Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

21–30 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#21

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person.

This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

Re: We identified a North Korean hacker who tried to get a job

#22
post #5

This is an interesting article, but doesn't this: > our Red Team launched an investigation using Open-Source Intelligence gathering (OSINT) methods. basically mean "some guys in the company googled him"?

You can go further. Reach out to data brokers and see whether they've got any information from ad tracking / leaks.

Is that OSINT, at that point? I guess maybe if you get a free trial, but isn't that stretching the definition a bit?

Re: We identified a North Korean hacker who tried to get a job

#23
This is cool, but we'd be naive to think the other side is not also learning from this operation. The "gotcha" questions that foiled them at the end will likely make it into their playbook for next go around, and these attacks are going to be more sophisticated.

Re: We identified a North Korean hacker who tried to get a job

#24

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

How do weekly 1:1 meetings with a manager not catch this very quickly? Okay, maybe the original suave interviewer comes back for those… Still feels like a good EM would pick up on discrepancies between work done and how the suave person talks about it.

It depresses me, but you’re probably right about in-office work being the only guarantee against this type of scam. I wish we could just have nice things.

Re: We identified a North Korean hacker who tried to get a job

#25
I fail to understand the whole "advancing the candidate through the interview to learn more about how they do this" plan.

They already knew the candidate's name, email, and GitHub were all part of past beaches. I could understand if they were fishing for more information to contribute to a shared list, but it seems like they knew virtually everything they needed to know.

Asking the candidate to justify the inconsistencies outright would've been just as helpful as the final interview IMO.

Is there something I'm missing there?

Re: We identified a North Korean hacker who tried to get a job

#27
Someone said that North Koreas are trying to get jobs. Ok

Then they had a candidate who was trying to cheat the systemeat

How did they establish and verify that the candidate was North Korean? Are North Koreans the only ones who try to remote work byt lying about their whereabouts?

Not at all.

If you live in a country outside of the US and you see the money software poeple make in the US it is mighty tempting to land a gig.

The fact that the persdon made simple mistakes and needed to be coached does not sound like a North Korean state operation.

If someone had told them Russian hackers are trying to get jbos.

Would they have asummed the person was Russian?

Re: We identified a North Korean hacker who tried to get a job

#30
North Korea's efforts have been evolving.

In the past, they just tried to break into bank computers, then into crypto company's computers. For the last two years, they've been working on getting people into crypto companies.

But now they appear to have enough people to spare than they also have groups working on "honest" employment as remote workers, who may not even have theft as the first thing on their mind.

Here's a federal case where a US woman was convicted of helping North Korea steal the identities of 70 people, and then remote in as them, to do remote work:

https://www.justice.gov/usao-dc/pr/arizona-woman-pleads-guil...

Post reply on HN