Threat Intelligence

Report: Fake job site aids North Korean hackers

North Korean remote IT worker scam

In a significant evolution of its cyber-espionage tactics, North Korea is now targeting job seekers in the AI and cryptocurrency sectors to infiltrate major US firms, according to researchers from security firm Validin, CNN reports.

Instead of impersonating company employees, operatives have created a sophisticated fake job platform that mimics the legitimate Lever recruiting service to gain long-term access to applicants' computers during the hiring process. Validin's CEO, Kenneth Kinion, explained that

"Going after job seekers gives North Korean actors a huge advantage," as candidates are more likely to run software from a perceived interviewer. This method exploits the secrecy of a job search, making victims less likely to report suspicious activity.

While no victims of this specific scheme are yet known, experts note that such cyber operations have previously funded billions for Pyongyang's weapons programs, with one White House estimate attributing half of North Korea's missile funding to cybercrime. This new strategy demonstrates a well-integrated and adaptive threat ecosystem.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds