Threat Intelligence, Identity, Government security

North Korea recruits Iranian workers for IT job fraud

(Adobe Stock)

North Korea has been recruiting workers from Iran as part of its ongoing remote IT job fraud scheme, Flare researchers revealed in a report last week.

Internal documents obtained by Flare explain how North Korean facilitators actively targeted Iranian IT workers for recruitment, scouting for them on LinkedIn and coaching them to prepare for interviews and commit identity fraud.

“Targeting Iran guys” one of the facilitators, known by the codename “Sea,” explicitly wrote in a spreadsheet used to track recruitment and job search efforts. Another operator, known as “Eugene,” wrote that he was “Hiring new guys in Iran, Syria and SA.”

A third recruiter, known as “Fineboy,” documented connecting with more than 50 Iranian developers, data engineers and .NET engineers on LinkedIn over the course of one week. In total, Flare was able to identify at least 14 Iranian workers who had formally begun the recruitment process with DPRK facilitators, and at least two who received formal offer letters from US employers.

The operators aimed to place these candidates in positions at U.S. defense contractors, cryptocurrency exchanges and financial institutions, Flare found. Communications between North Korean recruiters and Iranian candidates show how recruiters asked candidates to assume fraudulent identities to circumvent U.S. sanctions against Iran.

Facilitators also meticulously tracked the process of applying for jobs using fabricated personas, coaching recruits for interviews and other jobs skills, and handling onboarding issues like laptop acquisition and mandatory drug tests with the help of U.S.-based accomplices.

For example, Sea’s spreadsheet documents applying for more than 100 C#/.NET jobs using a fabricated persona named “Jack Long,” whose role would be assumed by an Iranian recruit. Additional internal documents showed recruits were paid $500 a month as a part-time “interview associate” while operators conducted the job search, and between $2,700 and $5,000 a month after being hired by an American or European company.

Most of the activity uncovered by Flare occurred prior to the recent Iran war, with some of the unearthed documents dating back to 2024. However, Flare Senior Cybercrime Researcher Adrian Cheek told SC Media that the ongoing conflict doesn’t necessarily mean the DPRK’s recruitment of Iranian workers will cease.

“The war hit Iran’s internet and communications hard, but it hasn’t knocked them out completely. There are a few ways people are still getting information in and out. Around 50,000 smuggled Starlink terminals are still being used across the country, even with the regime jamming signals and arresting anyone caught selling the devices,” Cheek wrote in an email.

SC Media asked if Flare knew why the records they obtained were written in English instead of Korean. Flare’s report notes that fluency in English was an important factor for North Korean recruiters in deciding whether to accept a candidate, with several rejections made based on lack of English skills.

“Our working theory is that the records may be maintained in English as a way for North Korean operators to practice the language, since opportunities to learn and use English inside North Korean are limited. It isn’t a confirmed finding from the records themselves,” Cheek said.

Cheek declined to share any details with SC Media about how the internal DPRK documents were obtained, saying this was necessary to protect Flare’s methods and sources.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds