ZeroHour
GBHackerspublished ()ingested Mayura Kathir
Part of a story covered by 2 sources: “North Korean IT Workers Use AI, On-Camera Proxies and Remote Desktop Tools to Pass Technical Interviews” — merged summary and timeline →

North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer

mediumPhishing & fraud exploited in the wildimportance 60
AI summary · glm-5.3-flash

Silent Push found North Korean IT workers recruiting on-camera proxies for job interviews while remotely controlling the computer, defeating identity and location checks.

Silent Push researchers engaged the "Tec Guru" persona via Discord and Telegram and assessed with moderate-to-high confidence that the operator is a North Korean IT worker recruiting on-camera proxies in the US, Europe, and Latin America for a 35/65 revenue split. During Google Meet interviews, the proxy stays on camera while the real worker supplies answers via ChatGPT-generated prompts, real-time messaging, or remote-control tools such as AnyDesk and TeamViewer. Successfully placed workers can access source code, cloud tenants, and CI/CD systems, and payments create sanctions exposure; the US, Japan, South Korea, and eight other governments issued a joint identity-verification alert on July 31, 2026.

  • Operator offered a 35/65 revenue split to identity proxies recruited via a "Mouse Review" Discord ad.
  • Real worker coaches the proxy or remotely controls their machine during coding tests using AnyDesk or TeamViewer.
  • Recommended Astrill VPN, a service Silent Push previously linked to North Korean threat-actor infrastructure.
  • July 31, 2026 joint alert from the US, Japan, South Korea, and others urged stronger identity verification.
Full article786 words · extracted from gbhackers.com · click to collapse

North Korean IT-worker operators are recruiting foreign nationals to sit on camera during remote job interviews.

At the same time, the real candidate provides answers, completes coding tasks, or remotely controls the proxy’s computer, according to new research from Silent Push.

The campaign turns ordinary job seekers into identity and payment intermediaries, creating a direct route around location checks, hiring controls, and sanctions screening.

The ad was allegedly promoted by the Discord account tecguru113, associated with Discord ID 1453753519436861505, and directed interested parties to Telegram account @tecguru0618.

Researchers engaged the operator using a controlled persona and assessed, with moderate to high confidence, that the individual behind the “Tec Guru” persona was a North Korean IT worker.

The scheme is built around “front” or facilitator recruitment. Rather than merely using stolen résumés or fabricated identities, the suspected operator sought real people in the United States, Europe, and Latin America to serve as the visible applicant during the hiring process.

The proxy is expected to turn on a webcam, communicate with recruiters, present a legitimate regional identity, receive salary payments through a local bank account, and represent technical skills they may not possess.

In exchange, the operator reportedly offered a 35/65 revenue split: 35% for the person lending their identity and 65% for the hidden IT worker.

This arrangement can defeat several standard controls at once.

A video interview may confirm that a real person is present, but it does not prove that the person on camera is the person completing the technical work, accessing the company environment, or ultimately receiving the employment income.

Silent Push found that the operator described a coordinated interview-fraud process.

During live assessments, the proxy could remain on camera and continue speaking with the employer while the real IT worker supplied answers through messaging, coached the proxy in real time, or remotely accessed the proxy’s device to complete coding exercises.

Job recruitment scam web page (Source : Silent Push).
Job recruitment scam web page (Source : Silent Push).

Silent Push traced the activity, to a suspicious recruitment advertisement posted in the “Mouse Review” Discord community, an unlikely venue focused on computer-mouse reviews.

Proxy Interview Scam

The operation reportedly referenced Google Meet for live assistance, AI tools such as ChatGPT to generate prompts or bridge technical knowledge gaps, and remote-access capabilities for coding tests.

Tools commonly abused in these scenarios can include AnyDesk, TeamViewer, and Chrome Remote Desktop, although organizations should focus on suspicious behavior rather than treating any specific remote-support product as malicious by default.

In its exchange with the persona, Silent Push also asked for VPN guidance. “Tec Guru” recommended Astrill VPN, a service the company has previously linked to North Korean threat-actor infrastructure and usage patterns.


During our conversation, we asked the threat actor about VPNs (Source : Silent Push).
During our conversation, we asked the threat actor about VPNs (Source : Silent Push).

That reference alone does not establish attribution, but combined with technical, financial, operational, and linguistic indicators, it contributed to the researchers’ assessment.

The consequences extend beyond a failed hiring process. A successfully placed worker may receive access to source code repositories, cloud tenants, CI/CD systems, customer data, internal collaboration platforms, and proprietary intellectual property.

The deceptive identity layer also complicates incident response because authentication records may point to a legitimate-looking employee while the actual work is performed elsewhere.

There is also a compliance dimension. U.S. authorities and international partners have warned that North Korean IT workers use false identities and remote employment to generate revenue for the country’s unlawful nuclear and ballistic-missile programs.

Organizations that knowingly or unknowingly facilitate payments may face significant sanctions exposure, depending on the facts and applicable jurisdiction.

On July 31, 2026, the United States, Japan, South Korea, and eight other governments issued a joint alert urging companies and online platforms to strengthen identity-verification practices and detect inconsistencies involving account details, contact information, and salary-payment accounts.

Companies should treat remote hiring as an identity-security process, not solely an HR workflow.

Effective checks include independently validating the applicant’s physical location, using unscheduled video verification, requiring candidates to perform live and unscripted tasks, and confirming that the individual who interviewed is the person who later receives and uses the corporate device.

Security teams should also monitor for unusual VPN use, remote-desktop installation attempts, impossible-travel events, concurrent sessions from different regions, abrupt changes to bank-account information, and access patterns inconsistent with a worker’s stated location.

The key warning is simple: a live camera feed is no longer sufficient proof of who is actually behind the keyboard.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/proxy-interviews-scam/