Particle.news

Download on the App Store

North Korean IT Worker Scheme Exposed: 35 Chinese Front Firms Identified

Strider Technologies reveals a network of Chinese shell companies aiding North Korean IT workers in infiltrating Western firms to fund weapons programs and steal sensitive data.

North Korean leader Kim Jong Un and Chinese President X Jinping during a 2018 visit.
Illustration: Sarah Grillo/Axios
Image

Overview

  • A Strider Technologies report uncovers 35 China-based front companies linked to North Korean IT operations, with ties to the sanctioned Liaoning China Trade Industry Co.
  • Three key entities—Dandong Deyun Trading Co., Guangzhou Aiyixi Trading Co., and Yongping Zhuoren Mining Co.—are highlighted as major facilitators of the scheme.
  • North Korean IT workers use falsified identities to secure jobs at Western firms, funneling salaries into Pyongyang's missile development programs.
  • The operation has evolved to include corporate espionage, targeting sensitive data and intellectual property from infiltrated companies.
  • Cybersecurity firms and the FBI are ramping up detection tools to identify fraudulent job applications and mitigate future infiltration attempts.