Remote Hiring Created New Attack Vectors
Well-funded hackers, many from North Korea, submit hundreds of resumes and pose as candidates to infiltrate your intellectual property.
They use fake identities, deepfake interviews over Zoom, VPNs, and virtual machines to bypass traditional screening.
One successful attack exposes code and customer data. At the very least it wastes your recruiter time and budget in the process.
How a DPRK IT worker gets flagged
One click is all it takes. The moment an applicant confirms interest, cside cross-references their devices, network, environment, and writing, before they ever reach an interview.
Stop Fake Job Applications with Client-Side Signals
Built for Frequently Targeted Industries
How cside Applicant Check Outperforms Traditional Screening
| Feature | Applicant Check Device ID | Traditional Screening |
|---|---|---|
| Covers every browser and operating system | ✓ | Relies on IP / email only |
| Detects VMs, VPNs, and headless browsers | ✓ | Usually ignored |
| Privacy-friendly (non-sensitive signals) | ✓ | Often stores PII or cookies |
| Real-time API / webhook for ATS | ✓ | Manual log review |
Recruiters Aren't Trained to Fight Fraudsters. Filter Them Out Early.
"cside helped our insider risk program prevent infiltration before it happened. Helping security and recruiting teams focus on what really matters."
FAQ
Frequently Asked Questions
The most effective fraud detection tools for fake job applicants pair device fingerprinting with network and environment analysis instead of relying on IP or email alone. cside deploys as one first-party JavaScript snippet that fingerprints each browser session across 250+ signals, flagging virtual machines, VPNs, residential proxies, and headless browsers in real time. That lets your team auto-reject or review suspicious applications before a fake job applicant ever reaches an interview.
At various level bypass methods are being used. To prevent you from seeing where the user is applying from VPN services are used. To apply for many applications fast they generate answers to questions in forms using LLMs. When going through identity verifications fake ID cards are being used sometimes using stolen identities. During interviews life answering bots help them respond to questions. There have even been videos circulating on the web where the bad actor used deep fake technology to cover their face.
Drawing on a baseline of 250+ browser, device, and network signals, the device fingerprinting looks for signals indicating that the application is made from automated or remote environments. Essentially separating real human devices from automated environments.
Cside simply detects signals that indicate VPN use as well as using virtual machines. There are a number of methods we use. None of the methods we use compromise a users privacy, they purely relate to system hardware identifiers.
Valuable intellectual property, access to user data, source code and API access keys to sensitive environments like payment platforms mean that bad actors have the highest chance of finding high value substance to exploit your business. Independent of the role, they will try to get their hands on the highest value items to resell or extort your business.
Common red flags include a resume that fits the role a little too perfectly, reluctance to turn on a camera or a video feed that looks unnatural in interviews, a stated location or time zone that contradicts the candidate's availability, and requests to ship a company laptop to an address that is not the candidate's own. cside surfaces the technical red flags automatically: it fingerprints each browser session across 250+ signals and flags virtual machines, residential proxies, VPNs, geo mismatches, and sessions where many devices are linked to one applicant.
The scheme, documented by the U.S. Department of Justice and the FBI, involves IT workers acting on behalf of North Korea who use stolen or fabricated identities to get hired into remote roles at Western companies, then funnel their wages back and, in some cases, steal data or extort the employer. They typically hide their real location behind VPNs and residential proxies, run their work inside virtual machines, and rely on local facilitators to receive company laptops. cside does not verify identity documents, but it exposes the technical infrastructure these operations depend on, fingerprinting each application session to flag VPNs, residential proxies, geo mismatches, virtualized environments, and clusters of devices tied to a single applicant.
cside is device intelligence, not video analysis, so it does not inspect a webcam feed or score a face for deepfakes. What it does do is flag the environment these tactics rely on. Applicants who use a deepfake or a live stand-in on a call are usually operating from a virtualized or remote-controlled environment behind a VPN or residential proxy, often from a session already linked to many other applications. cside catches those signals at the application stage, before an interview is ever scheduled, so a suspicious candidate can be reviewed rather than waved through.
cside deploys as a single first-party JavaScript snippet on your application or careers page, so there is no DNS change and nothing is routed through cside. Once an applicant's session is fingerprinted, the verdict can be sent to your ATS to auto-reject or flag suspicious applications for manual review, so recruiters see the risk signal alongside the rest of the candidate record. Legitimate applications flow through untouched.
No. cside runs quietly in the browser session while a candidate fills out the application, with no extra step, no CAPTCHA, and nothing for the applicant to install. Real candidates experience the normal application flow, while the fingerprint and its verdict happen in the background. The friction lands only where it should, on the fraudulent sessions your team chooses to reject or review.
cside does not reject anyone on a single signal. It evaluates each session across 250+ signals and looks for combinations that legitimate applicants rarely produce together, such as a virtualized environment behind a residential proxy with a geo mismatch and many devices tied to one session. A candidate who simply uses a corporate VPN is not treated the same as one running inside a VM from a proxied, high-risk session. You stay in control of the threshold and whether a flagged application is auto-rejected or sent for human review.
cside fingerprints the browser session using non-sensitive technical signals about the device, network, and environment, not personal data, and it does not rely on cookies to do so. It does not read identity documents or store the kind of PII that traditional screening often keeps. That keeps applicant screening privacy compliant while still separating real human devices from the automated and remote environments fake job applicants tend to use.