Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers

platform, threat

Key Findings

  • Silent Push identified a North Korean fake job recruitment scam channel hosted on a Discord server by a defender colleague, and we engaged the recruitment representative to ask about their offering and determine whether the individual was actually a North Korean IT worker.
  • After connecting via Telegram, we asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised us to use Astrill VPN, a VPN often used by North Korean IT workers
  • We identified the threat actor’s primary tactic as identity and proxy theft, under the guise of a front/facilitator recruitment scheme.
  • Based on technical reference indicators pointing to the persona being a North Korean IT worker, and on their speech patterns, among other flags, we believe they are North Korean.

Organizations engaging with North Korean IT workers face severe sanctions risks and are advised to verify applicants’ physical locations during job interviews. Silent Push developed a detection method for these operations.

Executive Summary

A cybersecurity colleague recently spotted an odd job advertisement being promoted on a Discord Server named “Mouse Review,” which is a server channel created to find and write computer mouse reviews.

Discord servers are free, often invitation-only, virtual meeting places divided into smaller text and voice rooms called channels. Much like digital clubhouses for groups, Discord Servers are popular online spaces for engaging and sharing various media.

We began investigating the job advertisement on the Mouse Review channel. The Discord account “tecguru113” (ID 1453753519436861505) is responsible for spreading the fake job advertisement in the Mouse Review Discord server.

One of our principal threat research analysts created a fake persona and contacted the Telegram account “Tecguru0618” mentioned in the job ad. This blog details our interaction with the representative, whom we believe, with moderate to high confidence, is a North Korean IT worker, and the information we gathered on the job advertisement scheme, including the threat actor’s thoughts about it.

In addition to the Silent Push preemptive cyber defense platform for proactive protection, our Traffic Origin IP geolocation and reputation solution provides important information about the physical origin of web traffic and actual locations of job applicants.


Investigating the North Korean Job Advertisement

Screenshot of the job recruitment scam web page
Screenshot of the job recruitment scam web page

The Video Capture

During our conversation with the North Korean IT worker, we captured a video clip.

During the course of our meeting:

  1. We successfully prompted Tec Guru to enable their video feed while we kept our camera off.
  2. When asked to confirm where we found the job posting, we used intelligence from our cybersecurity colleague to answer accurately. 
  3. In an attempt to effect a screen share, we pretended not to understand how to retrieve or use remote software, but Tec Guru declined to share his screen during the video call.
  4. As we started to run out of questions to ask, we mentioned countries such as Iran, Russia, and North Korea. As soon as Tec Guru heard “North Korea,” he quickly turned off his camera. 
  5. We tried to get the IT worker to disparage North Korea, but he avoided saying anything negative since it goes against what he has been taught. 

Primary Tactic: Identity & Proxy Theft (Front/Facilitator Recruitment)

The North Korean IT worker’s primary goal is proxy hiring, using Western or Latin American (LATAM) citizens as the “face” and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions.

Observed Tactics, Techniques, and Procedures

  • Geographic Targeting: The threat actor explicitly solicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/location blocks and regional tax compliance checks.
  • Front Person / Face-Rental: The advertisement explicitly requests a proxy to “turn on your camera during interviews,” “communicate with clients,” and “represent the necessary skills confidently.”
  • Revenue-Sharing Facilitation Scheme: The job ad scam offers a financial incentive split (35% to the proxy, 65% to the North Korean IT Worker) to incentivize foreign nationals to serve as financial and identity mules.

Technical TTPs: Interview Fraud and Remote Control

To bypass live technical assessments and code testing during remote hiring processes, the threat actor relies on real-time assistance and remote access tools.

Observed TTPs

  • Real-time Technical Proxying / Live Coaching: Using platforms such as Google Meet to provide real-time messaging, answers, and coding assistance during live interviews while the proxy sits on camera for the potential “job interview.”
  • Remote Desktop Control for Technical Assessments: Requesting remote screen/computer access during live coding challenges (“I can remotely access your screen and complete coding tasks while you continue the conversation smoothly”). This is commonly done using remote management software such as AnyDesk, TeamViewer, or Chrome Remote Desktop, and is frequently used by North Korean IT workers.
  • AI-Assisted Impersonation: Explicitly suggests the proxy use AI tools (e.g., ChatGPT) to generate response prompts and bridge knowledge gaps on the fly.

