Follow the Money: Corporate Paychecks to DPRK Remote IT Workers Routed to Sanctioned Military Program Accounts
Where does the paycheck go when a company mistakenly hires a North Korean (DPRK) worker for a remote IT role? To a sanctioned entity that procures for North Korea’s military programs, according to new research from security firm DTEX.
The FBI began warning private companies in 2022 about the DPRK remote worker program, which exploits vulnerabilities in corporate hiring processes to implant North Korean agents into foreign workforces and onto the payroll until they are detected. In some instances, the time between onboarding and termination can take months.
While experts theorized that the money the DPRK collected through this scheme went to finance its weapons of mass destruction (WMD) and ballistic missile programs—violations of UN Security Council sanctions—it was difficult to know for sure. Now, however, DTEX’s i3 team has shared documentation of where these remote workers’ paychecks really end up.
“Workers reported each payment to a single administrator account, moved it through cryptocurrency and Chinese financial channels, and sent it up the chain,” explained DTEX CEO and CTO Marshall Heilman in a LinkedIn post. “In one three-month window spanning late 2025 into early 2026, around $1.97 million flowed through what we assess to be Korea Ryonbong General Corporation, a sanctioned entity that procures for the regime’s military programs.”
DTEX’s threat brief, authored by Principal i3 Insider Risk Investigator Michael Barnhart, explained that the DPRK leadership then uses this pooled money to fulfill specific mandates—including weapons funding.
“For anyone still asking, ‘so what?’ or ‘is it really that bad?’ follow the money,” Barnhart wrote. “Western salaries paid to DPRK IT workers are funneled through front companies into weapons manufacturing and procurement and can then supply efforts we weren’t really factoring in, such as Russia’s war effort.”
North Korea signed a mutual defense pact with Russia in 2024, providing military troops, engineers, deminers, and drone operators in Russia’s Kursk region. North Korea has also supplied Russia with missiles, which Reuters reports it used to attack Ukrainian targets as recently as 30 July 2026.
“A military source, who requested anonymity because of the sensitivity of the matter, said Ukrainian radars had picked up two missile tracks characteristic of North Korean KN-23 or KN-24 short-range ballistic missiles flying towards Kryvyi Rih during the attack,” according to Reuters.
On 21 August, Military Watch Magazine reported that Russia received its first shipment of North Korean KN-30 ballistic missiles.
“Ukrainian intelligence says that approximately 90 North Korean military personnel have deployed to Russia’s Voronezh Oblast, where they are expected to operate up to six launchers, raising questions regarding whether the missiles are being exported to Russia, or simply represent part of Pyongyan’s contributions to its neighbor’s war effort,” Military Watch Magazine wrote.
Hundreds of Fortune 500 companies have mistakenly hired North Korean IT workers during the past several years. The Multilateral Sanctions Monitoring Team estimated in October 2025 that DPRK cyber actors and IT workers have stolen more than $2.8 billion in cryptocurrency since January 2024 and earned an estimated $350 to $800 million in revenue in 2024.
The movement of this corporate money to a sanctioned entity is just one reason why the DPRK remote worker problem is now a boardroom issue, Heilman wrote.
“No company sets out to bankroll a foreign weapons program, but that’s the position you can quietly end up in, and the problem compounds,” he explained. “The scheme works because it’s spread thin across thousands of unwitting employers, so every company that treats it as someone else’s issue sends a little more money up the chain.”
It can also expose companies to sanction violations penalties, since the DPRK’s WMD and ballistic missile programs are subject to both U.S. and UN sanctions. The U.S. Department of State and FBI issued a joint alert on 31 July 2026, joined by agencies from Australia, Canada, France, Germany, Italy, Japan, The Netherlands, New Zealand, and the United Kingdom on the DPRK remote worker scheme. They warned that under UN Security Council Resolution 2397, all UN Member States must repatriate to North Korea all North Korean nationals earning income in that member state’s jurisdiction.
“Additionally, contracting with North Korean IT workers and paying them for services rendered may also violate the domestic laws of many countries, including Japan, the United States, and the Republic of Korea, and may result in legal consequences or financial penalties,” the alert said.
No company sets out to bankroll a foreign weapons program, but that’s the position you can quietly end up in, and the problem compounds.
Along with this risk, companies that employ DPRK remote workers also open themselves to the threat of corporate espionage or ransomware, DTEX’s Heilman explained.
“So, this is not a payroll curiosity or a story for the security team to handle quietly,” Heilman explained. “It’s a business risk that touches national security, and it belongs in the same conversation as any other threat that could stop a company in its tracks.”
At the Black Hat security conference in Las Vegas in August 2026, for instance, cybersecurity researcher Vangelis Stykas released his latest work which found that the DPRK remote worker scheme had impacted 700 to 800 organizations in significant ways.
“It’s company access, it’s root access to servers, its root access to [Amazon Web Services],” Stykas told WIRED in a preview of his research. “For crypto companies, it’s keys, it’s blockchain access—it’s ridiculous access.”








