logo

New North Korean AI Hiring Scheme Targets US Companies

ID: ba009bf0-3efd-56b1-af84-6329564705d6

STIX ID: report--ba009bf0-3efd-56b1-af84-6329564705d6

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

A suspected DPRK-linked operator attempted to secure remote employment at a cybersecurity firm using stolen identities, AI-generated résumés, fake LinkedIn profiles, and anonymized infrastructure; investigators uncovered signs of a broader campaign including clustered corporate laptops (a "laptop farm"), PiKVM hardware-level remote control, Astrill VPN and Tailscale use, and VoIP number spoofing. Pre-hire OSINT and targeted interview techniques exposed behavioral and technical red flags, and the report recommends layered pre-hire validation, least-privilege onboarding, device controls, and ongoing monitoring to mitigate such hiring pipeline insider threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.