North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
ID: 028a9b38-781d-542b-badc-88284c7ba23a
STIX ID: report--028a9b38-781d-542b-badc-88284c7ba23a
Feed Name: cybersecurityNews.com
Researchers created a fake DeFi company to hire and monitor DPRK-linked operatives and observed a persistent insider-infiltration campaign: operatives used AI-forged IDs and stolen identities to pass hiring checks, installed remote-access tools (Google Remote Desktop, AnyDesk), routed activity through AstrillVPN and proxies, used ChatGPT/live-translation for development, and exfiltrated credentials and browsing histories — demonstrating a sophisticated, long-term insider threat model tied to Famous Chollima/Lazarus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