Financial and Operational TTPs

  • Direct Employer Payment Routing: The threat actor directs the proxy to accept direct salary/contract payments into local U.S./E.U. bank accounts and transfer the remaining balance (65%) back to the operative via unmonitored channels (cryptocurrency, wire transfers, or third-party payment processors).
  • Anonymized Communication Platforms: Relying on VoIP numbers (+1 U.S. country code) and Telegram handles (@tecguru0618) to maintain operational security (OPSEC) and avoid traceable corporate or local identities.
  • Aggressive Pretexting (“100% Legitimate”): Framing an illegal identity fraud scheme as a standard “subcontracting arrangement” and using reassuring language (“100% Privacy Guaranteed” and “Transparent”) to reduce the proxy’s perception of legal risk.

Key Risk Takeaways for Organizations

Organizations that fall prey to these fraudulent job scams face a variety of potential risks:

  1. Remote Identity Fraud: Candidates hired for remote roles may be sitting on camera while a completely different entity writes code, answers technical queries via chat, or controls the machine via remote desktop.
  2. Insider Threat / Data Exfiltration Risk: Once hired, these workers often use their corporate access to exfiltrate proprietary source code, steal sensitive intellectual property (IP), and extort victim organizations by threatening to leak corporate data in exchange for ransom payments.
  3. Sanctions Compliance: Companies that unknowingly hire or pay North Korean IT workers, even through a proxy, risk sanctions from the Office of Foreign Assets Control (OFAC), a financial intelligence and enforcement agency of the U.S. Department of the Treasury. OFAC administers and enforces economic and trade sanctions to support U.S. national security and foreign policy goals, as well as federal agencies.

The U.S. Department of State issued an alert on July 31, 2026, “Countries, Companies, and Other Entities Regarding North Korean IT Workers,” outlining North Korean IT Workers’ modus operandi and warning the international community and private sector of the threat they pose.


Chatlogs

We spoke with the representative, Tec Guru, on Telegram to gather more information and possibly arrange a video call. Throughout the conversations, we asked questions to determine if we were speaking to a North Korean IT worker.

We asked Tec Guru for VPN recommendations, and he replied, “Astrill VPN,” a service commonly used by North Korean threat actors. More information about our research on Astrill VPN is available in the blog post “Astrill VPN: Silent Push Publicly Releases New IPs on VPN Service Heavily Used by North Korean Threat Actors.”

During our conversation, we asked the threat actor about VPNs
During our conversation, we asked the threat actor about VPNs

We asked Tec Guru some leading questions about Asian countries, and North Korea in particular, but he replied that he knew nothing.  

Screenshot of our conversation asking about dictatorships in Asian countries
Screenshot of our conversation asking questions about Asian countries

As our conversation continued, Tec Guru revealed more details about the scam and explained how it works in a wall of text (shown below).

The threat actor explained the job ad scam in the chat log
The threat actor explained the job ad scam in the chat log

On the surface, this recruiting engagement appeared unremarkable. The recruitment pitch, the revenue split, and the offer of remote assistance during technical assessments are all consistent with interview fraud. And a model run out of many countries was not, by itself, an indicator of any particular threat actor. The operator made no confession and no clear attribution error.

The collective behavior we observed during the call raised flags, but the attribution doesn’t rest on them. It rests on the technical analysis that followed: the financial, operational, and infrastructure data the operator provided. We assess with high confidence that the operator is North Korean.

Silent Push has tracked North Korean threat activity for years. We publish additional technical detail on this adversary’s infrastructure, among many other threat actors, in our TLP Amber reports, developed exclusively for enterprise customers.


Interested in Learning More?

Start a conversation with one of our platform experts to learn how preemptive cyber defense can give your team more lead time on adversary infrastructure, before an attack is launched against your organization.

We also offer a free Community Edition so defenders can see how our platform integrates with their existing security stack.


Continuing to Track North Korean IT Workers

Our team will continue to monitor North Korean IT Workers and the many job recruitment scams currently targeting unsuspecting victims. We will report our progress as we identify new developments and expect to share more information soon. If you or your organization has any information to share, we always welcome the opportunity to collaborate.