Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

91–100 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#91
There are so many talented people trying to get their first or second job in the cybersecurity industry. Legit, honest, hard-working individuals want to get their chance in cybersecurity. So many posts from cybersecurity companies saying, "Meet us at conferences! Write content! Get to know us, then we'll hire you!" Then in their article they write this. Companies that are even letting these resumes or candidates get a second look are disgraceful. Companies need to get their shit together.

What happened to standard procedures? 1. Phone interview. 2. Video interview. 3. In-person interview. 4. Job offer and hired. Heck, even standard was 1. Phone interview. 2. In-person interview. 3. Job offer and hired.

> From the outset, something felt off about this candidate. During their initial call with our recruiter, they joined under a different name from the one on their resume...

Re: We identified a North Korean hacker who tried to get a job

#92
Apparently they're white brainwashed around Kim Jong Un and simply can't process any discussions that are even remotely negative about their dear leader.

Use this to your advantage during the interview process to weed them out: https://news.ycombinator.com/item?id=43853382

Re: We identified a North Korean hacker who tried to get a job

#93

Earlier quoted context omitted.

I've heard through the grapevine of some designers (one who worked at Shopify) getting caught using Fiverr (or something similar) to farm out all of their work. Despite all the weird crazy dog and pony show and jumping through hoops that most companies do now, most companies are abysmal at hiring.

What can you do during the hiring process to know that this amazing person, who aces every part of the interview, will farm out their work to cheap subcontractors?

Nothing I guess? Except that they will continue to be vetted after being hired for the quality of their work.

just spitballing but even if someone has a remote computer after getting hired, and is onboarded they should not have access to sensitive systems. So while you can't completely prevent the possibility of hiring a malicious actor security should not simply be on/off. The register article mentioned how after these devs were hired they were immediately able to kick off their plans. I think security is not structured properly if that is the case.

Re: We identified a North Korean hacker who tried to get a job

#94
post #66

> asking the candidate to verify their location, hold up a government-issued ID, and even recommend some local restaurants in the city they claimed to be in. I don't know, if I run into these questions in a job interview, especially with a small, less known company, I would be having serious questions about what this company is doing

"yeah, could you just hold up that ID please... Thanks, also a few more questions..Who was your favorite teacher, and what was the first car you owned ?"

Re: We identified a North Korean hacker who tried to get a job

#95
post #52

Earlier quoted context omitted.

So that's probably a sign that your team culture and management isn't the best... Healthy teams communicate a lot and really get to know each other, whether in person or remote. Ideally with regular in-person meetups to reinforce those working relationships. If you're just throwing work over the fence and it takes network analysis to figure out who's doing it...then maybe you should just be hiring a contractor anyway…

Yeah I similarly find this baffling. This very flatly would not work in any job I've had, whether in person or remote.

I have worked in places where this would work...all terrible places that usually had someone with a "maverick" view of how organizations worked derived from reading Warhammer books or something.

Re: We identified a North Korean hacker who tried to get a job

#96

Earlier quoted context omitted.

I've heard through the grapevine of some designers (one who worked at Shopify) getting caught using Fiverr (or something similar) to farm out all of their work. Despite all the weird crazy dog and pony show and jumping through hoops that most companies do now, most companies are abysmal at hiring.

What can you do during the hiring process to know that this amazing person, who aces every part of the interview, will farm out their work to cheap subcontractors?

The thing I'm always curious about with this is: What is the actual bad thing happening here?

Is the subcontracted work not good enough? Well, then the problem is that the work is not good enough.

Is the person not contributing in other ways that you want them to contribute because they have other jobs? (eg. chat conversations, meetings, team building, etc.) Well, then the problem is that they aren't making those contributions.

Or is it just that you're paying them more than you would have to pay the subcontractors if you found and managed them yourself? Well, then you are totally free to skip the middleman and do that yourself. But there is, actually, value in finding and managing freelance work. I certainly don't want to do that myself! If someone is good at doing that, and the quality of the work they are managing is acceptable to me, then it seems like they might be earning their paycheck?

I do get that the dishonesty element is bad in and of itself, but I honestly wonder whether, if this is a problem a firm is having, they should consider hiring the work out to subcontractors, without any subterfuge.

Re: We identified a North Korean hacker who tried to get a job

#97

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> Something in the industry as a whole is quite broken.

The problem is that it's very difficult to assess how good someone is in their job. The solution is to promote the best engineers into management so they can vet the candidates.

Re: We identified a North Korean hacker who tried to get a job

#98

Earlier quoted context omitted.

Hate to be that guy, but.. what’s the problem? The work is getting done for the price you agreed on. You care how it’s done suddenly? If AI does it, it’s the best thing since sliced bread. I’m sorry but capitalists that want to have it both ways annoy me. Agree on what gets delivered for how much and get out of the way. The “employer” mindset doesn’t jive with capitalism ya’ll are so fond of.

If you don't want to be an employee then don't sign an employment contract.

Ah, now suddenly you not only need to deliver work but you need to behave in a certain non-specified way. The contract then should arrange for that and perhaps pay extra because it’s a sign of dysfunction.

Re: We identified a North Korean hacker who tried to get a job

#99
post #37

Earlier quoted context omitted.

> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.

They're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly

Hired left and right != interviewed left and right != interviewed quite a few at Crowdstrike.

Maybe you’re contributing to the narrative with the posts like above. It’ll certainly drive engagement.

Re: We identified a North Korean hacker who tried to get a job

#100

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

The funny part is that in these stories about fake candidates using a whole team of people, it sounds like they are actually successful in doing the work, something that had not been achieved in software dev outsourcing before
Post reply on HN