North Korean agents are using AI to trick Western companies into hiring them, Microsoft says
Artificial intelligence has become a powerful tool in the hands of agents linked to North Korea, who are successfully deceiving Western companies through an increasingly sophisticated employment fraud scheme. According to a report published by Microsoft’s threat intelligence unit, operatives tied to the Pyongyang regime have started using AI tools to create highly convincing fake identities, with the goal of landing remote jobs in IT and software development. The scam itself isn’t exactly new — reports of North Korean workers infiltrating foreign companies have been circulating for years — but the level of technology involved now completely changes the game.
Microsoft described in a detailed blog post how this well-known fundraising tactic by the Pyongyang government is being supercharged by AI. The tools help create fake names, alter stolen identity documents, and boost the credibility of fictitious candidates applying for IT and software development positions at Western companies. Once hired, these fake professionals send their salaries back to Kim Jong-un’s state, and in some documented cases, they even threatened to leak sensitive company data after being fired 😬.
How the scheme works from start to finish
The scam begins long before the first contact with a company. North Korean agents rely on the support of facilitators located in the very countries where the target companies are based. These intermediaries help lend authenticity to the fabricated identities by providing addresses, phone numbers, and even local bank accounts. From there, AI kicks in to build complete professional profiles that look absolutely legitimate.
According to Microsoft, the groups identified as Jasper Sleet and Coral Sleet — names assigned following the cybersecurity analyst convention for identifying agent collectives — use generative AI platforms to produce lists of culturally appropriate names for different regions. An example prompt cited by the company would be something like create a list of 100 Greek names or create a list of email formats using the name Jane Doe. These names are then combined with email addresses in formats that mimic real patterns, building identities that easily pass an initial screening.
The sophistication doesn’t stop there. The operatives also scour job platforms like Upwork looking for software and IT-related openings. They analyze the technical requirements listed in the postings and use AI to tailor their resumes and cover letters for each specific role, maximizing their chances of landing an interview. Upwork stated that it takes aggressive measures to detect and remove bad actors from its platform, but acknowledged the challenge is ongoing.
Deepfakes and voice alteration during interviews
During remote interviews, the level of disguise reaches its peak. Microsoft revealed that the scammers use voice alteration software to mask their accents, convincingly passing themselves off as Western candidates. On top of that, the Face Swap AI app is used to insert North Korean workers’ faces into stolen identity documents and to generate professional-looking profile photos for resumes.
In some cases, a single operative manages multiple identities simultaneously, participating in interviews for different companies on the same day. AI also provides quick and accurate technical answers during live practical tests, making it nearly impossible for an average recruiter to realize they’re dealing with an ongoing fraud. This level of automation and digital disguise represents a massive leap from earlier attempts, which basically relied on forged documents and the work of human intermediaries.
In Microsoft’s own words: Jasper Sleet uses AI throughout the entire attack cycle to get hired, stay employed, and exploit the access gained at scale.
What happens after they get hired
After landing a position, these fake professionals operate normally for weeks or months, delivering work of sufficient quality to avoid raising red flags. Microsoft detailed that the agents use AI to write professional emails, translate documents, and even generate code, all with the goal of avoiding detection as fraudsters or getting fired for poor performance.
At the same time, many of them take advantage of their access to internal company systems to collect sensitive information and map out network infrastructures. In more serious situations, there have been documented cases of backdoor installations that can be exploited in future cyberattacks. In other words, the fraud goes far beyond simple salary diversion — it creates a gateway for corporate espionage and security threats that can cause significant long-term damage 🔓.
There’s also a blackmail component. When these fake workers are eventually discovered or let go, some of them resort to threatening to leak sensitive company data as a form of extortion. This behavior turns what was already a serious fraud problem into a full-blown information security crisis.
The scale of the operation is staggering
To get a sense of the scope of this scheme, Microsoft revealed that last year it managed to shut down about 3,000 Microsoft Outlook and Hotmail accounts that were being used by fake North Korean IT workers. That number makes it clear that we’re not talking about isolated incidents but rather an industrial, systematic operation directly sponsored by the state.
According to estimates from U.S. intelligence agencies, North Korean IT workers embedded in foreign companies generate hundreds of millions of dollars per year for the Pyongyang regime. That amount rivals what the country brings in through direct cyberattacks, like ransomware and cryptocurrency theft, and represents a stable revenue source that is particularly hard to disrupt. This is money that helps fund programs under international sanctions, which makes combating this type of fraud even more urgent from a geopolitical standpoint 💰.
The impact on the remote job market
This scenario described by Microsoft calls into question one of the biggest achievements of the job market in recent years: global remote hiring. Tech companies that embraced the distributed model now face a real dilemma. How do you guarantee a candidate’s authenticity when AI itself can fabricate an entire person, complete with a face, voice, professional background, and seemingly legitimate technical skills?
The problem doesn’t just hit startups or small businesses. Large corporations with structured hiring processes have also been targeted by these operations, precisely because the scale of remote work makes in-person verification and deeper international background checks more difficult. The trust that made remote work possible is being deliberately exploited by these agents.
How to protect yourself: Microsoft’s recommendations
Given this landscape, Microsoft and other security organizations are already offering concrete guidance so companies can defend themselves. One of the main recommendations is pretty straightforward: conduct job interviews for IT positions via video or in person, paying special attention to signs of deepfakes during video calls.
According to Microsoft, trained interviewers can spot AI-generated video or images through a series of visual indicators, including:
- Pixelation around the edges of the face, eyes, ears, and glasses
- Inconsistencies in how light interacts with the candidate’s face
- Facial movements that appear artificial or slightly out of sync
- Visual artifacts that briefly appear during changes in expression
Beyond these visual checks, other measures are being adopted across the industry to contain the threat:
- Investment in biometric identity verification solutions that go beyond simple document checks, using liveness detection to confirm that the person on camera is real
- Integration of behavioral analysis tools into recruitment platforms, capable of identifying inconsistencies between the candidate’s declared time zone and their connection IP address
- Adoption of multi-step verification protocols during the hiring process
- A healthy dose of skepticism toward profiles that seem too perfect, since AI-fabricated perfection often leaves subtle traces
AI as a double-edged sword
What this whole story shows us is something that had been taking shape for a while, but is now becoming very real. The same AI that is revolutionizing productivity, accelerating creative processes, and transforming the way we develop software is also being used as a tool for industrial-scale fraud. This isn’t a hypothetical scenario or science fiction. These are real operations, documented by one of the biggest tech companies on the planet, affecting businesses of all sizes.
For anyone working in tech or hiring remote professionals, the message is clear: investing in additional layers of security during the recruitment process is no longer optional. It’s a real and urgent necessity. Identity verification needs to evolve at the same pace that falsification tools are advancing. And this applies to HR departments and information security teams alike, who need to work together to close the gaps these agents are exploiting 🔒.
This case also raises an important point about how remote work platforms and recruiting tools need to rethink their validation mechanisms. It’s no longer enough to trust a well-written resume, a LinkedIn profile with solid connections, or a video interview where the candidate seems confident and technically competent. In a world where AI can fabricate all of that in a matter of minutes, human authenticity has become the most valuable — and hardest to verify — asset in the hiring process.
