{"id":106899,"date":"2026-08-02T11:54:06","date_gmt":"2026-08-02T11:54:06","guid":{"rendered":"https:\/\/www.europesays.com\/korea\/106899\/"},"modified":"2026-08-02T11:54:06","modified_gmt":"2026-08-02T11:54:06","slug":"north-korean-it-workers-use-real-time-deepfakes-to-beat-hiring-checks-eleven-nations-warn","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/korea\/106899\/","title":{"rendered":"North Korean IT Workers Use Real-Time Deepfakes to Beat Hiring Checks, Eleven Nations Warn"},"content":{"rendered":"<p>Your video interview screening process is no longer a reliable identity check. On July 31, 2026, the governments of <a href=\"https:\/\/www.state.gov\/releases\/office-of-the-spokesperson\/2026\/07\/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers\/\" rel=\"nofollow noopener\" target=\"_blank\">eleven allied nations<\/a> \u2014 including the United States, Japan, South Korea, and, for the first time, France, Germany, Italy, and the Netherlands \u2014 issued a coordinated alert warning companies globally that North Korean IT operatives are now using real-time AI deepfake video to impersonate real people during live job interviews, bypassing the one control that most hiring teams believed would catch them. The advisory names the mechanism specifically: video feeds that &#8220;appear to be manipulated or artificially generated&#8221; during conference calls, deployed by operatives working from North Korea, China, Russia, Southeast Asia, and Africa while appearing to sit in US home offices. The scheme funneled <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0416\" rel=\"nofollow noopener\" target=\"_blank\">approximately $800 million to Pyongyang&#8217;s nuclear weapons and ballistic missile programs<\/a> in 2024 alone.<\/p>\n<p>Deepfake Video Has Broken the Live Interview Screen<\/p>\n<p>The failure mode that eleven governments felt compelled to name jointly is specific and technically significant. North Korean operatives working under the umbrella of what cybersecurity firm CrowdStrike tracks as FAMOUS CHOLLIMA are not using pre-recorded videos or static image substitutions \u2014 techniques that liveness detection can flag. They are using real-time video inference: a deepfake model running live during a call, mapping a stolen or synthetic face onto the operative&#8217;s actual video feed and routing the output through a virtual camera driver that the video-conferencing platform treats as a normal webcam. The result is <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/crowdstrike-2026-technology-threat-landscape-report\/\" rel=\"nofollow noopener\" target=\"_blank\">indistinguishable from a normal video call<\/a> to a hiring manager who is not specifically probing for AI artifacts.<\/p>\n<p>CrowdStrike&#8217;s 2026 Technology Threat Landscape Report documented that <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/crowdstrike-2026-technology-threat-landscape-report\/\" rel=\"nofollow noopener\" target=\"_blank\">FAMOUS CHOLLIMA accounted for 47% of all state-sponsored hands-on-keyboard intrusions<\/a> against US technology companies in the twelve-month period ending March 2026 \u2014 making North Korean operatives the single largest state actor in direct-access corporate infiltration. The group&#8217;s method is to apply for remote developer, coder, and IT specialist positions using AI-generated resumes, portfolio websites, and cover letters crafted by large language models, pair that with a deepfake video identity during the interview, and then, once hired, use the access to steal source code, harvest credentials, and \u2014 when detected \u2014 <a href=\"https:\/\/www.ic3.gov\/PSA\/2025\/PSA250123\" rel=\"nofollow noopener\" target=\"_blank\">extort the company by threatening to release proprietary code publicly<\/a>.<\/p>\n<p>The AI component extends beyond the video call. <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/06\/ai-as-tradecraft-how-threat-actors-operationalize-ai\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Threat Intelligence reported in March 2026<\/a> that NK operatives now use large language models to shorten the time required to construct a convincing synthetic identity from days to hours \u2014 generating resumes with verifiable-looking work histories, LinkedIn profiles with appropriate connection densities, and portfolio websites with original code samples that pass automated applicant tracking system filters.