Log in
/
January 1, 202141 reports

Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.

Deployers
Yang Di
WaterPlum
Wagemole
Void Dokkaebi
UNC5267
Son Un Chol
Sok Kwang Hyok
Sim Hyon-Sop
Rim Un Chol
Ri Kyong Sik
Reconnaissance General Bureau
PurpleBravo
North Korean threat actors
Minh Phuong Ngoc Vong
Matthew Isaac Knoot
Lazarus Group
Ko Chung Sok
Kim Ye Won
Kim Sang Man
Kim Ryu Song
Kim Mu Rim
Jong Song Hwa
Jong Kyong Chol
Jang Chol Myong
Hyon Chol Song
Gwisin Gang
Government of North Korea
Famous Chollima
Department 53
Contagious Interview
Christina Chapman
Choe Jong Yong
Cho Chung Pom
Developers
Unknown large language model developers
Unknown deepfake technology developers
OpenAI