Silent Push identified a fraudulent recruitment campaign operating through the “Mouse Review” Discord server and a Telegram persona known as “Tec Guru,” which solicits U.S., EU, and Latin American residents to act as employment proxies for a suspected North Korean IT worker. Recruits are instructed to complete identity verification, appear in video interviews, receive employer payments, and remit 65% of their earnings to the operator.
The operator allegedly uses real-time interview coaching, potential remote-desktop access, AI-generated answers, VPNs, VoIP services, and cryptocurrency or other payment channels to bypass hiring, KYC, geographic, and sanctions controls. Silent Push assesses with high confidence that the activity is tied to a North Korean IT worker operation; employers that unknowingly hire such proxies face risks of insider access, data theft or extortion, and potential U.S. sanctions exposure administered by OFAC.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of State issued an alert concerning countries, companies, and other entities associated with North Korean IT workers.
Silent Push investigated a fraudulent job-recruitment advertisement distributed by the tecguru113 Discord account in the Mouse Review server and traced recruits to the Telegram persona Tec Guru. The company assessed with high confidence that the operator was a North Korean IT worker seeking proxies in the United States, EU, and Latin America to bypass identity, location, KYC, and sanctions controls.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesilentpush.com
Open sourceofac.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.