remotely by North Korean IT workers to cover their true location.
Identifying a North Korean agent
GAC and its counterparts provided a list of behaviours and characteristics often exhibited by workers involved in North Korean IT schemes.
They suggested web companies keep an eye out for certain behaviour, including frequent changes to registered information like account and banking details; multiple accounts created using the same identification document and accessed from the same IP address; a single account accessed from multiple IP addresses within a short period of time; and an account remains logged in for an unusually long period of time.
For companies hiring, some of the flagged behaviours include refusing to participate in video calls; video call discrepancies like photo ID mismatches or video feeds that seem manipulated or artificially generated; requesting payments in cryptocurrency; and signs the account is being operated by multiple people.
GAC and its counterparts said if multiple behaviours relate to someone applying for work, it's possibly a North Korean IT worker fraudulently seeking employment.
"North Korean IT workers often operate in teams, and the individual whom a hiring or procuring official interacts with may change depending on the time of day," the statement reads.
Big payouts toward North Korean weapons
According to the U.S. Treasury Department, North Korean IT worker schemes defrauded American businesses and generated $800 million US in 2024.
In April, two Americans were sentenced to prison for participating a plot that generated $5 million. Typical of the scheme, it involved a laptop farm operated by the two Americans, accessed remotely by a team of North Korean workers to extract income.
In that particular case, North Korean IT workers made use of at least 80 stolen U.S. identities to fraudulently obtain work at more than 100 American companies.
By generating funds through a network of illicit workers extracting income from companies globally, North Korea continues to finance its proliferation of weapons of mass destruction, according to the statement.
In March, North Korean leader Kim Jong-un promised to expand the regime's nuclear arsenal, and just last month his sister, Kim Yo-jong, said North Korea will never back down from its status as a country militarized by nuclear weapons.
WATCH | North Korea launches missile from a train: