Skip to content
The ColumnInvestigation· No. 929

INVESTIGATION: Kim Jong-un Had His Hackers Inside Your Offices — 167,000 Applications, 76 Jobs Obtained

In 2024, a candidate for an AI architect position applied to Nisos, a cybersecurity firm based in Virginia. He stumbled through his answers, changed the subject when asked to share his screen, and claimed to live in Florida while his metadata placed him elsewhere. Nisos didn't reject him. Instead, the firm sent him a booby-trapped laptop, monitored every keystroke, and began ma

Premium reading
MadMax
Key takeaways
  1. In 2024, a candidate for an AI architect position applied to Nisos, a cybersecurity firm based in Virginia. He stumbled through his answers, changed the subject when asked to share his screen, and claimed to live in Florida while his metadata placed him elsewhere. Nisos didn't reject him. Instead, the firm sent him a booby-trapped laptop, monitored every keystroke, and began ma
  2. INVESTIGATION: Kim Jong-un Had His Hackers Inside Your Offices — 167,000 Applications, 76 Jobs Obtained
  3. Introduction: A Ghost Cell at the Heart of American Tech Companies
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

INVESTIGATION: Kim Jong-un Had His Hackers Inside Your Offices — 167,000 Applications, 76 Jobs Obtained

Introduction: A Ghost Cell at the Heart of American Tech Companies

The Moment Everything Changed for Nisos

In 2024, a candidate for an AI architect position applied to Nisos, a cybersecurity firm based in Virginia. He stumbled through his answers, changed the subject when asked to share his screen, and claimed to live in Florida while his metadata placed him elsewhere. Nisos didn't reject him. Instead, the firm sent him a booby-trapped laptop, monitored every keystroke, and began mapping what turned out to be one of the most sophisticated employment fraud operations ever documented against Western companies.

The report published on June 16, 2026 is explosive: a cell of 22 North Korean agents submitted at least 166,893 applications, secured 21,645 interviews and obtained 76 real job offers from American companies between December 2024 and September 2025. This isn't conventional cyberwarfare. It's industrial infiltration disguised as job-seeking.

A Network Structured Like a Business

The Democratic People's Republic of Korea leaves nothing to chance. According to Nisos, the cell operated with a formal hierarchy: administrators, managers, team leaders, field operators, and American facilitators — referred to as "natives" in internal communications — recruited on U.S. soil to physically participate in video interviews, manage employer-issued computers, handle drug screening tests, and facilitate administrative onboarding.

Internal communications flowed through Discord, Telegram, and WhatsApp. Agents used three-letter initials to protect their identities. Everything was conducted exclusively in English to avoid triggering foreign-language detection. Performance dashboards tracked application-to-interview-to-offer conversion rates, exactly like a sales center.

The Numbers That Reveal the Scale of the Operation

An Industrial Ratio: 7,586 Applications Per Operator

With 22 operators identified, each was responsible on average for 7,586 applications, 984 interviews, and 3.5 job offers. The application-to-interview conversion rate was 13%, which is remarkably high for a large-scale fraud. The interview-to-offer conversion rate remained low — 0.35% — but volume compensates for everything. These numbers are not the product of improvisation. This is pure volume, applied with factory-floor rigor.

The roles targeted were heavily concentrated in software development, engineering, and data — more than 70% of positions pursued. Targeted salaries ranged from $55,000 to $230,000 per year. The technology sector accounted for 42.6% of offers obtained, followed by consulting, healthcare, and financial services. The reason is simple: tech roles offer high salaries, a well-established remote work culture, and an often inadequate vetting process.

Two Convicted American Facilitators

In May 2026, the U.S. Department of Justice convicted two American citizens for their roles in separate but similar operations. Matthew Isaac Knoot, of Nashville, and Erick Ntekereze Prince, of New York, were each sentenced to 18 months in prison. Together, their operations had generated more than $1.2 million for the North Korean regime and compromised nearly 70 victim companies across the United States.

These convictions illustrate a central element of the system: without local facilitators, the operation doesn't function nearly as well. North Korean agents need Americans to receive laptops, appear at video interviews, and complete physical testing. This isn't science fiction — it's a human supply chain for fraud.

The Tools: AI, Deepfakes, and Laptop Farms

Artificial Intelligence in Service of Pyongyang

North Korean operators didn't rely solely on their own interview skills. They used accent training tools to mask their linguistic origins, remote access technologies to control computers from abroad — presumably from China or Russia — and AI-powered deepfakes during video interviews to present a convincing American face. According to Nisos, the infrastructure also included identity brokers, networks for buying and selling stolen identities of real Americans.

The laptop farm is the physical element that reveals the full ingenuity of the system. Companies ship their corporate equipment to a U.S. address — that of a paid facilitator. The facilitator connects the computer to the internet and allows the North Korean operator, thousands of miles away, to access it remotely. For the company, the geolocation is perfect. For authorities, it is nearly undetectable without targeted surveillance.

Operational Infrastructure Worthy of a Small Business

Nisos describes a Discord infrastructure organized into distinct channels: an applications channel, a training channel, an identity management channel, a performance channel. Agents received precise instructions on what questions to anticipate, what answers to prepare, and what software to master for common tech roles. This level of organization far exceeds what one would expect from an improvised criminal operation. It's a structured fraud enterprise with internal HR processes.

Payments to American facilitators were routed through ERC20 cryptocurrencies — traceable in theory, but difficult to follow in practice when wallets are multiplied and mixed. The ultimate goal is always the same: circumvent international sanctions and fund Kim Jong-un's weapons program, in particular the development of ballistic missiles and nuclear weapons.

Context: A Program That Has Industrialized Since 2020

From a Few Hundred to Thousands of Active Operators

The Nisos report documents a specific cell, but the phenomenon is far broader. According to the United Nations, North Korean IT workers generate between $250 million and $600 million per year for the regime, active in more than 40 countries. South Korea's National Intelligence Service reported that Pyongyang's cyber division grew from 6,800 agents in 2022 to 8,400 in 2024. CrowdStrike identified 45 distinct operations linked to North Korean IT workers in March 2026 alone — up from 33 in March 2025. The acceleration is massive.

The law firm Skadden published an analysis in June 2026 detailing the legal risks for companies that inadvertently hire these agents: potential sanctions violations, cybersecurity risks, criminal liability, and reputational damage. More than 40 individuals have been indicted by the DOJ in these operations, including American citizens, Chinese nationals, and Taiwanese nationals.

Operation Famous Chollima — The Name the Industry Won't Forget

CrowdStrike designates the operation under the name Famous Chollima — a reference to the winged horse of Korean mythology, a symbol of speed and power. The name is well chosen: the operation moves fast, very fast, and strikes everywhere at once. In 2025, the volume of attacks doubled compared to the previous year. The DOJ announced in June 2025 nationally coordinated actions including raids on 29 laptop farms across 16 states, the seizure of 29 financial accounts, and 21 fraudulent websites.

These operations are far from anecdotal. Some North Korean operators access sensitive systems, intellectual property data, and source code infrastructure. These are not merely salary scams — they are data theft vectors and potentially long-term sabotage tools for a regime that considers the West its principal enemy.

Victim Companies: How Did They Let This Slip Through

Remote Hiring Culture as a Blind Spot

The COVID-19 pandemic normalized remote work at a speed that security departments couldn't keep pace with. In 2020, tech companies massively adopted fully online hiring processes: résumés, video interviews, digital onboarding. For an operation like Famous Chollima, this was ideal terrain. There's never a handshake, never a photo badge, never a physical identity check. Just a convincing LinkedIn profile, a solid résumé, and an agent trained to ace technical interviews.

