False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation
2025-04-21 • Paloalto Networks •
https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/
Unit 42 reports that DPRK IT-worker operations are adopting real-time deepfake technology to pass remote job interviews under synthetic identities. The team found that a researcher with no prior deepfake experience could create a passable interview persona in about 70 minutes using free tools, a generated face, and consumer hardware, showing how accessible the technique has become. Unit 42 links the trend to known DPRK tactics around synthetic identities, compromised personal data, and evidence from the Cutout.pro breach that exposed email addresses likely tied to IT-worker activity. The recommended defenses combine HR and security controls: stronger identity verification, monitoring across the employee lifecycle, and interview checks such as hand-over-face movement, rapid head turns, expression changes, and lighting changes that can expose deepfake artifacts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | thispersonnotexist.org | 2025-04-21 | 2025-04-21 |