In the first half of 2026, blockchain intelligence firm TRM Labs assessed that North Korean hackers stole around US$643 million in cryptocurrency, accounting for roughly 66 percent of tracked global crypto theft.
Scale: cryptocurrency theft and an industrialised revenue model
The figure from TRM Labs illustrates how Pyongyang has turned cyber activity into a repeatable revenue engine. The source describes North Korea’s approach as treating hacking “not only as an instrument of statecraft but as an industry,” combining large-scale cryptocurrency theft, bank heist operations and other cyber-enabled revenue generation into a reliable source of hard currency. Generative artificial intelligence, the source says, lowers the cost of running these already volumetric, fraud-driven models.
Fraudulent IT-worker operations and the rise of scale-enabled access
One of the clearest examples is the regime’s fraudulent IT-worker programmes. The source cites an estimate in which 22 operatives submitted at least 166,893 applications to US companies across 2024 and 2025, sat more than 21,000 interviews and secured at least 76 job offers. Australian firms are increasingly affected, “prompting the government to join a coalition of states in warning about these fraudulent workers.”
Generative AI reduces the cost of almost every stage of that operation, the source explains: tailoring English-language resumes and cover letters, sustaining convincing online personas built on synthetic faces and altered voices, and providing real-time assistance during technical interviews. For an operation built around volume, “AI does not need to create an exceptional candidate,” the source notes — a small increase in success rates becomes valuable when multiplied across hundreds of thousands of attempts.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageSoftware developers, compromised builds, and a researcher’s tally
Developers are a particularly attractive target. Security researcher Vangelis Stykas found North Korean hacking had affected 1,640 organisations across 57 countries, with between 700 and 800 of those organisations seriously compromised. Many operations began as fake recruitment approaches: developers were asked to complete coding exercises that secretly installed malware. Because developers often have privileged access to source code and build tools, initial footholds can be leveraged to steal intellectual property, insert backdoors or pivot to other networks.
The source emphasises how AI bolsters the social-engineering side of these operations: recruiter personas can be maintained more convincingly, outreach can be personalised at scale, and attackers can generate plausible responses to technical questions about coding tasks or requirements.
Open-source supply chains and the Amazon-linked compromises
In July, Amazon linked four previously separate code compromises to a North Korea-linked group, suggesting the activity is systematic rather than occasional. The source flags a second-order risk: as developers increasingly use AI-based coding assistants and automated review systems, attackers not only gain tools to modify code faster but also new avenues to exploit how software is written, checked and distributed. The blending of AI-assisted development and malicious code modification raises the prospect that routine development tooling may be weaponised in unexpected ways.
Ransomware, ecosystem ties, and asymmetric advantage
North Korea-linked actors have used ransomware for years, including against healthcare providers, and since 2024 have been connected to parts of the commercial ransomware ecosystem. The source finds limited evidence that AI has yet “materially transformed” these operations, but warns that coding assistants could make it easier for capable hackers to modify malware and adapt existing tools — producing faster iteration rather than fully autonomous ransomware.
One persistent asymmetry favours Pyongyang: “AI systems feed on data and bite hardest against open, densely digitised societies,” the source says. Little online information exists about North Korea’s people, systems and infrastructure, so the data-hungry tools the regime turns against others have less to work on when directed back at it. That imbalance amplifies the utility of AI as a force multiplier for deception and scale.
What this means for technologists, the Australian government, and affected enterprises
- Technologists and security teams: expect social-engineering attacks that leverage AI-assisted personas, automated outreach and AI-generated technical responses; developers and build systems are highlighted as priority controls because recruitment lures and coding exercises have been used to deliver malware.
- The Australian government: the source says the government has joined a coalition warning about fraudulent workers — signalling a policy posture that recognises the cross-border, revenue-driven nature of these campaigns and the need for international coordination.
- Affected enterprises and procurement leaders: software supply chains and remote hiring practices are prime risk vectors; the Amazon linkage and the scale of developer compromises in the researcher’s count underline that routine engineering interactions can be the delivery mechanism for both theft and espionage.
Across these threads, AI’s contribution is not advertised as a single, spectacular breakthrough. Rather, the source concludes, “the likely future is therefore not a spectacular, AI-enabled attack but the steady expansion of a cyber model whose strength lies in organisation, persistence and volume.” The challenge for defenders, accordingly, is less to anticipate one dramatic moment than to detect and disrupt an industrialised, AI-enabled fraud apparatus working at scale.