The warning signs documented by the FBI and Nisos are clear: refusal to appear on unplanned video, a background that never changes, requests for a specific laptop hosting service, inconsistencies in identity information, multiple workers connecting from the same IP address. These markers are known. But at a startup hiring 20 developers a month, who has the time to verify them all with this level of scrutiny?

The Financial Sector in the Crosshairs for 2026

According to Fortune and CrowdStrike, North Korean adversaries have become in 2026 the primary nation-state intrusion threat for companies in the American financial sector. Financial services firms, consumer banks, and their service providers are now in the crosshairs — far more sensitive targets than tech startups. Access to banking systems via infiltrated employees would represent a major qualitative leap for Pyongyang's illicit financing program.

The Nisos report of June 2026 may be the most detailed warning ever published on this type of operation. But the fact that it required Nisos to deliberately accept a suspicious agent, send him a booby-trapped laptop, and monitor his activities for months to obtain this data says everything about the difficulty of passive detection. Ordinary companies have neither the resources nor the counterintelligence culture to run this type of operation.

The Institutional Response: Between Targeted Prosecutions and a Lack of Systemic Framework

The DOJ Is Accelerating but It Isn't Enough

The Department of Justice has ramped up actions since 2024: indictments of North Korean, Chinese, and Taiwanese nationals, convictions of American facilitators, seizures of accounts and computer equipment. But these actions remain reactive: they intervene after operations have run for months or years. And for every cell exposed, how many others are quietly operating inside companies that didn't have Nisos's luck or instincts?

The FBI now offers a reward of $5 million for any information leading to the arrest of members of these networks. The FBI, State, and Treasury agencies have published joint advisories detailing red flags. But the tech startup ecosystem — with its hundreds of thousands of companies, decentralized hiring processes, and default-trust culture — is structurally difficult to protect through government advisories.

What Companies Can Concretely Do

The recommendations from Skadden and Nisos converge: require at least one physical verification before hiring, use deepfake detection tools during video interviews, ship computer equipment only to the address on official identity documents, tie corporate access to verified physical devices, analyze connection patternsinternal reporting systems. These measures are not technically complex. They mainly require an organizational will to take the risk seriously.

The real question is one of collective responsibility. Companies that inadvertently hire North Korean agents are not criminals — but they are objectively funding a weapons program that threatens regional and global security. There is a moral and strategic obligation to treat this risk with the same rigor as any other compliance or cybersecurity risk.

The Geopolitics Behind the Scheme: Sanctions, Missiles, and Regime Survival

A Program Indispensable for Funding Kim Jong-un

North Korea lives under one of the most severe international sanctions regimes in the world since the acceleration of its nuclear program. Legitimate exports are virtually nonexistent. The country depends on a combination of trafficking, cybercrime, and fraudulent employment operations to fund both the government and its weapons development. The remote IT worker program has become one of the most profitable and hardest-to-detect revenue streams.

The link between fraudulent salaries and intercontinental ballistic missiles is direct and documented. In 2026, Kim Jong-un personally visited a weapons production plant and called for multiplying missile production capacity by 2.5. He also inaugurated a new nuclear materials factory. This is no coincidence: revenues from cyberespionage and employment fraud directly feed these programs. The American tech companies that hired an agent from the Nisos cell were, unknowingly, contributing to this acceleration.

A Challenge to the International Order

This type of operation raises a fundamental question for the international order: how do you contain a state determined to circumvent all sanctions when its primary circumvention tool is indistinguishable from a normal employee? China and Russia host a large proportion of these operators — without the cooperation of both countries, any American judicial action remains structurally limited.

The international community is discussing information-sharing mechanisms between companies, between governments, and between sectors. But North Korea has a head start: it improves its tools and processes faster than regulators can document them. The Nisos report of June 2026 describes an operation that ran between late 2024 and late 2025. Meanwhile, new cells — with lessons learned from that cell's exposure, with new protocols, new AI tools, new identities — are almost certainly already at work.

