@efipm
🚨 North Korea lures engineers to rent identities in fake IT worker scheme 🇰🇵 📌 Famous Chollima / Lazarus Group is using a new tactic: renting real engineers’ identities to infiltrate companies. Instead of relying solely on stolen credentials, the group now walks up “front-men” — legitimate engineers who agree to rent out their identity for remote IT jobs. This lets the real threat actors from North Korea operate under the radar while the “front-man” handles any identity or compliance checks. 📌 They combine advanced social-engineering, AI, and remote-access toolchains to evade detection. The campaign uses AI-enhanced fake resumes, deep-fake video interviews, and remote-access software (VPNs, desktop-sharing) to mask the true origin of activity. The “front-man” may never do the actual technical work — the DPRK operatives do. 📌 This isn’t a small-scale hack: Hundreds to thousands of global companies are potentially exposed, spanning not just tech but finance, healthcare, crypto, and more. Researchers have documented systematic outreach, mass applications via platforms like GitHub and freelancer sites, and infiltration attempts at major corporations — highlighting this as a global security and supply-chain threat. Sources: [1] https://t.co/V34xd5kg10 | [2] TechCrunch