Skip to content
NetarxImpact Database
Fake IT Worker InfiltrationConfirmed AI-enabledConfirmedCampaign

North Korean operatives adopt real-time deepfakes to pass remote job interviews

Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate · Technology · United States · April 2025

What happened

In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.

How the deception worked

The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.

AI involvement · Confirmed AI-enabled

Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.

The control that would have caught it· our reading, not a claim from the sources

Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.

Sources (2)

  1. False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation
    Palo Alto Networks Unit 42·unit42.paloaltonetworks.comOpen ↗
  2. North Korean Operatives Use Deepfakes in IT Job Interviews
    Dark Reading·darkreading.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.