The North Korean ‘fake’ IT worker saga has taken another twist with fresh research from Palo Alto Networks threat research lab, Unit 42, suggesting these hostile cyber-actors are using real-time deepfake technology in face-to-face interviews to secure remote work positions.
After analysing last year’s data breach at AI image editing platform Cutout.pro, which exposed the personal information of nearly 20 million users, Unit 42 said it uncovered ‘scores’ of email addresses likely linked to North Korean IT worker operations.
Adding to the evidence, another Unit 42 study, initially shared with The Pragmatic Engineer newsletter, documented a case study involving a Polish AI firm that encountered two separate deepfake candidates.
In that case, Unit 42 said interviewers suspected both personas were controlled by the same individual, especially after the operator displayed markedly more confidence during the second technical interview, likely due to having already encountered the format and questions.
According to threat researchers, these tactics align with the known techniques and procedures of those executing the DPRK IT worker scam, with North Korean threat actors having already demonstrated significant interest in identity manipulation and synthetic profiles.
However, by using deepfake tech in attempts to fool interviewers in real-time, Unit 42 warns that these malicious IT workers have taken their campaign to the next level, and with worrying ease.
Unit 42 said that it took researchers with no prior experience just over one hour to create a real-time deepfake using readily available tools and cheap consumer hardware, allowing adversaries to create convincing synthetic identities without specialist tools or knowledge.
Using only an AI search engine, images generated by thispersonnotexist, a passable internet connection and a GTX 3070 graphics processing unit purchased almost five years ago, Unit 42 managed to produce multiple deepfake identities of passable quality.
However, if threat actors, including the North Korean government, are willing to commit more resources, such as more powerful graphics processing units, these deepfakes can be vastly improved, capable of slipping by remote interviewers.
For its part, Unit 42 advises interviewers to look out for several technical shortcomings to spot real-time deepfake systems in action.
Recommended reading
- North Korean Threat Actors Have Infiltrated UK Firms
- OpenAI Reveals Scale of Threat Actors Using AI to Influence Elections
- North Korea Stole $659M in Crypto Last Year, Says US
That includes temporal consistency issues, where rapid head movements cause noticeable artifacts as the tracking system struggles to maintain positioning, as well as audio-visual synchronisation problems, with slight delays between lip movements and speech being detectable under careful observation.
Sudden changes in lighting conditions can also reveal inconsistencies in rendering, particularly around the edges of the face, while occlusion movements, such as when a hand or object passes in front of the face, can leave telltale signs, as deepfake systems often fail to properly reconstruct the partially obscured face.
Vetting IT candidates has become an increasingly pressing issue, with North Korean threat actors actively targeting European firms in the past months, as well as HM Treasury’s ‘Probability Yardstick’ indicating with ‘almost certainty’ that fake IT workers have been looking to join UK businesses.





