For the past several years, the Democratic People’s Republic of Korea has been conducting a campaign known as the “fake job interview”: members of the regime pose as job applicants to infiltrate Western companies and extract information or assets. This Saturday, a Colombian and an Argentinian presented a live demonstration of these interviews at the 34th edition of DEF CON, the largest cybersecurity conference for the Western hacking community, held annually in Las Vegas.

There are documented cases: in 2024, KnowBe4, a US cybersecurity training company, unknowingly hired a remote engineer who was actually an identity operated by a North Korean worker. In 2025, the cryptocurrency exchange Kraken detected inconsistencies during the interview process and, instead of suspending the hiring process, proceeded to study North Korean techniques.

Perhaps the most high-profile case involved 300 US companies that unknowingly hired foreign workers with ties to North Korea. The operation used stolen US identities and a “farm” of more than 90 computers—a cluster of computers installed in the same location and remotely controlled—in Arizona.

In a presentation titled “Smile, We’re Filming You! Streaming from a Laptop Farm of North Korean Workers,” hackers Mauro Eldritch and Heiner García explained how they managed to record these job interviews of a threat actor known as Famous Chollima (CrowdStrike).

After their presentation, they spoke with Clarín.

A fake farm to observe them from the inside. One of the North Korean infiltrators in the DEF CON investigation. Photo: Quetzal

Eldritch, an Argentinian, leads Quetzal Team, the threat research team of Bitso, a financial services and cryptocurrency company with a presence in Latin America. García, a Colombian, is the founder of NorthScan, an organization dedicated to threat research and intelligence.

To investigate the campaign, the specialists posed as “facilitators”—that is, people willing to help North Korean workers find jobs and operate from other countries—and went through the entire recruitment process.

Once accepted, they built a fake computer farm and provided the workers with controlled environments. The workers believed they were remotely accessing legitimate computers to perform their work.

Everything was recorded, including the “tactics, techniques, and procedures” of the alleged potential employees and what are known as engagement indicators, all documented in a technical report on a platform called any.run. The full article was published this Monday.

In this new phase of the investigation, García and Eldritch didn’t limit themselves to posing as facilitators: they created a fictitious startup that supposedly provided services to cryptocurrency “whales,” as those who possess vast fortunes in digital assets are called—an attractive client type for the operators.

Presenting themselves as employers, they hired one of the men and asked him to recruit close friends under a trust-based scheme. This allowed them to gather and observe a group of four North Korean agents.

García, using the cinematic alias “Andy,” also posed as a complicit team leader with a personal relationship to the supposed CEO, capable of guaranteeing the hires. From the outset, the workers believed they had found a vulnerable company willing to trust them. In reality, their every session was being monitored.

The investigators could observe and record everything they did: how they configured their computers, what systems they used to verify their identity, how they set up VPN connections to conceal their location, and how they worked throughout the day.

At the same time, they applied open-source intelligence (OSINT) techniques and targeted reconnaissance to reconstruct the infrastructure supporting the operation. According to their explanation, they uncovered networks of fake companies and identities, intermediaries located in various countries, financial transactions, and even schemes related to US work visas.

“First, we observed several overlapping indicators that align with the first stage we presented at a Swiss conference (InsomniHack): the same recruitment methods, the same language patterns, and activity on GitHub, Telegram, and other professional social networks,” Eldritch explained to this publication after the presentation.

By Editor

One thought on ““Smile, we’re filming you”: They infiltrated a network of North Korean workers, recorded them, and showed it on DEF CON 34”

Leave a Reply