Skip to content
NetarxImpact Database
Fake IT Worker InfiltrationUnknownConfirmed

Kraken advanced a North Korean fake job applicant to unmask his tradecraft

Kraken (Payward, Inc.) · Cryptocurrency · United States · May 2025

What happened

Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.

How the deception worked

The infiltration relied on the fact that remote hiring verifies documents and video, not people. The candidate presented a resume and a government ID built from a stolen identity, joined interviews from remote colocated Mac desktops routed through VPNs to mask his real location and network, and appeared to be coached in real time, which produced audible shifts between voices. Kraken's team, already holding a partner-supplied list of email addresses tied to the group, matched his application address and let the process continue. In the final round Chief Security Officer Nick Percoco ran trap identity verification: asking him to confirm his location live, hold up his government ID, and recommend restaurants in the city he claimed to live in. He could not answer questions about his own city or citizenship.

AI involvement · Unknown

Kraken reported the candidate's primary ID appeared altered, likely using details from an identity theft case two years earlier, and that he switched between voices during interviews in a way consistent with real-time coaching. Kraken did not attribute either to AI.

The control that would have caught it· our reading, not a claim from the sources

Unscripted, locality-specific live verification during a video interview, cross-checked against threat-intel lists of known applicant identifiers, catches what document checks and reference calls cannot.

Sources (2)

  1. How we identified a North Korean hacker who tried to get a job at Kraken
    Kraken·blog.kraken.comOpen ↗
  2. Kraken tells how it spotted North Korean hacker in job interview
    Cointelegraph·cointelegraph.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.