ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta

North Korean IT Workers Use AI and Remote Desktop Tools to Fake Technical Interviews

mediumThreat actorimportance 60
AI summary · glm-5.3-flash

Silent Push links a Discord recruitment scheme to North Korean IT workers using AI, remote desktop tools and on-camera proxies to pass technical interviews.

Silent Push assessed with moderate-to-high confidence that a representative known as Tec Guru, recruiting on-camera proxies via a Mouse Review Discord advertisement, is a North Korean IT worker. The scheme proposed a 65/35 revenue split with the hidden worker, live coaching through Google Meet, AI tools including ChatGPT to fill knowledge gaps, and remote access tools such as AnyDesk, TeamViewer, and Chrome Remote Desktop during coding exercises. Fraudulent hires can gain insider access enabling data theft, extortion, payroll fraud, and sanctions exposure; a July 31, 2026 multinational warning urged stronger identity checks and payment scrutiny.

  • Silent Push assessed 'Tec Guru' as a North Korean IT worker with moderate-to-high confidence.
  • Scheme offered a 65/35 split with on-camera proxies, live Google Meet coaching, and ChatGPT for knowledge gaps.
  • Remote tools AnyDesk, TeamViewer, and Chrome Remote Desktop could let off-screen operators complete coding tests.
  • Risks include insider access, data theft, extortion, payroll fraud, and sanctions exposure for employers.
  • IoCs: Discord account tecguru113 and Telegram handle @tecguru0618; Astrill VPN and US-style VoIP number noted.
Full article812 words · extracted from cybersecuritynews.com · click to collapse

North Korean operators are using artificial intelligence, remote-control software, and hired stand-ins to make fraudulent job candidates look genuine during technical interviews.

The scheme turns routine hiring into a route for sanctions evasion, payroll fraud, data theft, and access to company systems. The activity surfaced through a job advertisement posted in the Mouse Review Discord community.

It sought people in the United States, Europe, and Latin America who would appear on camera, communicate with employers, and lend their local identities to a remote worker operating behind the scenes.

Silent Push said in a report shared with Cyber Security News (CSN) that the recruitment channel and engaged the person behind it using a controlled persona.

The researchers assessed with moderate to high confidence that the representative, known as Tec Guru, was a North Korean IT worker, based on technical references, operational details, and observed language patterns.

This is not a conventional malware campaign, but it creates a serious entry point for later abuse. A company can unknowingly hire someone whose interview performance, identity, location, and work are supplied by others, then grant them access to sensitive systems.

North Korean IT Workers Use AI and Remote Desktop Tools

The advertisement described a proxy arrangement in unusually direct terms. A local participant would turn on a camera, speak with clients, and present the required skills, while the real operator supplied help in real time. The pitch proposed a 35 percent share for the proxy and 65 percent for the hidden worker.

For employers, that arrangement makes remote interviewing unreliable as an identity check. In a related case involving AI resume identity fraud, a suspected operative allegedly used forged career material and a VoIP number to pursue a remote position.

Job recruitment scam web page (Source – Silent Push)

Silent Push said the operator offered live coaching through Google Meet and proposed using AI tools, including ChatGPT, to fill knowledge gaps while the proxy remained on screen.

The plan also involved remote access during coding exercises, allowing another person to complete work while the visible candidate kept the conversation moving.

Tools such as AnyDesk, TeamViewer, and Chrome Remote Desktop can make that handoff easier when an interviewer is focused only on a shared screen.

The same concern appeared in reporting on forged IDs remote desktops, where remote-management software was linked to efforts to hide the real worker’s activity.

The representative advised the researchers to use Astrill VPN. The recommendation, along with Telegram and a US-style VoIP number, was part of the operational picture, not proof alone.

Hiring Controls Must Match the Risk

The immediate danger is not limited to a weak interview. Once a fraudulent worker is hired, the organization may face an insider who can copy proprietary code, collect sensitive information, or demand money in exchange for not publishing stolen material.

Payments can also be routed through a proxy’s bank account before funds are transferred onward. Companies may also face sanctions exposure if they unknowingly pay a North Korean worker through an intermediary.

A July 31, 2026 multinational warning urged stronger identity checks and scrutiny of payment anomalies, a concern also covered in warnings on North Korean workers.

Hiring teams should verify a candidate’s physical location with independent checks, confirm that identification documents and payment details match, and treat unusual account changes as warning signs.

Live interviews should include managed video verification and technical exercises that can detect outside assistance, rather than relying on a single camera feed.

Security teams should also limit new hires to the access needed for their role, monitor early account activity, and investigate unexpected remote-control tools or prolonged sessions.

These precautions matter because fake-worker operations can overlap with recruiter-led attacks, including North Korean worker campaigns that use malicious coding tasks against job seekers. The investigation shows how easily a fraud operation can blend social engineering with common workplace technology.

Organizations should treat recruitment as part of their security perimeter: verify the person, verify the location, and ensure that the person completing the interview is the one who will receive access after hiring.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Discord accounttecguru113Account reported as posting the fraudulent recruitment advertisement
Discord account ID1453753519436861505Identifier associated with the tecguru113 account
Telegram handle@tecguru0618Account used by the representative contacted during the investigation

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/north-korean-it-workers-2/