candidate fraud, explained

someone is applying to your job as somebody else.

this page is the whole thing in plain english. what candidate fraud is, how the North Korean IT scam actually works, how a deepfaked face gets onto a video interview, the tells your team can watch for, and the open source threat intelligence anyone can read. no jargon, no fear-selling. every number links to whoever published it.

how candidate fraud is actually done

the methods on record.

each one has been documented at a named company, with primary sources. it is not a closed list.

the North Korean IT scam

not a lone hacker. a government program.

thousands of North Korean IT workers, operating principally from China and Russia, apply for remote positions at American companies under stolen or fabricated American identities. their wages fund the regime's weapons programs, and the Department of Justice, the Treasury, and the FBI have confirmed it publicly since 2022. here is what is on the record: the scale of it, and the people behind it.

~$800M

generated in 2024, per the U.S. Treasury

U.S. Department of the Treasury

5,000+

companies targeted through mid-2025, per Okta

Okta Threat Intelligence

320+

detected fraudulent hires in 12 months, per CrowdStrike

CrowdStrike, via CyberScoop

up to 90%

of the worker's wages kept by the regime

U.S. Department of the Treasury

wanted by the United States

North Korean nationals, indicted for an $88 million scheme.

employees of the sanctioned front companies Yanbian Silverstar and Volasys Silverstar, charged in December 2024 with a multi-year conspiracy to obtain remote IT employment at U.S. companies under false identities. the Department of State offers a reward of up to $5 million for information leading to the disruption of the network.

these are the ones with a name and a photograph. how many are in your pipeline right now?

Rewards for Justice

14 named individuals, reward up to $5,000,000 for information

photographs: U.S. Department of State, Rewards for Justice. United States government works, in the public domain.

at no point does any of these workers appear on camera as themselves. that is the entire mechanism.

read the laptop farm case

the operation, end to end

follow the scam from identity to payout.

our map of how a fraudulent hire actually happens, built from the DTEX syndicate research and the Justice Department's charging documents. select any stage to read it. the marked stages are the ones aperture interrupts.

03 · get through hiring

the live session

the only point in the whole operation where the real human being must be present. face-swap overlays, voice changers, coached scripts, answer-feeding tools, or a proxy sitting the call in their place.

run by · job seekers, proxies, skill trainers

where aperture interrupts

this is where aperture works. NeuralPrint reads the person continuously, and every follow-up is built from the previous answer, so there is nothing to rehearse and nothing to look up.

legend

  • aperture interrupts
  • the main path
  • supporting ecosystem

our map. stages and roles follow DTEX research and DOJ charging documents.

the organisation behind one application

you are not screening a candidate. you are screening a syndicate.

DTEX Systems mapped the full production line behind a single fraudulent application: the trainers who prepare the candidate for your specific job description, the forgers who issue the identity, the facilitators who make the hire look domestic, the project managers who run them once you hire, and the launderers who move the salary. the recruiter on the other side of the call sees one person.

01

DPRK origin roles

prepare the candidate

prepare job seekers for specific roles and tailor their skillsets for the interview they are about to sit.

02

international facilitators

03

supporting ecosystem

04

victims

chart adapted from Figure 12, DTEX Systems, “Exposing DPRK's Cyber Syndicate and Hidden IT Workforce”, May 2025.

deepfakes

deepfakes have reached the interview.

a deepfake candidate is a real person, typically a proxy or a North Korean IT worker, presenting another person's face and voice over live video. the software is freely available, runs on consumer hardware, and has been identified in interviews at security companies, startups, and Fortune 500 firms.

a human catches some of this on a good day — a lagging mouth, a hand that breaks the filter. NeuralPrint reads the person continuously across the whole session, so the difference between a rendered face and a live one shows up as a measurement, not a hunch. every tell a human can notice is below, at what a fake candidate actually looks like.

“it took just over an hour with no prior experience to figure out how to create a real-time deepfake using readily available tools and cheap consumer hardware.”

Palo Alto Networks Unit 42, April 2025
how detection actually works
a photograph of an indicted North Korean IT worker, used to illustrate a real-time face swap
live session
00:00NeuralPrint

neuralprint reading

session in progress

real personconfirmed
consistencystable
confidence0.97

illustration of the technique. photographs: U.S. Department of State, Rewards for Justice, public domain.

the tells

what a fake candidate actually looks like.

29 signs pulled from FBI advisories, security research, and recruiters who caught one — grouped by where in your process they show up. none proves fraud alone. several together, in the same hire, is the pattern every case below shares.

watching for all of this, on every call, for every candidate, forever, is not something a human can do at scale. that is the reason aperture checks all of it automatically, on every session.

open source threat intelligence

we monitor the intelligence the investigators publish.

the North Korean IT scam leaves a documentary trail: indicted individuals, sanctioned front companies, and thousands of identifiers published by the Department of Justice, the Treasury, and security researchers. recruiters who have been impersonated publish the addresses used in their name. we collect all of it and check every applicant against it.

what we match on every applicant

  • identifiers named in government advisories
  • personas documented in published security research
  • infrastructure tied to known laptop farms
  • sanctioned front companies and their aliases
  • repetition across your own applicant pool
  • addresses reported by the recruiters they impersonate

a hit is never a silent rejection. it is a flag on the candidate with the matching source attached, so your team can read exactly why.

browse the source library
feeds we ingest

every source above is public. most hiring teams do not consult them. aperture does, for every applicant.

what a session answers

the questions we answer, on every session.

