shiichan

Remote-Controlling Company Laptops? OpenAI Uncovers New Tricks in a North-Korea-Linked Fake Hire Scheme

Hey, it's Shiichan! I've got another OpenAI report on countering misuse of AI, and this one gets pretty high-tech with its fake-hiring tricks.

OpenAI News openai.com

What was announced?

OpenAI's News reported that it banned ChatGPT accounts tied to what appeared to be multiple deceptive employment campaigns. The banned accounts had used OpenAI's models to develop materials supporting possibly fraudulent applications for IT, software engineering, and other remote jobs around the world. OpenAI couldn't pin down the operators' locations or nationalities, but their behavior matched what's been publicly reported about North Korea (DPRK)-linked IT worker schemes. Some of the actors behind this activity may have been contractors hired by the core DPRK-linked group to handle application tasks and operate hardware, including within the US.

Why it matters

OpenAI published a report on a similar North Korea-linked employment deception campaign back in February 2025. Back then, the actors used AI to manually build credible personas with fabricated employment histories at well-known companies, one at a time. This time, they attempted to automate resume creation itself, and there were signs of applicants apparently based in Africa, plus recruitment of people in North America to run laptops on the operators' behalf. The takeaway: fake-hire schemes are becoming easier to scale up with AI.

What changes

OpenAI identified two distinct types of operator, each playing a different role.

  • Core operators: tried to automate resume creation based on job descriptions, skill templates, and persona profiles, and researched tools for managing and tracking job applications. They also generated job-posting-style text to recruit contractors around the world.
  • Likely contractor operators: used ChatGPT to help complete actual job application tasks, and to draft messages to the core operators asking about payments and personas.

Core operators also used ChatGPT as a research tool for setting up remote-work environments, including generating text to recruit people in the US willing to receive company-issued laptops. OpenAI shared what it learned from this takedown with industry peers and relevant authorities.

Dive Deep

What stood out most was the set of tools the operators were researching.

  • Tailscale (peer-to-peer VPN)
  • OBS Studio (streaming/recording software)
  • vdo.ninja for injecting live video feeds
  • HDMI capture loops

Tools like these could be used to circumvent corporate security measures, maintain an undetected persistent remote presence, and get around identity checks that rely on live video calls. OpenAI grouped these misuse patterns as follows:

  • Automating detailed resumes aligned to job descriptions, personas, and industry norms: LLM Supported Social Engineering
  • Answering employment application questions, coding assignments, and real-time interview questions based on uploaded resumes: LLM Supported Social Engineering
  • Seeking guidance on remotely configuring corporate laptops to appear domestically located, including geolocation masking and endpoint security evasion: LLM-Enhanced Anomaly Detection Evasion
  • Getting coding help for tools that move the mouse automatically or keep a computer awake remotely: LLM Aided Development

OpenAI itself declined to say how successful this activity actually was, noting that assessing impact would require input from multiple stakeholders. Still, it pointed out that by weaving AI into nearly every step, the operators also left behind more clues that helped OpenAI piece their methods together.

Wrap-up

  • OpenAI banned ChatGPT accounts tied to multiple suspected deceptive employment campaigns
  • The tactics matched North Korea (DPRK)-linked IT worker operations, with both core operators and likely contractor operators identified
  • New elements included automated resume generation, apparent applicants based in Africa, and recruitment of North American laptop operators
  • Operators researched tools like Tailscale, OBS Studio, vdo.ninja, and HDMI capture loops that can bypass corporate security and identity checks
  • The range of tricks also included geolocation spoofing and requests for help with mouse-automation tools

If you're involved in remote hiring or corporate security, this one might make you sit up a little straighter!