North Korea Deploys “Laptop Farms” in US to Steal Financial assets, Amazon Reveals
Amazon has blocked over 1,800 remote work applications suspected of being part of a North Korean scheme to circumvent UN sanctions and steal financial assets, highlighting a complex cyber operation leveraging a network of “laptop farms” within the United States.
The American tech giant detected a nearly one-third increase in suspicious applications over the past year, according to a recent post by Amazon security manager Stephen Schmidt on LinkedIn. These applications originate from individuals seemingly seeking remote IT positions, particularly within the US, but are believed to be controlled by operatives in North Korea.
The Rise of “Laptop Farms”
Behind these fraudulent profiles lie “laptop farms”: physical premises within the United states housing numerous computers remotely controlled from abroad. As Schmidt explained, this isn’t an isolated incident affecting only Amazon, but a widespread issue likely occurring across the entire industry.
The scheme allows North Korea to bypass international sanctions prohibiting its citizens from earning money overseas. A U.S. Army report from 2020 details the evolution of Pyongyang’s cyberwarfare programme, which now includes a 6,000-member unit known as Office 121, operating in multiple countries.
“North Korea is actively training cyber agents and infiltrating key sites around the world,” noted Hong Min, an analyst at the Korea Institute for National Unification in Seoul, in a statement to AFP.
Economic Motives Drive Cyberattacks
Given Amazon’s business model,the primary motivation appears to be economic. One analyst suggested a high probability that the operation aims to steal financial assets. This assessment aligns with recent actions by the U.S. government, which in November announced sanctions against eight individuals accused of being state-sponsored hackers involved in stealing and laundering money to fund North Korea’s nuclear weapons program.
The scale of these operations is significant. In July, an American woman received a sentence of over eight years in prison for operating a “laptop farm” that facilitated North Korean operatives in securing remote work at more than 300 American IT companies. Authorities estimate this system generated over $17 million for both the woman and the North Korean regime.
LinkedIn as a Recruitment Tool
Intelligence agencies are also tracking the use of professional networking platforms like LinkedIn. South Korean intelligence warned last year that North Korean agents are posing as recruiters on LinkedIn to target individuals in the South Korean defense sector for information gathering.
despite U.N. sanctions, North Korean IT specialists continue to find work internationally, often disguising their nationalities. A 2024 report from the U.S.-based organization 38 North claims these specialists have secured contracts for an estimated $200 million annually.
Cybercrime is considerable.According to the U.S. Treasury, cybercriminals affiliated with North Korea have stolen more than $3 billion over the past three years, primarily in cryptocurrencies. This ongoing activity underscores the evolving threat posed by North Korea’s cyber capabilities and the challenges in enforcing international sanctions in the digital age.
Why: North Korea is using cybercrime to circumvent international sanctions and generate revenue, primarily to fund its weapons programs and sustain its economy.
Who: The primary actors are North korean state-sponsored hackers, particularly
