Detect Deepfakesby Resemble AI
Deepfake case study · Video

Peering Into the Live Infrastructure Behind North…

North Korean IT operatives are using real-time AI deepfake video to bypass hiring checks and infiltrate global technology companies for state-sponsored…

Incident date
Jul 2026
Target
various corporate hiring managers and technology companies
Updated Aug 9, 2026 · 1 min read

On July 31, 2026, a coalition of eleven nations including the United States, France, and Japan issued a joint alert warning that North Korean IT operatives are utilizing real-time AI deepfake video to impersonate job candidates. This sophisticated tactic allows state-backed actors to infiltrate corporate hiring processes by appearing as legitimate applicants during live video interviews.

What happened

The operation, linked to the group tracked as FAMOUS CHOLLIMA, employs real-time video inference rather than static images or pre-recorded clips. Operatives map stolen or synthetic faces onto their own feeds using virtual camera drivers, which video-conferencing platforms process as standard webcam input. This technique is designed to bypass traditional liveness detection and visual inspection by hiring managers.

Beyond the interview, the scheme relies on a complex infrastructure of laptop farms. Once a candidate is hired, company-issued laptops are sent to proxies in Western countries. These devices are equipped with IP-KVM hardware or legitimate remote administration tools like AnyDesk and TeamViewer, allowing the actual operatives—located in countries including North Korea, Russia, and China—to maintain full control of the machines as if they were working from a US home office.

This infrastructure supports multiple objectives. Operatives use large language models to generate convincing resumes, LinkedIn profiles, and code portfolios to pass initial screening filters. Once embedded, they collect salaries that are funneled back to Pyongyang to fund nuclear and ballistic missile programs—amounting to approximately $800 million in 2024. Additionally, the roles provide direct access to corporate environments, enabling the theft of source code, the harvesting of credentials, and the extortion of victim organizations by threatening to release proprietary data. Security research presented at Black Hat 2026 by analyst SttyK emphasizes that identifying this live infrastructure is now critical for defenders to disrupt these infiltration efforts.

Sources