Researchers at Silent Push successfully exposed a suspected North Korean IT worker actively scouring Discord to recruit foreigners. The objective was to orchestrate fraudulent job interviews and secure remote employment using stolen identities. The operator offered intermediaries a highly lucrative proposition: impersonate the candidate during interviews, funnel the salary into their personal account, retain a 35% commission, and transfer the remaining 65% to the scheme’s mastermind.
The Deceptive Recruitment Process
The intricate investigation commenced with a remarkably deceptive job posting within the Mouse Review Discord community. An account operating under the alias “tecguru113” aggressively solicited collaboration from individuals residing in the United States, the European Union, and various Latin American nations, explicitly targeting Brazil, Mexico, Argentina, Colombia, and Chile.
A Silent Push analyst subsequently adopted a fictitious persona and established contact with the author via Telegram. The operator, identifying as “Tec Guru,” meticulously outlined the fraudulent scheme. The recruited intermediary was required to activate their camera during interviews, converse directly with the prospective employer, and essentially lease their identity. Meanwhile, the genuine developer surreptitiously provided correct answers and executed all technical tasks.
Remote Access and AI Assistance
During technical evaluations, Tec Guru proposed connecting directly to the intermediary’s computer using AnyDesk, TeamViewer, or Chrome Remote Desktop. He would independently write the required code while the visible participant maintained the conversational facade. Furthermore, candidates could leverage ChatGPT and other AI tools to assist in formulating responses. This elaborate charade effectively bifurcates a single “employee” into two distinct roles. The local proxy supplies the physical appearance, documentation, and a legitimate bank account, whereas the remote programmer fulfills all actual labor requirements.
Connecting the Dots to North Korea
The specific choice of VPN services immediately captured the researchers’ attention. When questioned about suitable options, Tec Guru instantly recommended Astrill VPN. Silent Push had previously linked this particular service to the infrastructure utilized by North Korean IT workers. While the mere selection of a VPN proves nothing definitively, researchers meticulously documented it as one of several corroborating indicators.
The analysts eventually coaxed their interlocutor into activating his camera. Tec Guru adamantly refused to share his screen, and upon the mere mention of North Korea, he abruptly terminated the video feed. Following a comprehensive review of the technical, financial, and infrastructural data, Silent Push published a detailed blog post exposing the North Korean IT worker. The company asserted with high confidence that the operator is indeed a North Korean citizen. Because the researchers never obtained a direct confession, Tec Guru’s affiliation with the North Korean program remains an attribution by Silent Push, rather than a legally established fact by law enforcement.
A Widespread and Dangerous Phenomenon
The model proposed by Tec Guru flawlessly mirrors schemes that authorities across multiple nations consistently attribute to North Korean remote workers. In a joint advisory published on July 31, 2026, the United States, the United Kingdom, Germany, France, the Netherlands, Japan, South Korea, and other nations comprehensively detailed these tactics. The report highlighted the widespread use of forged documents, willing intermediaries, VPNs, remote access tools, and proxy bank accounts. Frequently, these intermediaries actively participate in interviews on behalf of the genuine worker and receive a substantial portion of the salary in exchange for their identity.
The Threat of “Laptop Farms”
Another prevalent variation centers on the creation of sophisticated “laptop farms.” A company unwittingly ships a corporate computer to the residential address of an employee located in the United States or another permitted jurisdiction. The proxy simply powers on the device and grants unfettered remote access to an individual physically located thousands of miles away. Consequently, the employer registers a familiar, localized IP address and falsely assumes the employee is working from the stated geographic region.
The sheer scale of these illicit operations has long surpassed isolated, fraudulent interviews. In April 2026, the United States Department of Justice dismantled a massive scheme that assisted North Korean specialists in infiltrating over 100 prominent companies. The perpetrators exploited the identities of at least 80 American citizens and accumulated illicit proceeds exceeding 5 million dollars. Consequently, two orchestrators managing American “laptop farms” received severe sentences of 108 and 92 months in federal prison.
Crucially, the risk for an employer extends far beyond merely dispensing a salary under a fictitious name. The FBI previously issued a stark warning that, once employed, North Korean IT workers can easily secure legitimate access to proprietary source code and sensitive internal systems. They often exfiltrate confidential data and, following termination, relentlessly demand extortion payments to prevent its public release. SecurityLab has previously documented alarming instances where a seemingly benign remote employee rapidly metamorphosed into a severe insider threat.
Silent Push strongly advises organizations to rigorously verify not only physical documents and resumes but also the actual geographic location of the candidate during the interview process. Employers must meticulously cross-reference connection geographies and scrutinize the use of VPNs, remote desktop protocols, and any discrepancies between the employee’s name and the designated salary account holder. While no single indicator definitively proves a connection to the DPRK, the ominous combination of a fabricated identity, an on-camera proxy, concealed remote access, and an unorthodox payment arrangement absolutely demands immediate and thorough secondary verification.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.