The Next Phase: Toward More Sensitive Targets

From Tech Startups to Financial Institutions

The evolution documented by CrowdStrike is concerning: in 2025, the Famous Chollima operation not only doubled its volume, it also broadened its targets. Banks, insurance companies, fintechs, and asset managers are now explicitly in scope. An agent embedded in a financial institution has access to far more valuable data — payment systems, customer databases, SWIFT infrastructure, transaction data. The qualitative leap is considerable.

It is also likely that these operations will evolve toward extortion: an agent already in a position, with access to sensitive data, could threaten to leak it if their identity is about to be discovered. Cases of extortion by former North Korean IT workers have already been documented by the FBI — a logical evolution of the business model toward even higher revenues per operator.

AI as a Double-Edged Weapon

Artificial intelligence is at the heart of this war. It enables North Korean agents to generate applications in bulk, simulate convincing interviews, create coherent fictitious identities, and defeat standard verification systems. But AI can also be the tool of defense: real-time deepfake detection, behavioral analysis of work patterns, IP address correlation, advanced biometric verification. The question is who develops these defensive tools fast enough, and who deploys them at the scale of hundreds of thousands of companies.

The Nisos report concludes that the best protection remains a combination of active friction in the hiring process, physical identity verification, and an organizational culture that treats remote hiring as a security risk, not just an HR matter. This isn't a revolution — it's an adjustment. But it is urgent.

Conclusion: A Silent Economic War with No Visible Front

What the Nisos Report Changes — and What It Doesn't

The Nisos report published in June 2026 is the most detailed X-ray ever published of a North Korean employment fraud operation. It documents figures, processes, a hierarchy, and tools. It allows companies, regulators, and governments to understand exactly what they're facing. That's not nothing — information is the first line of defense.

But an X-ray is not a treatment. The cell described by Nisos operated between late 2024 and late 2025. It generated 76 jobs at real companies, accessed real systems, transferred real salaries to Pyongyang. Since the report's publication, new cells — having drawn lessons from this cell's exposure — are almost certainly active. The silent economic war continues. It has no visible front. It has no formal declaration. And for now, it has no strategic response commensurate with its scale.

The West Must Name the Enemy to Fight It

We need to call this operation what it is: an organized economic attack by an enemy state against Western companies. This is not ordinary cybercrime. It is not a marginal phenomenon. It is a strategic funding line for a nuclear weapons program that threatens regional stability in the Asia-Pacific and, ultimately, global security. The West cannot continue treating this threat as an HR compliance problem. It must treat it for what it is: a component of hybrid warfare waged by Pyongyang against liberal democracies, with China and Russia serving as its geographic and diplomatic umbrella.

By Maxime Marquette, columnist

Columnist's transparency note

Who I Am and My Acknowledged Biases

I am an independent columnist-analyst, not a cybersecurity expert or international criminal law specialist. My analysis rests on verified public sources — the Nisos report, DOJ press releases, CrowdStrike and Skadden analyses. I have no access to classified information. I am pro-liberal democracy and consider North Korea a dangerous and illegitimate regime. This bias shapes my analytical angle.

What I Don't Know

I do not know the identities of the 76 companies that offered employment to this cell. I don't know how many of these agents are still in position. I cannot assess the full extent of data that may have been compromised. The Nisos report documents one cell over a specific period — it is possible that other cells operate with different protocols, harder to document. The estimate of 22 operators is Nisos's, based on its investigation — other sources could give different figures for the program as a whole.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). INVESTIGATION: Kim Jong-un Had His Hackers Inside Your Offices — 167,000 Applications, 76 Jobs Obtained. MadMax. https://mad-max.co/en/article/enquete-kim-jong-un-avait-ses-hackers-dans-vos-bureaux-167-000-candidatures-76-e

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Investigation2836 words19 min read