惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
North Korean Hiring Fraud Runs on AI and US Laptop Farms
https://www.infosecurity-magazine.com/profile/alessandro-mascell · 2026-06-17 · via www.infosecurity-magazine.com

A North Korean scheme to plant fake IT workers inside Western companies has been exposed from the inside, after one of its operatives tried to infiltrate the very firm that tracks the fraud.

Risk intelligence provider Nisos recently detailed how a supposed Florida-based AI architect applied for a remote job at the company in June 2025, and how the application unraveled into a look inside an active fraud cell.

A Resume Too Good to Be True

The resume mirrored Nisos' job posting almost word-for-word and listed tools that did not exist during the stated employment periods. A brand-new email address with no breach history, a VoIP phone number and several conflicting resumes deepened the suspicion.

Nisos said the interviews settled it. The candidate's eyes tracked across the screen as if reading, and the firm concluded an AI tool was supplying answers in real time.

To be sure, the team invented a hurricane and asked how it had hit the candidate's supposed home in Florida. The candidate calmly reported minor rain and wind from a storm that never happened.

Read more: North Korean Hackers Targeted KnowBe4 with Fake IT Worker

Inside the Laptop Farm

Rather than walk away, Nisos played along. Canary tokens traced the operative's connections to Astrill VPN, a service favored by North Korean workers, and the delivery address for the work laptop matched neither the resume nor the real Floridian whose identity had been stolen.

Nisos shipped a rigged laptop to the address and, through its camera, saw a closet stacked with machines, a literal laptop farm.

The devices were driven by PiKVM hardware, which lets a remote operator control a computer as if sitting at it, even before it boots, and is hard for corporate security to spot.

The access laid bare the cell's setup:

  • Roughly 40 devices on the network, about 20 actively in use

  • Multiple personas employed at different companies at once

  • A Tailscale mesh VPN linking the machines

  • Willing Americans hosting the laptop farms on US soil

A National Problem

Nisos said hundreds of suspected laptop farms operate across the US, with wages routed through American bank accounts opened under stolen identities before reaching North Korea.

US authorities have said in the past that such revenue helps fund the regime's sanctioned weapons programs.

Nisos urged employers to treat remote hiring as a security problem: deepening background checks, adding unexpected questions to interviews to expose AI coaching and monitoring device behavior after a hire, since standard vetting no longer catches operatives this well prepared.