North Korean IT Workers Use Real-Time Deepfakes to Beat…
Eleven nations issued a joint alert warning that North Korean operatives are using real-time deepfake video to bypass hiring checks and infiltrate global…
- Incident date
- Jul 2026
- Target
- Global technology companies
On July 31, 2026, a coalition of eleven nations—including the United States, Japan, South Korea, France, Germany, Italy, and the Netherlands—issued a coordinated advisory warning that North Korean IT operatives are utilizing real-time AI deepfake video to impersonate candidates during job interviews. This sophisticated tactic allows operatives to bypass identity verification processes, enabling them to secure positions at global technology companies while appearing to work from domestic home offices.
What happened
The scheme involves operatives, identified by CrowdStrike as the group FAMOUS CHOLLIMA, using real-time video inference to map synthetic or stolen faces onto their own feeds. This output is routed through a virtual camera driver, making it indistinguishable from a standard webcam feed to hiring managers. These deepfakes are supported by AI-generated resumes, portfolio websites, and cover letters that pass automated tracking filters.
Once hired, the threat actors maintain the illusion through "laptop farms." Companies ship equipment to proxies in Western countries, who connect the devices to IP-KVM (Internet Protocol Keyboard-Video-Mouse) hardware. This allows the operatives, based in locations including North Korea, Russia, China, Southeast Asia, and Africa, to remotely control the physical machines. In cases where IP-KVM hardware is unavailable, they utilize legitimate remote administration tools like AnyDesk, TeamViewer, and Chrome Remote Desktop, which often bypass corporate IT allowlists.
This infiltration serves two primary purposes for the North Korean government. First, it generates direct revenue; in 2024 alone, these workers funneled approximately $800 million toward Pyongyang’s ballistic missile and nuclear weapons programs. Second, it provides deep access to corporate infrastructure. Once inside, operatives exfiltrate source code, harvest credentials, and steal sensitive data. If detected, they often pivot to extortion, threatening to release proprietary code publicly unless a ransom is paid. The advisory warns that companies inadvertently employing these operatives may be in violation of international and domestic laws, including US sanctions, potentially exposing firms to enforcement actions from the Office of Foreign Assets Control.