Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers
North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.
- Date it happened
- 2021-01-01
- Organisation involved
- Yang Di, WaterPlum, Wagemole, Void Dokkaebi, UNC5267, Son Un Chol, Sok Kwang Hyok, Sim Hyon-Sop, Rim Un Chol, Ri Kyong Sik, Reconnaissance General Bureau, PurpleBravo, North Korean threat actors, Minh
- Product, system or model
- Zoom, WebSocket-based C2, Video interview platforms, Upwork, remote3, Remote admin tools, Raspberry Pi Zero, OtterCookie v4, OtterCookie v3, OtterCookie, Laptop farms, Job boards, InvisibleFerret, Git
- validin.com
- edition.cnn.com
- anthropic.com
- washingtonpost.com
- thehindu.com
- unit42.paloaltonetworks.com
- gartner.com
- gartner.com
- justice.gov
- thehackernews.com
- thehackernews.com
- cybersecuritydive.com
- wsj.com
- fortune.com
- inc.com
- theregister.com
- cyberscoop.com
- knowbe4.com
- blog.knowbe4.com
- knowbe4.com
- techtarget.com
- politico.com
- dtexsystems.com
- wired.com
- cloud.google.com
- bbc.com
- cyberscoop.com
- justice.gov
- cyberscoop.com
- cyberscoop.com
- justice.gov
- justice.gov
- justice.gov
- cyberscoop.com
- cyberscoop.com
- cyberscoop.com
- cyberscoop.com
- wired.com
- justice.gov
- ofac.treasury.gov
- the420.in
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.