logo

North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees

ID: 028a9b38-781d-542b-badc-88284c7ba23a

STIX ID: report--028a9b38-781d-542b-badc-88284c7ba23a

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: Guru Baran

...
...

Researchers created a fake DeFi company to hire and monitor DPRK-linked operatives and observed a persistent insider-infiltration campaign: operatives used AI-forged IDs and stolen identities to pass hiring checks, installed remote-access tools (Google Remote Desktop, AnyDesk), routed activity through AstrillVPN and proxies, used ChatGPT/live-translation for development, and exfiltrated credentials and browsing histories — demonstrating a sophisticated, long-term insider threat model tied to Famous Chollima/Lazarus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.