Silent Push cybersecurity researchers have identified a suspected North Korean IT worker operation that recruits foreign nationals as proxies for job interviews. The scheme utilizes individuals in the United States, Europe, and Latin America to impersonate candidates on camera, complete identity checks, receive payments, and conceal the true worker's location. The activity was detected through a suspicious job advertisement posted in the "Mouse Review" Discord server.
The account, identified as "tecguru113," advertised a position seeking individuals who could serve as the public face of an IT job candidate. Silent Push researchers contacted the linked Telegram account, "Tecguru0618," using a controlled persona to investigate the offer.
The proxy was expected to participate in video interviews, interact with clients, and showcase technical skills that might not actually belong to them. Foreign recruits can assist overseas workers in bypassing employer checks related to geography, sanctions, tax rules, Know Your Customer requirements, and IP-address restrictions. This included sending answers through chat, coaching the proxy during video calls, or remotely controlling the proxy’s computer during coding tests.
Researchers recorded a video chat with the suspected operator, who quickly shut off the camera when the conversation turned to North Korea. The real worker could potentially gain access to company systems, source code, customer data, cloud environments, and internal communications.











