216.73.217.22

Inside DPRK's Fake Job Platform Targeting U.S. AI Talent

· Published 26/11/2025 10:07 · Modified 21/12/2025 18:05

Export JSON

Essential information

Published
26/11/2025 10:07
Modified
21/12/2025 18:05
Tags
2025-11-26 ai talent clickfix clipboard hijacking contagious interview cryptocurrency fake job platform malware delivery social engineering
Related entities
2 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware, 7 others

Description

This analysis details a sophisticated DPRK-linked operation called , which uses a to target U.S. . The campaign mimics legitimate recruitment processes, offering job listings from well-known tech companies to lure victims. The platform, hosted at lenvny[.]com, is designed to appear as a legitimate AI-powered interview tool. It employs various techniques to establish credibility, including professional design, fake testimonials, and comparisons with real companies. The attack culminates in a through a technique, triggered when victims attempt to record a video introduction. This operation specifically targets high-value professionals in AI and sectors, aiming to gain access to strategic information and financial assets.

External references