
The Interview Looked Real — The Candidate Wasn’t
Reporting from Unit 42 highlights a growing tactic in state-linked intrusion campaigns: the use of real-time deepfakes to create synthetic candidate identities during remote job interviews. Researchers found the technique can be produced with consumer tools and modest hardware in roughly an hour, enabling operators to interview multiple times under different personas and reduce the chance of being added to internal watchlists. Unit 42 ties this method to long-documented recruitment schemes by North Korean IT operatives aimed at infiltrating Western organizations for espionage and other malicious activity. The technique’s practicality was demonstrated in multiple incidents where employers nearly hired non-existent candidates; in at least one case, a contractor later loaded malware onto a corporate workstation after being onboarded. Key operational advantages for attackers included reusing a single operator across many applications by changing their synthetic persona, and avoiding straig
Continue reading on Dev.to
Opens in a new tab




