North Korean IT Worker Used Stolen Identity, AI-Generated Resume in Job Scam
ID: 68e5b113-8fb3-5714-833d-bfbacd73d984
STIX ID: report--68e5b113-8fb3-5714-833d-bfbacd73d984
Feed Name: GBHackers
A suspected North Korean IT operative attempted to infiltrate a U.S. threat intelligence firm using stolen identity and an AI-generated resume, leveraging Astrill VPN anonymization, PiKVM-based remote control hardware, and a Tailscale mesh network to manage a laptop farm of dozens of devices tied to multiple employee identities; investigators observed device activation and camera evidence and recommend stronger pre-employment OSINT and technical screening to mitigate this evolving DPRK remote workforce fraud and espionage technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
