Tech News
← Home  ·  All topics

North Korean

4 GoKawiil briefs on this topic

North Korean hacking group infects 30,000 devices via fake job recruiter schemes

Security researchers uncovered a North Korean state-linked hacking operation that impersonated job recruiters to trick victims into installing malware, ultimately compromising roughly 30,000 devices across multiple countries. The campaign used fake hiring processes and interview-related documents as delivery mechanisms for malicious software.

Employers Add Identity Checks to Hiring After AI Fraud Surge

Companies are introducing extra verification steps during job interviews to confirm candidates are genuine humans, not AI-assisted impersonators or fraudulent remote workers. The shift follows a rise in AI-generated deepfakes and schemes involving North Korean operatives posing as legitimate remote employees to infiltrate companies.

Huntress details how it caught fake North Korean IT workers in 2026 probes

Security firm Huntress published findings from investigations conducted throughout 2026 in which it helped organizations confirm they had unknowingly hired North Korean operatives posing as IT staff. Cases included an Australian healthcare firm that flagged three employees suspected of impersonating Chinese nationals, plus two separate incidents in the financial services sector uncovered in August. Huntress noted these DPRK-linked workers have grown more skilled and active, blending into IT teams while funneling wages back to the regime and potentially planting malware or stealing data.

Identity Verification Gaps at Hiring and Account Recovery Emerge as Major Attack Vector

A joint alert from the US State Department, Japan, Canada and the UK warns that North Korean operatives are using falsified identity documents to get hired as remote IT workers at foreign companies, letting them enter corporate networks with legitimate-looking access. Separately, groups like Scattered Spider have used social engineering against help desks to trick staff into resetting passwords or MFA for accounts they don't own, bypassing strong authentication entirely.