For the past several years, the Democratic People’s Republic of Korea has been conducting a campaign known as the “fake job interview”: members of the regime pose as job applicants to infiltrate Western companies and extract information or assets. This Saturday, a Colombian and an Argentinian presented a live demonstration of these interviews at the 34th edition of DEF CON, the largest cybersecurity conference for the Western hacking community, held annually in Las Vegas.
There are documented cases: in 2024, KnowBe4, a US cybersecurity training company, unknowingly hired a remote engineer who was actually an identity operated by a North Korean worker. In 2025, the cryptocurrency exchange Kraken detected inconsistencies during the interview process and, instead of suspending the hiring process, proceeded to study North Korean techniques.
Perhaps the most high-profile case involved 300 US companies that unknowingly hired foreign workers with ties to North Korea. The operation used stolen US identities and a “farm” of more than 90 computers—a cluster of computers installed in the same location and remotely controlled—in Arizona.
In a presentation titled “Smile, We’re Filming You! Streaming from a Laptop Farm of North Korean Workers,” hackers Mauro Eldritch and Heiner García explained how they managed to record these job interviews of a threat actor known as Famous Chollima (CrowdStrike).
After their presentation, they spoke with Clarín.
A fake farm to observe them from the inside. One of the North Korean infiltrators in the DEF CON investigation. Photo: Quetzal
Eldritch, an Argentinian, leads Quetzal Team, the threat research team of Bitso, a financial services and cryptocurrency company with a presence in Latin America. García, a Colombian, is the founder of NorthScan, an organization dedicated to threat research and intelligence.
To investigate the campaign, the specialists posed as “facilitators”—that is, people willing to help North Korean workers find jobs and operate from other countries—and went through the entire recruitment process.
Once accepted, they built a fake computer farm and provided the workers with controlled environments. The workers believed they were remotely accessing legitimate computers to perform their work.
Everything was recorded, including the “tactics, techniques, and procedures” of the alleged potential employees and what are known as engagement indicators, all documented in a technical report on a platform called any.run. The full article was published this Monday.
In this new phase of the investigation, García and Eldritch didn’t limit themselves to posing as facilitators: they created a fictitious startup that supposedly provided services to cryptocurrency “whales,” as those who possess vast fortunes in digital assets are called—an attractive client type for the operators.
Presenting themselves as employers, they hired one of the men and asked him to recruit close friends under a trust-based scheme. This allowed them to gather and observe a group of four North Korean agents.
García, using the cinematic alias “Andy,” also posed as a complicit team leader with a personal relationship to the supposed CEO, capable of guaranteeing the hires. From the outset, the workers believed they had found a vulnerable company willing to trust them. In reality, their every session was being monitored.
The investigators could observe and record everything they did: how they configured their computers, what systems they used to verify their identity, how they set up VPN connections to conceal their location, and how they worked throughout the day.
At the same time, they applied open-source intelligence (OSINT) techniques and targeted reconnaissance to reconstruct the infrastructure supporting the operation. According to their explanation, they uncovered networks of fake companies and identities, intermediaries located in various countries, financial transactions, and even schemes related to US work visas.
“First, we observed several overlapping indicators that align with the first stage we presented at a Swiss conference (InsomniHack): the same recruitment methods, the same language patterns, and activity on GitHub, Telegram, and other professional social networks,” Eldritch explained to this publication after the presentation.
Escort Platforms in Helsinki: How Digital Directories Have Changed the Search Process – HedgeDoc
Escort Platforms in Copenhagen: Understanding the Role of Online Directories – HedgeDoc
Escort Platforms in Helsinki: The Evolution of Local Online Listings – HedgeDoc
How Escort Platforms Support Local Connections in Helsinki – HedgeDoc
Exploring Escort Platforms in Helsinki: How Online Listings Have Evolved – HedgeDoc
At8Rytby9J
Exploring Copenhagen’s Adult Social Scene: A Practical Guide to Local Profile Browsing and Connections – HedgeDoc
Escorts in Copenhagen: Understanding the Local Escort Scene
374193
A Look at the Escort Industry in Copenhagen – HedgeDoc
Exploring Escort Services In Copenhagen What Visitors Should Know
90797
Escort Services: A General Overview – HedgeDoc
A Guide To Escort Services In Oslo What Visitors And Residents
Ahevmkmdn
A Practical Guide to Exploring Escort Listings in Norway – HedgeDoc
Exploring the Escort Scene in Helsinki: What Visitors Should Know |…
326706
138246
Escorts In Helsinki A Local Guide To Finding Reliable Profiles
A Beginner S Guide To Escort Services In Helsinki
Escorts in Copenhagen: Understanding the City's Professional Companion Scene – CodiMD
Escorts in Oslo: A Look at Professional Companion Services in Norway's Capital – CodiMD
Escorts in Oslo: Exploring the City's Professional Companion Services – HedgeDoc
Escorts in Helsinki: An Overview of Professional Companion Services – HedgeDoc