NeuralPrint reads the person. λ-CORE reads the evidence. background verification and open source threat intelligence run alongside. everything a session captures is bound to it over an encrypted channel, and what reaches your team is a clear determination with the reasoning attached.

01

is this a real person?

NeuralPrint axon

NeuralPrint reads a candidate the way a person does, only continuously and without getting tired. face, voice, gesture, timing, the texture of how someone actually speaks. a rendered face and a live one do not behave the same way, and the difference is measurable across a whole session rather than at one moment a candidate can prepare for.

what you get

a live human being, present for the whole session.

02

are the answers their own?

adaptive questioning

every follow-up is built from the answer just given, so there is no question list to look up, rehearse, or feed to a second screen. an answer that came from somewhere else cannot survive being asked what happened next. the session also runs on our platform rather than a general meeting app, which is what makes it reviewable at all.

what you get

their own answers, about their own work.

03

can they actually do the job?

λ-CORE

λ-CORE scores six behavioral dimensions against everyone else who applied for the same role, with a confidence interval on each, because a single number with no context is a guess. the ranking sharpens as more candidates interview.

what you get

a ranked pool where every score carries its reasons.

source library

everything on this site, traced back to who said it.

department of justice press releases and indictments, treasury sanctions, fbi advisories, security research, press coverage, and firsthand accounts from recruiters and security teams. all public, all linked.

showing 15 of 48 sources

security research

Okta Threat Intelligence

September 30, 2025

North Korea's IT workers expand beyond U.S. big tech

130+ tracked identities linked to 6,500+ first-round interviews at more than 5,000 companies through mid-2025.

security research

Endorsed, via Fortune

September 1, 2026

47 percent of U.S. remote IT applications now show North Korean fraud patterns

Based on 175,000 flagged applications analysed in 2026, up from 11 percent in Q3 2024. Endorsed's David Head cautions that no single trait should make an applicant look suspicious on its own.

press

Fortune

October 4, 2025

How North Korean IT workers fund Kim Jong Un's weapons program from inside American companies

FBI estimate of hundreds of millions to $1 billion over five years; UN Panel estimate of $250 to $600 million a year; an estimated 1,000 to 10,000 active fake employees.

firsthand account

Quetzal, Bitso security team

October 30, 2025

Interview with the Chollima III

Two applicants claiming to be from Jalisco and Chihuahua who spoke no Spanish, tunnelling through Astrill VPN to U.S. residential addresses tied to laptop farms.

u.s. treasury

U.S. Department of the Treasury

November 4, 2025

Treasury sanctions DPRK bankers and Korea Mangyongdae Computer Technology Company

Eight individuals and two entities laundering IT-worker and cybercrime proceeds. Treasury notes over $3 billion stolen by North Korea-affiliated cybercriminals over three years.

security research

Palo Alto Networks Unit 42

November 2023

Two campaigns by North Korean bad actors target job hunters

Named the Wagemole fraudulent-worker campaign and the Contagious Interview lure that targets job seekers with malware.

dept. of justice

U.S. Department of Justice

May 6, 2026

Two U.S. nationals sentenced for facilitating fraudulent remote information technology worker scheme

Matthew Knoot and Erick Ntekereze Prince, 18 months each. DOJ noted these were the seventh and eighth U.S. laptop-farmer convictions in five months.

security research

DTEX Systems

May 2025

Exposing DPRK's Cyber Syndicate and Hidden IT Workforce

Figure 12 of this report maps the full crime syndicate behind a single fraudulent application: skill trainers, social engineering specialists, credential forgers, laptop farm and payment facilitators, project managers, and money launderers. Carries forewords from Kevin Mandia and former Principal Deputy Director of National Intelligence Sue Gordon.

press

Fortune

May 18, 2025

Inside North Korea's IT worker program: 'this is the mafia'

Workers organized in competing teams, 16-hour days, quotas, and one worker keeping $200 of a $5,000 monthly wage.

fbi

FBI Internet Crime Complaint Center

May 16, 2024

U.S. businesses and facilitators enabling North Korean IT worker fraud (PSA)

dept. of justice

U.S. Department of Justice (via GlobalSecurity mirror)

May 16, 2024

Charges and seizures brought in fraud scheme aimed at denying revenue for workers associated with North Korea

Mirror of the DOJ release; justice.gov's archived copy is behind a bot check. DOJ called it the largest case of its type ever charged.

u.s. treasury

U.S. Treasury, State Department and FBI

May 16, 2022

Guidance on the Democratic People's Republic of Korea information technology workers (tri-seal advisory)

The baseline U.S. government description of the scheme, including per-worker earnings of up to $300,000 a year and the red flags hiring teams should watch for.

security research

DTEX Systems

May 14, 2025

i3 threat advisory: inside the DPRK

Catalogues observed risk indicators: KVM-over-IP devices, anti-screen-lock utilities, OBS and ManyCam misuse to inject several workers into one video call, sessions running for days.

press

CNBC

March 9, 2025

Meet the 21-year-old helping coders use AI to cheat in Google and other tech job interviews

Documents the Interview Coder tool and reports that Google was considering moving away from virtual interviews in response.

security research

DTEX Systems, via CyberScoop

March 31, 2025

7 percent of a Fortune Global 2000 customer base under active North Korean infiltration investigation

DTEX co-founder Mohan Koo: some of the infiltrators under investigation have the keys to the kingdom.

frequently asked questions

plain answers about candidate fraud and what aperture does about it

still have questions? get in touch →

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes