case file 04proxy interviewOctober 2025Mexico, remote pipeline
from Jalisco, without the Spanish
Bitso's security team documented two applicants for a senior engineering role who used stolen resumes and AI-generated faces, said they were from Jalisco and Chihuahua, and could not speak Spanish. Their LinkedIn profiles vanished after the interviews.
2
applicants, one role
0
words of Spanish spoken
same day
profiles deleted after the call
what happened
Bitso, a Latin American cryptocurrency exchange, was hiring a senior engineer. Two applicants, presenting as Mateo and Alfredo, applied with stolen resumes and AI-generated profile photos. One said he was from Jalisco. One said he was from Chihuahua. Neither spoke Spanish.
Both connected through Astrill VPN, the anonymizer named repeatedly in Microsoft's and the FBI's reporting on North Korean IT workers, tunnelling out to U.S. residential addresses associated with laptop farms. One joined the call with his camera off.
After the failed interviews, both LinkedIn profiles disappeared.
“He applied for the position, saying he was from Jalisco, México. He joined the call without his camera on.”
Sofía, talent acquisition specialist, Bitso
how it was caught
By a talent acquisition specialist who spoke Spanish and asked a question in it. The candidate could not answer.
Bitso's security team then pulled the network data and found the VPN tunnels and the residential exit addresses tied to known laptop farm infrastructure, confirming the pattern.
what it cost
No hire was made, so the cost was interview time and the security investigation that followed.
The case matters because it shows the geography has moved. This is no longer only American companies hiring supposedly American workers. The same operation targets Latin American companies with supposedly Latin American identities.
the tells
signals that were visible, in hindsight, before anyone was hired.
- A claimed home region whose language the candidate cannot speak.
- Camera off, or camera trouble, at the start of the call.
- A residential IP address that does not match the claimed city.
- A VPN or anonymizer between the candidate and the interview.
- A LinkedIn profile that disappears immediately after a failed interview.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
Both candidates joined through infrastructure built to disguise where they actually were. Because the interview runs on aperture rather than a general meeting app, the session is something that can be examined at all.
A candidate who says they are in Jalisco and a session that says otherwise is a contradiction, and it is visible from the moment the interview begins rather than months into employment.
A camera-off interview is not one you can verify. aperture runs a live, verified session for everyone who applies, which removes the need for a recruiter to guess who deserves scrutiny.
sources
- [1]Interview with the Chollima III
Quetzal, Bitso security team · firsthand account · October 30, 2025
Two applicants claiming to be from Jalisco and Chihuahua who spoke no Spanish, tunnelling through Astrill VPN to U.S. residential addresses tied to laptop farms.
- [2]Jasper Sleet: North Korean remote IT workers' evolving tactics to infiltrate organizations
Microsoft Threat Intelligence · security research · June 30, 2025
3,000 accounts suspended. Documents face-swap edits onto stolen IDs, voice changers in interviews, and Astrill VPN plus remote-management tooling.
- [3]Unmasking the DPRK remote worker problem
Silent Push · security research · January 2026
How laptop-farm proxy chains defeat geofencing, so an interview that looks like it comes from a U.S. home is routed from overseas.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
deepfake · March 2025
put your hand in front of your face
Hiring for one backend role out of about 500 applicants, security startup Vidoc got two AI-deepfaked candidates deep into its pipeline. One was exposed by a request that took three seconds: cover part of your face with your hand.