<\/p>\n<p>How Laptop Farms Maintain the Illusion After Hiring<\/p>\n<p>The deepfake interview gets the operative past the front door. Keeping them inside requires a different layer of infrastructure. Once a company ships a laptop to its new &#8220;US-based employee,&#8221; an IP-KVM (Internet Protocol Keyboard-Video-Mouse) device connected to that laptop transmits all keyboard signals, video output, and mouse movements across the internet to the actual operative&#8217;s location abroad. The device appears to the laptop as normal local peripherals; the operative experiences full remote control of a physical machine in an American home. The <a href=\"https:\/\/www.state.gov\/releases\/office-of-the-spokesperson\/2026\/07\/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers\/\" rel=\"nofollow noopener\" target=\"_blank\">July 31 joint advisory<\/a> specifically identifies this technique \u2014 laptop farms where proxies in Western countries receive company-issued equipment and allow overseas actors to remotely access it \u2014 as a core operational method.<\/p>\n<p>Remote administration tools including Chrome Remote Desktop, AnyDesk, TeamViewer, RustDesk, and GoTo\/LogMeIn serve as a backup layer and are more commonly used when IP-KVM hardware is unavailable. Unlike custom malware, these are legitimate applications that most corporate IT allowlists do not block \u2014 making them difficult to detect without behavioral analysis of login patterns and geographic access anomalies.<\/p>\n<p>A Scheme That Pays Twice<\/p>\n<p>The advisory and independent security research document that these operatives are not merely collecting salaries. They are running two parallel revenue streams for Pyongyang. The first is the salary itself: workers remit wages to parent North Korean agencies, with <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0416\" rel=\"nofollow noopener\" target=\"_blank\">$800 million flowing this way in 2024 alone<\/a>. The second is the data access: once embedded inside a company&#8217;s systems, operatives exfiltrate source code, harvest session cookies and credentials, and \u2014 when their cover is blown \u2014 <a href=\"https:\/\/www.ic3.gov\/PSA\/2025\/PSA250123\" rel=\"nofollow noopener\" target=\"_blank\">demand ransom payments in exchange for not releasing stolen intellectual property publicly<\/a>.<\/p>\n<p>CrowdStrike&#8217;s parallel financial reporting documents the scale of the crypto side: North Korean state-sponsored actors <a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">stole approximately $2.02 billion in cryptocurrency during 2025<\/a>, a 51% increase from the prior year, with the record $1.5 billion Bybit exchange hack in February 2025 being the largest single cryptocurrency theft in history. FAMOUS CHOLLIMA and related units often convert the IT worker salary proceeds through multi-chain cryptocurrency networks \u2014 using both Ethereum and Tron, switching between them based on liquidity and compliance monitoring intensity \u2014 to obscure the flow of funds back to Pyongyang. In March 2026, the Treasury Department&#8217;s Office of Foreign Assets Control <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0416\" rel=\"nofollow noopener\" target=\"_blank\">blacklisted 21 cryptocurrency addresses across both blockchains<\/a> as part of its action sanctioning six individuals and two entities connected to the scheme.<\/p>\n<p>The March 2026 OFAC action <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0416\" rel=\"nofollow noopener\" target=\"_blank\">sanctioned six individuals and two entities<\/a> connected to the scheme \u2014 including Amnokgang Technology Development Company, a DPRK-managed IT operation, and Nguyen Quang Viet, a Vietnamese national whose firm converted approximately $2.5 million in NK IT worker earnings into cryptocurrency between mid-2023 and mid-2025.<\/p>\n<p>Why European Governments Joined This Advisory<\/p>\n<p>Prior multilateral advisories on the North Korean IT worker threat were issued by the US, Japan, South Korea, and a handful of Five Eyes partners. The July 31, 2026 advisory marks the first time France&#8217;s Ministry for Europe and Foreign Affairs, Germany&#8217;s Federal Foreign Office, Italy&#8217;s Ministry of Foreign Affairs and International Cooperation, and the Netherlands&#8217; Ministry of Foreign Affairs co-signed a joint warning on this specific threat.<\/p>\n<p>Their inclusion is a signal about geography: North Korean IT workers are no longer primarily targeting US and South Korean companies. The advisory explicitly notes that operatives are seeking contracts &#8220;throughout the world, including in North America, Europe, and East Asia.&#8221; European tech sectors \u2014 particularly Germany&#8217;s industrial software industry, France&#8217;s aerospace and defense contractors, the Netherlands&#8217; semiconductor and maritime technology firms, and Italy&#8217;s manufacturing technology companies \u2014 are now assessed as active target environments by all eleven signatory governments.<\/p>\n<p>Hiring One Unknowingly May Already Violate US Law<\/p>\n<p>The eleven-nation advisory carries a warning that goes beyond cybersecurity: companies that inadvertently employ North Korean IT workers may be violating international and domestic law regardless of whether they knew the worker&#8217;s true identity.