Inside DPRK's Fake Job Platform Targeting U.S. AI Talent

2025-11-20 Validin

https://www.validin.com/blog/inside_dprk_fake_job_platform/

Thumbnail for Inside DPRK's Fake Job Platform Targeting U.S. AI Talent

Validin tracks a DPRK-linked Contagious Interview variant that uses a polished fake hiring platform at lenvny[.]com to target job seekers, including software developers, AI researchers, cryptocurrency professionals, and other technical candidates. The operation differs from DPRK IT-worker impersonation schemes by compromising real applicants through a staged recruiting flow: LinkedIn contact, interview process, video-answer request, ClickFix-style webcam troubleshooting, and malware delivery. The lure is built as a React/Next.js job portal with realistic company pages, UUID-driven job listings, resume upload prompts, social-proof elements, and impersonated AI, crypto, and Web3 brands such as Anthropic, Yuga Labs, Anchorage Digital, and Digital Currency Group. Its completeness and startup-like design language make the malicious workflow look like a normal hiring process, increasing the chance that victims will submit identity details and follow later malware-delivery instructions.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.lever.co/ 2025-11-20 2025-11-20
URL https://app.lenvny.com/cam-v-ab… 2025-11-20 2025-11-20
URL https://drivers.softpedia.com/d… 2025-11-20 2025-11-20
DOMAIN carrerlilla.com 2025-11-20 2025-11-20
DOMAIN app.lenvny.com 2025-11-20 2025-11-20
DOMAIN drivers.softpedia.com 2025-11-20 2025-11-20
DOMAIN lenvny.com 2025-11-20 2025-11-20
DOMAIN assureeval.com 2025-11-20 2025-11-20
DOMAIN advisorflux.com 2025-11-20 2025-11-20
IPv4 72.61.9.45 2025-11-20 2025-11-20
IPv4 69.62.86.78 2025-11-20 2025-11-20

Related Actors

Related Reports

« Back