North Korean IT Workers Exploit AI and Remote Desktop for Fraudulent Hiring
North Korean actors are using AI tools and remote desktop software to facilitate fraudulent job candidates in technical interviews, aiming to bypass sanctions and commit payroll fraud.

North Korean operators have devised a sophisticated scheme to circumvent international sanctions and engage in payroll fraud by leveraging artificial intelligence and remote-control software to present fake candidates during technical interviews. This operation, uncovered by researchers at Silent Push, involves hiring local individuals to appear on camera while a remote North Korean worker provides real-time assistance and completes technical tasks.
The scheme surfaced through a job advertisement posted in a Discord community, seeking individuals in the United States, Europe, and Latin America. These local participants were tasked with appearing on camera, communicating with potential employers, and lending their identities to a remote operator. The proposed profit-sharing model offered 35% to the local proxy and 65% to the hidden worker, highlighting the illicit nature of the operation.
Researchers, with moderate to high confidence, identified the representative behind the advertisement, known as 'Tec Guru,' as a North Korean IT worker. This assessment was based on technical references, operational details, and observed language patterns. While not a conventional malware campaign, this method creates a significant entry point for malicious actors to gain access to sensitive company systems by placing compromised individuals within an organization's workforce.
The advertisement explicitly detailed a proxy arrangement where the local participant would handle the visual and verbal aspects of the interview, while the actual operator would provide assistance. This setup makes traditional remote interviewing unreliable as an identity verification method. In a related incident, a suspected operative allegedly used forged career materials and a VoIP number to pursue a remote position, further underscoring the deceptive tactics employed.
Silent Push reported that the operator suggested using AI tools, including ChatGPT, to fill knowledge gaps during the interview. Furthermore, the plan involved using remote access tools such as AnyDesk, TeamViewer, and Chrome Remote Desktop during coding exercises. This allowed the remote North Korean worker to complete technical tasks while the visible candidate maintained the conversation, effectively masking the true identity and capabilities of the applicant.
The immediate danger extends beyond a flawed interview process. Once a fraudulent worker is hired, they can potentially exfiltrate proprietary code, steal sensitive information, or engage in extortion. Payments can also be routed through the proxy's bank account before being transferred onward, complicating financial tracing. Companies risk sanctions exposure if they unknowingly compensate North Korean workers through intermediaries.
To counter such threats, organizations are urged to implement robust hiring controls. This includes verifying a candidate's physical location through independent checks, ensuring identification documents and payment details align, and treating unusual account changes as red flags. Live interviews should incorporate managed video verification and technical exercises designed to detect external assistance, rather than relying solely on a single camera feed.
Security teams should also enforce the principle of least privilege, granting new hires only the access necessary for their roles. Monitoring early account activity and investigating any unexpected remote-control tools or prolonged sessions are crucial steps. These precautions are vital as fake-worker operations can intersect with other malicious activities, such as North Korean campaigns that use deceptive coding tasks to target job seekers.