
North Korean tech operatives are now using advanced live deepfake technology during video interviews to infiltrate organizations worldwide. This sophisticated approach creates convincing synthetic identities in real-time, enabling them to circumvent standard verification protocols and gain employment for both financial exploitation and possible intelligence gathering.
This represents a major tactical evolution beyond their previous reliance on static fake profiles and stolen identity credentials for securing remote work. The DPRK has long shown expertise in identity deception, having previously developed synthetic personas backed by compromised personal data.
Their latest strategy features real-time facial manipulation during video calls, potentially allowing a single operative to interview repeatedly for the same position while presenting entirely different synthetic identities.

This tactic also helps operatives avoid detection and prevents them from being flagged in security bulletins or wanted notices issued by international law enforcement agencies.
Researchers at Palo Alto Networks’ Unit 42 uncovered this trend after analyzing indicators shared in The Pragmatic Engineer newsletter, which featured a case study of a Polish AI company that encountered two separate deepfake job candidates.
According to the researchers, both personas were likely controlled by the same individual. Notably, the person appeared more confident during the second technical interview, likely due to prior familiarity with the interview format.
Real-Time Deepfake Activity
Additional evidence came to light when Unit 42 investigated a breach at Cutout.pro, an AI-powered image editing platform. The analysis revealed a number of email addresses that appear linked to DPRK-affiliated IT worker operations.

The investigation revealed numerous instances of face-swapping techniques being used to generate highly convincing professional headshots for synthetic identities.
What makes this threat especially alarming is how easily accessible the technology has become. Researchers showed that a single person—with no prior experience in image manipulation—could craft a realistic synthetic identity suitable for job interviews in just 70 minutes, using commonly available hardware and software.
Technically, these deepfakes are created using generative adversarial networks (GANs) to produce lifelike facial images, paired with facial landmark tracking software that maps the operator’s expressions onto the synthetic face in real time.
The manipulated video feed is then passed through virtual camera software, allowing the deepfake to appear as a standard webcam input during video calls.
Despite their sophistication, real-time deepfake systems still have detectable weaknesses. They often struggle with fast head movements, occlusion (such as hands covering part of the face), adapting to changing lighting conditions, and maintaining proper audio-visual sync.
For example, when an operator’s hand passes across their face, the system frequently fails to reconstruct the partially hidden features, resulting in visual artifacts. Likewise, abrupt lighting changes can expose inconsistencies in facial rendering, particularly around the edges.
To address this growing threat, organizations should adopt layered identity verification measures throughout the hiring process. This could include requiring candidates to perform movements that challenge deepfake capabilities—such as turning their head to the side, gesturing near the face, or tilting the head so the ear touches the shoulder.



