Opens in a new tab
vmblog logo 2024 wht (updated)

State-Backed Cybercrime Will Look Like a Day Job

Share: 

David Marshall | Published: December 3, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Steve Stone, SVP of Threat Discovery and Research, SentinelOne 

State-sponsored hacking is no longer confined to the shadows of intelligence agencies or the covert infrastructure of military cyber units. Increasingly, it is blending into the white-collar labor market, disguising itself within the same global hiring ecosystems that legitimate technology professionals use every day. As more governments learn to weaponize talent marketplaces, remote-work platforms, and international contracting pipelines, the actions of cyber adversaries could become indistinguishable from those of legitimate workers in 2026. This shift represents not just an evolution of cybercrime, but a redefinition of how states project power, generate revenue, and infiltrate the private sector. 

The line between criminal enterprise and national agenda has already dissolved for the Democratic People’s Republic of Korea (DPRK). Recent SentinelLabs research into North Korea’s IT worker network has uncovered a threat ecosystem comprised of several hundred workers at major companies, including Fortune 500 companies, many of which operate in or through China. Additionally, more than a thousand job applications have been submitted this year by fabricated, DPRK-linked personas. These applications weren’t aimed solely at small firms or unsuspecting startups; many targeted established cybersecurity and software companies with mature hiring processes. The scale and sophistication of the operation reveal a cyber workforce that now blends state-directed espionage with gig-economy freelancing, using legitimate hiring pipelines to raise funds for the regime’s sanctioned weapons and intelligence programs. 

This threat-laden hybrid model is strategically efficient. Through infiltrating real companies under the guise of freelance developers, QA testers, or DevOps engineers, DPRK operatives gain direct access to valuable codebases, proprietary tools, and privileged systems. In tandem, they generate a steady income in hard currency, which is routed back to Pyongyang while appearing on paper as perfectly ordinary contract work. Unlike high-risk ransomware operations or headline-grabbing breaches that invite retaliation, this approach is quiet, distributed, and difficult to attribute. A fake resume in a stack of hundreds, a cloned LinkedIn profile with borrowed credentials, or a contractor working from an anonymized cloud instance rarely triggers the alarm bells that a traditional cyber intrusion might. 

What we are seeing from North Korea today is not an anomaly; it’s a preview. As sanctions continue to tighten, geopolitical competition intensifies, and global tech talent shortages persist, more states will adopt similar tactics. Why invest years cultivating clandestine access vectors when you can simply get hired? Why risk the exposure of a noisy cyberattack when you can secure permissions through HR, billing, and onboarding? The economic logic is compelling, the operational footprint is small, and plausible deniability is high. 

Soon, this model will become the playbook for state-sponsored revenue generation: cyber operators posing as freelancers, consultants, or remote contractors embedded across global tech ecosystems. These operatives will bid on development projects, manage cloud infrastructure, contribute to open-source libraries, or provide routine IT support, all while funneling intelligence, access, and earnings back to their sponsoring governments. This results in a threat landscape where the most dangerous adversary is not the one probing your firewall, but the one contributing pull requests to your repository. 

For organizations, the convergence of cybercrime and statecraft requires a recalibration of what an “insider threat” looks like and truly means. These insider incidents may not stem from a disgruntled employee or negligent mistake; instead, they may come from a highly trained operative who passed a video interview, supplied valid references, and performs their assigned tasks with professional competency until the moment they decide to pivot toward their fundamental objective. 

As nations increasingly mask covert cyber operations behind everyday job titles, the burden will fall on companies to strengthen their vetting processes, evaluate supply-chain risk in human labor as rigorously as they do in software, and adopt security models that assume trust must be continuously verified rather than granted at hire. The future of the workforce will be a battlefield in disguise, and recognizing that now is the first step in preparing for these threats in the future.   

## 

ABOUT THE AUTHOR

Steve Stone 

Steve Stone is currently the Senior Vice President of Threat Operations at SentinelOne, where he leads a team of industry experts focused on bad guys and breaches. This includes managed detection and response, SentinelLabs, incident readiness and response, detection engineering, and threat hunting. 

His expertise is frequently highlighted in various media outlets, including Forbes, the New York Times, Bloomberg, and the BBC. He is a regular speaker at prominent industry forums such as RSA, Gartner, and BlackHat. Steve has also provided sworn testimony on cyber threats to both the Senate Armed Services Committee and the House Permanent Select Committee for Intelligence. His achievements include guiding two teams to win the NSA’s Rowlett Award, being recognized as the Defense Intelligence Agency Analyst of the Year, earning multiple Department of Defense Senior Civilian of the Year awards, and being a listed author for several National Intelligence Estimates. 

Steve holds a Bachelor of Science in Anthropology from the University of Illinois, a Master of Science in Emergency Management from Jacksonville State University, and a Master of Science in Information Design and Strategy from Northwestern University. He served as an adjunct faculty member at McKendree University and a Board Member for Missouri State University’s CX program. He actively contributes to multiple industry groups, including serving as a Board Member for the Financial Services Information Sharing and Analysis Center, Foresight Institute (AGI: Cryptography, Security, and Multipolar Scenarios), and the Data Security Maturity Model Working Group.