Silent Push Links Discord Job Scam to Suspected North Korean IT Worker Recruiting Proxies

Summary
Silent Push investigated a Discord job ad seeking Western and Latin American proxies for remote tech interviews and payments, assessing the recruiter with high confidence as a North Korean IT worker based on technical, financial, and infrastructure indicators.
Key points
- A Discord account promoted a fake job ad, and Silent Push contacted the recruiter through Telegram and a video call.
- The scheme sought people in the U.S., Europe, and Latin America to act as the public face and legal identity for remote job applications.
- The recruiter offered interview coaching and remote computer access to help proxies pass technical assessments.
- The proposed arrangement directed proxies to receive employer payments and transfer 65% to the recruiter.
- Silent Push assessed the operator as North Korean with high confidence, citing technical, financial, operational, and infrastructure indicators.
- Organizations risk identity fraud, insider access and data theft, and potential sanctions exposure if they unknowingly hire or pay North Korean IT workers.
Article Details
- Attack Vectors
- The Discord account tecguru113 posted a fraudulent job advertisement in the Mouse Review server and directed interested people to the Telegram account Tecguru0618.
- The scheme solicited people in the U.S., E.U., and several LATAM countries to serve as the on-camera and legal identity for remote job applications.
- The representative proposed coaching proxies during interviews and remotely accessing their computers to complete live coding assessments.
- The representative suggested using AI tools such as ChatGPT to help proxies answer questions and recommended Astrill VPN when asked about VPNs.
- The proposed arrangement had proxies receive employer payments into local accounts and transfer 65% to the operative.
- Defensive Notes
- Verify remote applicants’ physical locations during job interviews; Silent Push says its Traffic Origin IP solution can help identify the physical origin of web traffic.
- Assess whether the person on camera is independently completing technical interviews and coding tests.
- Organizations that hire or pay North Korean IT workers through proxies risk sanctions exposure. The article also warns of potential intellectual-property theft and extortion after hiring; it does not report those outcomes in this investigation.
MITRE ATT&CK
T1219 · Remote Access ToolsThe representative offered to remotely access a proxy’s computer to complete live coding tasks while the proxy continued the interview.T1656 · ImpersonationThe proposed hiring scheme used a proxy’s face and legal identity to represent a different worker in interviews and employment.
Vendors
Products
Astrill VPNAfter connecting via Telegram, we asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised us to use Astrill VPN, a VPN often used by North Korean IT workersChatGPTAI-Assisted Impersonation: Explicitly suggests the proxy use AI tools (e.g., ChatGPT) to generate response prompts and bridge knowledge gaps on the fly.DiscordSilent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord ServersGoogle MeetReal-time Technical Proxying / Live Coaching: Using platforms such as Google Meet to provide real-time messaging, answers, and coding assistance during live interviews while the proxy sits on camera for the potentialTelegramAfter connecting via Telegram, we asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised us to use Astrill VPN, a VPN often used by North Korean IT workersTraffic Origin IPIn addition to the Silent Push preemptive cyber defense platform for proactive protection, our Traffic Origin IP geolocation and reputation solution provides important information about the physical origin of web
Countries
ArgentinaThe threat actor explicitly solicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/location blocks and regionalBrazilTargeting: The threat actor explicitly solicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/locationChilesolicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/location blocks and regional tax compliance checks.Colombiaactor explicitly solicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/location blocks and regional taxMexicoTargeting: The threat actor explicitly solicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/location blocks andNorth KoreaAs we started to run out of questions to ask, we mentioned countries such as Iran, Russia, and North Korea.United StatesGeographic Targeting: The threat actor explicitly solicited individuals based in the U.S., E.U., and LATAM (Brazil, Mexico, Argentina, Colombia, and Chile) to serve as “proxies” who can bypass geographic IP/location