<\/p>\n<p><a href=\"https:\/\/www.state.gov\/releases\/office-of-the-spokesperson\/2026\/07\/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers\/\" rel=\"nofollow noopener\" target=\"_blank\">UN Security Council Resolution 2397<\/a> requires all member states to repatriate to North Korea any North Korean national earning income in their jurisdiction. At the domestic level, paying a North Korean national for services rendered may constitute a violation of US sanctions under Executive Order 13810 and Executive Order 13382, potentially exposing firms to OFAC enforcement. The <a href=\"https:\/\/www.fatf-gafi.org\/en\/countries\/detail\/DPRK.html\" rel=\"nofollow noopener\" target=\"_blank\">Financial Action Task Force lists North Korea as a high-risk jurisdiction subject to a call for action<\/a> \u2014 its most severe designation \u2014 with specific guidance that IT worker salaries constitute a proliferation financing mechanism.<\/p>\n<p>A <a href=\"https:\/\/www.skadden.com\/insights\/publications\/2026\/06\/north-korean-remote-it\" rel=\"nofollow noopener\" target=\"_blank\">Skadden, Arps, Slate, Meagher &amp; Flom analysis published in June 2026<\/a> found that while neither DOJ nor OFAC had yet filed enforcement actions against companies that inadvertently hired NK IT workers \u2014 characterizing those firms as &#8220;victims&#8221; \u2014 the firms &#8220;are not in the clear.&#8221; Both agencies have issued signals, the Skadden analysis concluded, that companies with deficient compliance programs that lead to the hiring of such workers could face criminal exposure, with DOJ tools including deferred prosecution agreements and the full weight of wire fraud, money laundering, identity theft, and sanctions conspiracy charges.<\/p>\n<p>Prosecutions Are Already Underway, with US Residents Sentenced<\/p>\n<p>The enforcement signal is not hypothetical. In April 2026, the Justice Department <a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker\" rel=\"nofollow noopener\" target=\"_blank\">sentenced two New Jersey residents<\/a> \u2014 Kejia Wang, 42, of Edison, and Zhenxing Wang, 39, of New Brunswick \u2014 to 108 months and 92 months in federal prison respectively for operating laptop farms that helped North Korean IT workers obtain employment at more than 100 US companies, compromising the stolen identities of at least 80 American citizens and generating more than $5 million for the regime. In May 2026, Matthew Issac Knoot of Nashville, Tennessee, and Erick Ntekereze Prince of New York each received <a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker-0\" rel=\"nofollow noopener\" target=\"_blank\">18-month sentences<\/a> for running separate laptop farms that together affected nearly 70 companies and generated approximately $1.2 million for Pyongyang.<\/p>\n<p>In total, the Justice Department has secured eight sentences in 2026 alone against US-based facilitators operating under its DPRK RevGen: Domestic Enabler Initiative.<\/p>\n<p>Legislation Takes Shape<\/p>\n<p>Four days before the joint advisory&#8217;s publication, US Representative Young Kim (R-CA-40) introduced the North Korean Fraudulent Applicants Knowingly Enriching the Regime Act \u2014 referred to as the North Korean FAKER Act (<a href=\"https:\/\/www.govtrack.us\/congress\/bills\/119\/hr9963\" rel=\"nofollow noopener\" target=\"_blank\">H.R. 9963<\/a>) \u2014 in the House of Representatives. The bill would authorize the Secretary of State to coordinate with US allies and partners to detect, attribute, and disrupt North Korean IT worker schemes and related activities, and would engage private-sector technology firms \u2014 including online employment platforms, payment processors, and identity verification companies \u2014 in that effort.<\/p>\n<p>The bill was referred to the House Foreign Affairs Committee on July 27, 2026, and had one cosponsor as of publication. It represents the first legislation specifically designed to institutionalize allied coordination on this threat with private-sector platform engagement as an explicit mandate.<\/p>\n<p>What Companies Should Do<\/p>\n<p>The eleven-nation advisory and independent security research from Skadden, CrowdStrike, Mandiant, and Palo Alto Networks Unit 42 identify a layered control set that no single measure can replace:<\/p>\n<p>During hiring: Require live, unscheduled video calls rather than scheduled interviews \u2014 and probe for AI artifacts by asking the candidate to perform unexpected physical actions, move to a different location in the room, or hold up a specific object. Conduct at least one in-person verification for any remote hire, or use AI-detection tools that analyze video feeds for deepfake signatures. Cross-reference all identity documents against independent databases rather than accepting candidate-provided references. Verify banking information against all identity documents before sending the first paycheck.<\/p>\n<p>Payment red flags: Reject any request to receive payment via cryptocurrency, money transfer service, or a third-party bank account. These routing patterns are the primary mechanism by which salaries are funneled back to Pyongyang.<\/p>\n<p>After onboarding: Monitor login patterns for geographic anomalies, simultaneous logins from multiple IP addresses, and unusually long logged-in sessions. Bind corporate laptops to verified physical identities and restrict access by geography or Autonomous System Number. Flag requests to install VPN software, remote desktop tools, or IP-KVM hardware on company machines.<\/p>\n<p>Reporting: Anyone who suspects they have encountered a North Korean IT worker scheme is encouraged to report to the FBI via IC3.gov or to their country&#8217;s equivalent national cybersecurity authority.<\/p>\n<p>Frequently Asked QuestionsHow do North Korean IT workers pass video job interviews if they are working from abroad?<\/p>\n<p>Since at least 2024, operatives working for FAMOUS CHOLLIMA and related North Korean units have used real-time AI deepfake technology \u2014 running a face-swapping model as live video inference during the call, routing the output through a virtual camera driver \u2014 to impersonate a real or synthetic person during live video interviews. The result looks like a normal webcam feed to most hiring managers. Standard advice to &#8220;turn your camera on&#8221; is no longer a reliable identity check. Hiring teams should ask candidates to perform spontaneous, unscripted physical actions that a deepfake pipeline would struggle to render convincingly, and should use AI-detection software that analyzes video feeds for synthesis artifacts.<\/p>\n<p>What happens to a company that unknowingly hires a North Korean IT worker?<\/p>\n<p>Companies that inadvertently hire NK IT workers have, to date, been characterized by the Justice Department as victims rather than perpetrators. However, both DOJ and OFAC have explicitly signaled that companies with inadequate compliance programs that lead to the hiring of NK workers face potential criminal exposure \u2014 including wire fraud conspiracy, sanctions violations, and money laundering charges. At minimum, companies face significant remediation costs, data breach notification obligations, and reputational harm. The Skadden analysis published in June 2026 recommends treating this as a compliance program failure requiring the same rigor applied to anti-money-laundering and export control due diligence.<\/p>\n<p>What is a laptop farm and how does North Korea use it?<\/p>\n<p>A laptop farm is a setup, typically in a US resident&#8217;s home, in which company-issued computers are received under false identities and then connected to IP-KVM hardware or remote desktop software. This allows North Korean operatives abroad to fully control the laptop \u2014 appearing to the company&#8217;s network as a US-based employee with a legitimate IP address, while the actual worker is in Pyongyang, China, Russia, or Southeast Asia. The company ships the laptop, pays the salary, and never meets the worker; the facilitator in the US takes a fee and forwards the wages overseas. Multiple US residents have been sentenced to federal prison in 2026 for operating laptop farms.<\/p>\n<p>What is the North Korean FAKER Act?<\/p>\n<p>The North Korean Fraudulent Applicants Knowingly Enriching the Regime Act (H.R. 9963) was introduced by Representative Young Kim (R-CA-40) on July 27, 2026, four days before the eleven-nation advisory. If enacted, it would authorize the Secretary of State to coordinate with US allies and private-sector technology companies \u2014 including employment platforms, payment processors, and identity verification firms \u2014 to detect, attribute, and disrupt North Korean IT worker schemes. The bill was referred to the House Foreign Affairs Committee and had one cosponsor as of publication.<\/p>\n","protected":false},"excerpt":{"rendered":"Your video interview screening process is no longer a reliable identity check. On July 31, 2026, the governments&hellip;\n","protected":false},"author":2,"featured_media":106900,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[12110,1147,55138,6254,171,55139,52109,55137,55140],"class_list":["post-106899","post","type-post","status-publish","format-standard","has-post-thumbnail","category-korea","tag-crowdstrike","tag-cybersecurity","tag-deepfake-job-interview","tag-fbi","tag-korean","tag-laptop-farm-north-korea","tag-north-korean-hackers","tag-north-korean-it-worker-scam","tag-ofac"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/106899","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/comments?post=106899"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/106899\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media\/106900"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media?parent=106899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/categories?post=106899"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/tags?post=106899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}