
AI is changing how states operationalise their cyber capabilities. In North Korea’s case, it’s transforming the country into a bigger cyber power by helping Pyongyang expand what it already does: generate revenue, obtain trusted access and collect intelligence at extraordinary scale.
North Korea has built one of the world’s most unusual state cyber programs, treating hacking not only as an instrument of statecraft but as an industry. Its operations combine cryptocurrency theft, fraudulent overseas IT employment and other forms of cybercrime with longstanding espionage against foreign defence, aerospace, government and policy targets. AI fits naturally into this model because its greatest value is in lowering the cost of running existing fraudulent models.
The scale of North Korea’s malicious cyber activity is already remarkable. In the first half of 2026, blockchain intelligence firm TRM Labs assessed that North Korean hackers stole around US$643 million (A$900 million) in cryptocurrency, accounting for roughly 66 percent of tracked global crypto theft. Pyongyang has effectively industrialised cyber-enabled revenue generation, from large-scale cryptocurrency theft to bank heist operations. It’s turning capabilities once associated with intelligence services and transnational criminal organisations into a reliable source of hard currency. AI makes this considerably more efficient.
This is most prominent in North Korea’s fraudulent IT-worker operations, in which nationals win legitimate remote IT jobs using fabricated or stolen identities, drawing salaries that benefit the regime while gaining trusted access to the systems they are hired to build. One estimate has found that as many as 22 operatives submitted at least 166,893 applications to US companies across 2024 and 2025, sat more than 21,000 interviews and secured at least 76 job offers. Australian firms are also increasingly affected, prompting the government to join a coalition of states in warning about these fraudulent workers.
Generative AI reduces the cost of almost every stage of that operation: tailoring English-language resumes and cover letters, maintaining convincing online personas built on synthetic faces and altered voices, and supplying real-time assistance during technical interviews. For an operation built around volume, AI does not need to create an exceptional candidate. Even a small increase in the proportion of applications that reach employers become valuable when multiplied across hundreds of thousands of attempts.
The technology is also supporting similar North Korean operations targeting software developers. After gaining access to North Korean hacking infrastructure, security researcher Vangelis Stykas found that North Korean hacking had affected 1,640 organisations across 57 countries. Between 700 and 800 of those organisations were seriously compromised. Many of those operations began as fake recruitment approaches, with developers asking to complete coding exercises that secretly installed malware.
Developers are particularly attractive targets because their work often gives them privileged access to source code, sensitive systems, and the tools used to build and distribute software. AI makes the surrounding social manipulation for these attack cheaper and more scalable. Recruiter personas can be maintained more convincingly, outreach can be personalised and hackers can generate plausible responses to developers’ questions about coding tasks or technical requirements.
The regime is pushing further still, now into open-source software supply chains. In July, Amazon linked four previously separate code compromises to a North Korea-linked group, suggesting this activity to be systematic rather than occasional. Here, AI creates a second-order problem. Not only do generative tools help attackers modify code faster, but AI-based coding assistants and automated review systems are increasingly becoming a routine part of software development. As developers become more reliant on these tools, attackers may also find new ways to exploit how software is written, checked and distributed.
As the boundary between revenue generation and espionage continues to blur, a foothold obtained for one purpose can serve another. For instance, in August, researchers linked a campaign targeting defence and aerospace organisations in France, Germany, Brazil and India to a North Korea-linked hacking group. The attackers relied on familiar methods: fake recruitment, compromised developers and malware delivered through apparently ordinary professional exchanges. The campaign’s goal was espionage, but its techniques closely resembled those used in North Korea’s financially motivated operations.
This incident shows why AI-enabled recruitment fraud has consequences beyond employment scams. The same tools that manufacture applications and personas can strengthen scams and recruitment lures, while also allow attackers to gain access to sensitive organisations, where that access can later support espionage.
The use of ransomware – software that holds data for ransom – is a less established version of the same model. North Korea-linked hackers have used ransomware for years, including against healthcare providers, and since 2024 has been connected to parts of the commercial ransomware ecosystem. Evidence that AI has materially transformed these operations remains limited, but coding assistants could make it easier for capable hackers to modify malware and adapt existing tools. The likely effect is faster iteration rather than autonomous ransomware.
One asymmetry runs in Pyongyang’s favour: AI systems feed on data and bite hardest against open, densely digitised societies. These societies describe North Korea’s targets far better than North Korea itself. Little information about the country’s people, systems and infrastructure exists anywhere, still less online, so the data-hungry tools the regime turns against others find little purchase when pointed back at it.
This is what makes AI particularly valuable to Pyongyang. It makes a system already built around repetition, deception and scale cheaper and more effective. The likely future is therefore not a spectacular, AI-enabled attack but the steady expansion of a cyber model whose strength lies in organisation, persistence and volume.
Leave a comment