What’s happening?
Okay, here’s the short, slightly terrifying version: threat operators linked to North Korea are no longer content with sneaking into the tech department — they’re applying for jobs in healthcare, sales, marketing, and other non-tech roles. These actors build fake lives, pass interviews, and actually do the work so they keep their cover while sending money back through convoluted channels. It’s not a Hollywood spy movie, but it is surprisingly organized and oddly persistent.
They use forged or stolen identity documents, consumer VPNs and proxy services, fake personas (sometimes generated with machine learning), and a network of helpers who keep laptops and accounts running. In some investigated cases, devices had remote KVM tools installed and even USB capture cards attached to make video look like a normal webcam — clever and creepy.
Investigators have spotted this operation showing up across hundreds of companies and industries. The campaign goes by several nicknames in threat reports, and multiple security firms and government agencies have raised alarms about the scale and sophistication. The operators lean on fake profiles, multi-account browsers, tracking spreadsheets, and off-the-shelf AI and transcription tools to ace interviews and produce believable work outputs.
How to spot and stop the fakes
If you hire people, congratulations — you’re a target. But you can make life harder for these schemers. Here are practical signs to watch for and actions to take (short, sharp, and useful):
- stolen IDs: Watch for identity documents that have odd fonts, mismatched metadata, repeating patterns, or photos that look like they were pasted. A little attention during onboarding goes a long way.
- Weird device behavior: unexpected remote KVM tools, USB capture cards, or unauthorized peripheral attachments are red flags — especially when installed right after account provisioning.
- Strange file habits: downloads from anonymous file-sharing services, oddly modified profile pictures, or GitHub accounts that seem cobbled together can indicate deception.
- Networking quirks: frequent use of consumer VPNs, proxies, or IP addresses that don’t match declared locations deserves scrutiny.
- Interview oddities: candidates who read answers off scripts, use real-time transcription/chatbots for replies, or display robotic but plausible competence could be leaning on automated help.
Defensive checklist (a.k.a. boring but effective):
- Strengthen identity checks: require verified documents, use video or in-person interviews when possible, and corroborate employment history and references.
- Limit onboarding privileges: don’t hand out full access or allow immediate use of payroll/banking tasks before background and compliance checks are complete.
- Harden endpoint controls: monitor for remote KVM tools, block or alert on unknown USB devices, and enforce company-issued hardware and MDM where practical.
- Log and investigate anomalies: unusual VPN/proxy usage, mismatched geolocation vs. claimed addresses, and odd internal meeting recordings should trigger follow-ups.
- Sanctions and money flow checks: validate vendor chains and payment destinations — hiring or paying someone tied to sanctioned networks can create serious legal exposure.
- Train the hiring team: teach recruiters to spot social-engineering tricks, verify identities thoroughly, and escalate suspicious cases instead of rushing hires.
One final thing: these actors are getting better by using automation and machine-assisted deception — chatbots, transcribers, and other tools help them answer technical questions convincingly. Keep an eye on unusual tool usage during interviews and onboarding, and treat any oddity like a lead to investigate. Slow hiring down if you have to — it’s a lot cheaper than a compliance headache later.
Yes, it’s annoying. But with careful checks, good device hygiene, and a few suspicious squints during interviews, organizations can make this scheme a lot less profitable — and a lot more frustrating for the bad guys.