Security researchers at Silent Push identified a fraudulent job recruitment scheme hosted on a Discord server. The campaign aims to insert a suspected North Korean IT worker into Western tech companies using local proxy candidates. Threat actors use these remote roles to generate foreign revenue and bypass international financial sanctions.
At a glance
- Actor or group: Suspected North Korean state-linked operative (high confidence)
- Activity type: Interview fraud, proxy hiring, and identity theft
- Targets or victims: Remote technology firms in the United States, Europe, and Latin America
- Scale: Multiple concurrent contracts with claimed salaries of up to $180,000 per position
- Jurisdiction or law-enforcement status: Target of U.S. OFAC sanctions and State Department warnings
- Source: Silent Push Threat Intelligence
TL;DR
Silent Push uncovered a fraudulent hiring ring recruiting foreign workers to front for a North Korean IT worker. The operative conducts live interview coaching and remote desktop manipulation to secure developer positions. Organizations that hire these proxies face severe security breaches, corporate extortion, and international sanctions violations.
What Happened
Researchers discovered an unusual job advertisement posted inside a public Discord community dedicated to computer hardware reviews. An account using the handle “tecguru113” promoted a deceptive subcontracting partnership. The listing promised applicants significant income if they agreed to represent the group during remote hiring interviews.
An investigator created a cover persona and contacted the promoter on Telegram under the profile “Tecguru0618.” During these discussions, the operative outlined a structured revenue-sharing scheme. The candidate would receive 35 percent of all earnings. Meanwhile, the remote operative claimed 65 percent of each paycheck.
The operation relied on deceptive interview tactics. The promoter instructed the proxy to sit on video during technical screenings. Behind the scenes, the operative provided live answers through messaging platforms. Furthermore, the handler offered to take remote control of the applicant’s computer during live coding challenges. An advertisement recovered from the campaign stated: “For live coding challenges, I can remotely access your screen and complete coding tasks while you continue the conversation smoothly.”
The handler also directed the proxy to use artificial intelligence assistants to generate technical responses. Once hired, the proxy would receive regular direct deposits into local bank accounts. The recruit would then wire the majority share back to the operative through third-party processors or cryptocurrency wallets.
Who Is Behind It
Silent Push attributes this recruitment scheme with high confidence to a North Korean IT worker. Multiple operational and technical indicators support this assessment.
During private chats, the investigator asked the operative for virtual private network recommendations. The suspect immediately suggested Astrill VPN. Cyber threat analysts recognize this specific service as a primary tool used by North Korean network operators.
Additionally, researchers observed distinct behavioral reactions during a direct video call. When analysts mentioned regional politics and referenced North Korea, the operative abruptly terminated the video feed. The operative also refused to utter any criticism of the regime.
The technical infrastructure, language syntax, and financial routing align directly with documented Pyongyang front operations. Researchers noted: “We identified the threat actor’s primary tactic as identity and proxy theft, under the guise of a front/facilitator recruitment scheme.”

Impact or Scale
The operative targeted tech applicants located across the United States, the European Union, and Latin American countries. Target regions included Brazil, Mexico, Argentina, Colombia, and Chile. The threat actor sought proxies in these jurisdictions to bypass geographic location blocks and regional tax verification filters.
The promoter claimed that typical remote software developer roles yield between $130,000 and $180,000 annually. Moreover, the operative claimed to handle multiple full-time contracts simultaneously for a single collaborator. These unauthorized earnings directly support the North Korean regime and its state-funded weapons initiatives.
For target enterprises, the operational risks extend far beyond lost wages. Once hired, a North Korean IT worker gains privileged access to internal company repositories. Operators frequently exfiltrate proprietary source code and sensitive customer databases. Subsequently, threat actors blackmail employer organizations, threatening public leaks unless the company pays a hefty ransom.
Protection and Future Outlook
Organizations that accidentally employ state-sponsored operatives face severe legal penalties. The United States Department of the Treasury enforces strict sanctions through the Office of Foreign Assets Control. Companies that pay these individuals risk hefty fines and formal regulatory sanctions.
The United States Department of State warned about these deceptive practices in a formal advisory. Silent Push emphasized the legal danger, stating: “Organizations engaging with North Korean IT workers face severe sanctions risks and are advised to verify applicants’ physical locations during job interviews.”
Hiring managers must strengthen their candidate verification protocols. Companies should require in-person video interviews with active identity checks. Security teams should cross-reference applicant internet addresses with corporate application portals. Additionally, interviewers must prohibit candidate screen sharing via third-party remote desktop software. Human resource departments should monitor employee device logins for unexpected virtual private network activity. Finally, background screening must confirm that tax records match the candidate’s actual location.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!