Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

61–70 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#61
post #20

From somewhere in the depths of an old reddit thread, someone recommended asking candidates "How fat is Kim Jong Un?" Instant hang-up.

Why would this work? Spies are trained to behave like the host country would expect, why wouldn't hackers? If hackers have access to the outside world (something they would need to be effective), they'd know the world thinks Kim is fat. "He's very fat, haha!", end of story. Edit: wait, or better yet: "how on earth would I know, and why are you asking this in a job interview? Is this because I'm Korean? I'd like to fi…

These aren't spies first. They are often children of well to do, high loyalty group North Koreans. It's just a privileged job.

The skill and IQ level varies widely, from super smart to super unskilled. And these roughly get sorted out into different groups with different MO's. North Koreans aren't some uniformly skilled group. You could be targeted by a team of world class bytecode exploit geniuses who rehearses every move, or by the equivalent of Milton from Office Space.

Dissing Kim is something that is not currently widely permitted in NK. Just isn't worth personally.

Not saying no one from NK never will, but so far almost everyone will immediately stop the conversation at this point. There are plenty of crypto people who have monthly or weekly encounters with NK job applicants.

Re: We identified a North Korean hacker who tried to get a job

#62

I fail to understand the whole "advancing the candidate through the interview to learn more about how they do this" plan. They already knew the candidate's name, email, and GitHub were all part of past beaches. I could understand if they were fishing for more information to contribute to a shared list, but it seems like they knew virtually everything they needed to know. Asking the candidate to justify the inconsiste…

Dollars to donuts the NK team is reading this article and adapting their strategies. IMO, rather than ask candidates to justify inconsistencies, you should forward the information to law enforcement and tell the candidate you’re hiring somebody else.

Well they claim the final interview involved asking the candidate very specific questions about the town they claimed to be living in, and hold up government issued ID to the camera.

My assumption based on this was they weren't certain it was someone malicious and they were double checking their own conclusion. If not it makes no sense to tip the candidate off that you're suspicious about them.

At that point I'd say asking the candidate outright is better than playing a weird game of "Name 5 restaurants not on Google maps in the town you live in".

But if they were sure, then yeah, skip the interview altogether and forward the information to law enforcement.

Re: We identified a North Korean hacker who tried to get a job

#63

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Hate to be that guy, but.. what’s the problem? The work is getting done for the price you agreed on. You care how it’s done suddenly? If AI does it, it’s the best thing since sliced bread. I’m sorry but capitalists that want to have it both ways annoy me. Agree on what gets delivered for how much and get out of the way. The “employer” mindset doesn’t jive with capitalism ya’ll are so fond of.

If you don't want to be an employee then don't sign an employment contract.

Re: We identified a North Korean hacker who tried to get a job

#64
post #45

Earlier quoted context omitted.

> genuine candidates will usually pass real-time, unprompted verification tests. I wonder these are similar to the "tests" in Suits, where they (somewhat inadvertently) check whether someone went to Harvard by asking about the food places students typically went to.

Its a pretty standard thing to do when you suspect someone of being not who they say they are. WW2 German spies would claim to be from New York, and OSS or MPs would ask them who the Yankees lead pitcher was. Not really a unique or new way of doing things.

And in Ronin when Deniro asks Sean Bean the color of the boathouse at Hereford.

Re: We identified a North Korean hacker who tried to get a job

#65
post #20

Earlier quoted context omitted.

Why would this work? Spies are trained to behave like the host country would expect, why wouldn't hackers? If hackers have access to the outside world (something they would need to be effective), they'd know the world thinks Kim is fat. "He's very fat, haha!", end of story. Edit: wait, or better yet: "how on earth would I know, and why are you asking this in a job interview? Is this because I'm Korean? I'd like to fi…

These aren't spies first. They are often children of well to do, high loyalty group North Koreans. It's just a privileged job. The skill and IQ level varies widely, from super smart to super unskilled. And these roughly get sorted out into different groups with different MO's. North Koreans aren't some uniformly skilled group. You could be targeted by a team of world class bytecode exploit geniuses who rehearses ever…

I find this answer highly implausible, not the least because maintaining cover doesn't count as dissing ("I infiltrated the org by telling them the lies they wanted to hear" is hacking 101). Also, North Koreans aren't dumb.

I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it?

> Dissing Kim is something that is not currently widely permitted in NK

This wouldn't be "widely", this would be a specific interaction with a hostile foreigner for the purpose of infiltrating them. It's not the same as being allowed to say this to fellow North Koreans.

> Not saying no one from NK never will, but so far almost everyone will immediately stop the conversation at this point.

Legitimate candidates would at this point too, so as a tactic this is useless.

Re: We identified a North Korean hacker who tried to get a job

#66
> asking the candidate to verify their location, hold up a government-issued ID, and even recommend some local restaurants in the city they claimed to be in.

I don't know, if I run into these questions in a job interview, especially with a small, less known company, I would be having serious questions about what this company is doing

Re: We identified a North Korean hacker who tried to get a job

#68

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

[deleted]

Re: We identified a North Korean hacker who tried to get a job

#69

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring.

They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their team's time) but it's not a lack of basic process in this case.

I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI, these type of candidates (whether state-sponsored malicious actors or overemployment shops) are appearing in every industry and every role constantly by the hundreds. I disagree completely with other posts claiming only crypto and finance are being targeted; while it's hard to confirm and the North Korean operation specifically may be more tailored, fake candidates are rampant throughout the tech industry now.

Re: We identified a North Korean hacker who tried to get a job

#70

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Hate to be that guy, but.. what’s the problem? The work is getting done for the price you agreed on. You care how it’s done suddenly? If AI does it, it’s the best thing since sliced bread. I’m sorry but capitalists that want to have it both ways annoy me. Agree on what gets delivered for how much and get out of the way. The “employer” mindset doesn’t jive with capitalism ya’ll are so fond of.

An arrangement like that is probably violating data protection rules that everybody agreed on. In my company, customer data must not leave company systems, let alone the country.
Post reply on HN