North Korea Pushes Back Over AI-Powered Cyber Allegations

Pyongyang denies using fake IT workers to fund its weapons programs as U.S. allies warn of AI-powered infiltration campaigns

North Korea Rejects AI Cyber Threat Allegations

Illustration: Andre M. Chang/ZUMA Press Wire via Reuters Connect

North Korea has launched a public rebuttal against accusations that it is using overseas IT workers and cyber operations to generate revenue for its weapons programs — highlighting how cyber activity has become an increasingly important front in the confrontation between Pyongyang and Washington.

The statement, reported this week by North Korean state media KCNA, is notable because Pyongyang chose to directly address allegations surrounding its cyber operations. North Korea routinely rejects accusations from the United States and its allies, but its cyber activities have increasingly become a focus of international pressure alongside its nuclear and missile programs.

The response came after the United States, South Korea, Japan and eight other countries issued a joint warning accusing North Korean IT workers of using fake identities, artificial intelligence tools and remote jobs to infiltrate legitimate companies around the world and generate revenue for Pyongyang.

According to the advisory, the money earned through these schemes helps North Korea evade international sanctions and support its nuclear weapons and ballistic missile programs.

A North Korean foreign ministry spokesperson dismissed the allegations as “political accusations” and criticized the U.S.-led Multilateral Sanctions Monitoring Team (MSMT), which tracks sanctions violations.

“It is illogical that the U.S., which has possessed and operated the biggest cyber force in the world, is talking about cyber threats from other countries,” the spokesperson said, according to KCNA.

The international warning described increasingly sophisticated methods used by North Korean IT workers, including forged identity documents, third-party intermediaries, VPNs, remote desktop tools and AI-generated profiles designed to make them appear as legitimate foreign employees.

In some cases, the advisory said, operatives have used manipulated video during job interviews to create convincing false identities. Once hired, they can gain access to internal systems, sensitive data and company networks, creating a potential insider threat.

The rise of remote work has created a new opportunity for attackers, allowing them to target organizations not only through technical vulnerabilities but also by exploiting trust in the people who have access to their systems.

The warning comes amid broader concerns over North Korea’s expanding cyber capabilities. Amazon Threat Intelligence recently revealed research linking a North Korea-associated group to attacks targeting open-source software packages used by developers worldwide.

Amazon said the group compromised trusted software maintainers and inserted malicious code into popular developer libraries, potentially exposing thousands of organizations that relied on those packages.

Together, the incidents highlight a broader evolution in North Korea’s cyber strategy: combining human deception, artificial intelligence and software supply-chain attacks to gain access to foreign organizations.

The latest warnings reflect growing concern in Washington and allied capitals that North Korea’s cyber operations are becoming a central tool for generating revenue, collecting intelligence and expanding access to global networks — even as Pyongyang continues to deny the allegations.