Key facts
- North Korean hackers are using AI to disguise cyberattacks as fake online job interviews.
- The hackers trick applicants into running malware to steal cryptocurrency.
- Over 30,000 devices in more than 100 countries have been compromised.
North Korean state-backed hackers are leveraging AI tools, including voice changers and deepfake technology, to impersonate job applicants and steal cryptocurrency. The sophisticated scams have compromised over 30,000 devices globally and resulted in over $10 million in stolen digital assets.

The increasing sophistication of AI-powered cybercrime poses a significant threat to businesses and individuals, enabling large-scale theft of digital assets and compromising sensitive company data. This highlights the growing need for enhanced cybersecurity measures and employee vigilance against advanced social engineering tactics.
North Korean hackers are employing advanced AI technologies to conduct sophisticated cyberattacks, masquerading as legitimate job applicants to infiltrate companies and steal cryptocurrency. These state-backed actors are using AI to generate fake identities, alter stolen identification documents with deepfake technology, and employ voice-changing software to mask their accents during remote interviews. This allows them to pass as credible candidates for IT and software development roles in Western firms.
According to Microsoft, groups identified as Jasper Sleet and Coral Sleet are at the forefront of this tactic. They leverage AI across the entire attack lifecycle, from creating "culturally appropriate" names and email formats for applications to scouring job postings for relevant roles. Once hired, the fake workers use AI to generate emails, translate documents, and write code, aiming to avoid detection and maintain their employment.
Japanese authorities reported that these North Korean actors compromised over 30,000 devices in more than 100 countries and regions between late 2025 and July 2026. The scheme has resulted in the theft of over $10 million in cryptocurrency. Microsoft also noted that they disrupted approximately 3,000 Microsoft Outlook or Hotmail accounts used by these fake IT workers last year. Companies are advised to conduct interviews in person or via video to better detect deepfake or AI-generated content.