Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

41–50 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#42

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

If this harms the crypto industry even a little I'm not sure I'd feel even a twinge of sympathy. Is there anything I can do to assist NK in these affairs?

Re: We identified a North Korean hacker who tried to get a job

#43

I fail to understand the whole "advancing the candidate through the interview to learn more about how they do this" plan. They already knew the candidate's name, email, and GitHub were all part of past beaches. I could understand if they were fishing for more information to contribute to a shared list, but it seems like they knew virtually everything they needed to know. Asking the candidate to justify the inconsiste…

Dollars to donuts the NK team is reading this article and adapting their strategies. IMO, rather than ask candidates to justify inconsistencies, you should forward the information to law enforcement and tell the candidate you’re hiring somebody else.

Re: We identified a North Korean hacker who tried to get a job

#44

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

This sounds unnecessarily dismissive. It was a quick and interesting read, and there are some useful data points for every company that is hiring to improve their processes.

Re: We identified a North Korean hacker who tried to get a job

#45
post #2

> Not all attackers break in, some try to walk through the front door. Now made even easier for fraudsters and including state actors thanks to Generative AI. Also: > Generative AI is making deception easier, but isn’t foolproof. Attackers can trick parts of the hiring process, like a technical assessment, but genuine candidates will usually pass real-time, unprompted verification tests. This is why Leetcode / Hacker…

> genuine candidates will usually pass real-time, unprompted verification tests. I wonder these are similar to the "tests" in Suits, where they (somewhat inadvertently) check whether someone went to Harvard by asking about the food places students typically went to.

Its a pretty standard thing to do when you suspect someone of being not who they say they are. WW2 German spies would claim to be from New York, and OSS or MPs would ask them who the Yankees lead pitcher was. Not really a unique or new way of doing things.

Re: We identified a North Korean hacker who tried to get a job

#46

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

How do weekly 1:1 meetings with a manager not catch this very quickly? Okay, maybe the original suave interviewer comes back for those… Still feels like a good EM would pick up on discrepancies between work done and how the suave person talks about it. It depresses me, but you’re probably right about in-office work being the only guarantee against this type of scam. I wish we could just have nice things.

This isn't necessarily the issue here -- this attempt seemed to be fairly motivated and had access to resources (AI, coaches, ...) to help them get through the process.

IF they can get such a 'candidate' hired... whats to say they couldn't continue the sham. One could imagine a team of hackers could easily pass of work that a single IC could reasonably have produced.

If their goal is exfiltration (or some other hack) of a {bitcoin exchange, govt, ...} actually putting in {weeks/months/year[s]} of actual work to insert someone into the right position at the right company is insanely worth it.

Re: We identified a North Korean hacker who tried to get a job

#47

This is pretty common stuff I saw with just even regular startups with remote applicants -- I take their claim that it was NK hacker with a grain of salt.

The interview a friend conducted a few weeks ago had a rich GitHub account of shoddy code across what was no less than 15 different languages, and a lot of it, all with names related to interview questions (many having the company name in them).

The interview call over zoom was clearly an AI avatar, and the answers were verbally spoken but constructed in a "bulleted" way that an LLM might produce.

All of the timestamps in the commits were made with the KST timezone.

Re: We identified a North Korean hacker who tried to get a job

#48

Earlier quoted context omitted.

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

If this harms the crypto industry even a little I'm not sure I'd feel even a twinge of sympathy. Is there anything I can do to assist NK in these affairs?

“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto.

If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).

Re: We identified a North Korean hacker who tried to get a job

#49

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Totally agreed. The number of "engineers" who try to cheat their way through interviews, juggle multiple jobs without disclosing them makes it a total nightmare.

Re: We identified a North Korean hacker who tried to get a job

#50

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

last years falcon (crowdstrike specific conference) they for the first time every showed live the interviews of 3 north koreans trying to get a job in software engineering positions at some forture 500 companies. i was baffled at every 'security' question to validate the person is actually in the US gets glossed over like: "my ID is at my home right now, and im in my office so i don't have that with me".
Post reply on HN