- North Korean hackers use Genai to hold jobs in Western companies
- New research from octa reveals AI -written cvs and messages
- This is an escalation from an existing fake interview campaign
New research from Octa has revealed that hackers from the Democratic People’s Republic of Korea (DPRK) use generative AI in its malicious interview campaign – a number of tactics involving employment in remote technical roles in Western companies, usually in industries with sensitive security data such as defense, aerospace or technology.
This is not the first time North Korean fake job hackers have gone the extra mile with their campaigns, but the new research has found that Genai is playing an integrated role in the employment schemes.
The AI models are used to “create convincing people in several stages of the job application and the interview process”, and then, when employed, Genai is used again to help maintain more roles that all earn revenue for the state.
Malicious interview
AI was used by these hackers in a number of ways, including generation of CVs and cover letters, conducted mock interviews via chat and webcam, translation, translation and summary of messages as well as management of communication to more jobs from different accounts and services.
To help, the hackers have a sophisticated network of ‘facilitators’ that provide support in the country, technical infrastructure and ‘legitimate business coverage’ – which helps the North Koreans with domestic addresses, legitimate documents and support during the recruitment process.
The campaign is growing increasingly sophisticated, especially considering that hackers are now using both sides of the job search process that targets job seekers with fake interviews where they deliver malware and infoSalers.
These detailed schemes often start on legitimate platforms such as LinkedIn or Upwork – with attackers who reach the victims to discuss potential options. Anyone on a job hunt or in the hiring process must be extra vigilant about who they are talking to and should be careful not to download any unknown software.