We identified a North Korean hacker who tried to get a job
111–120 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#112Earlier quoted context omitted.
I also can’t imagine this not getting caught if not in the interview process surely during every day work. Maybe this says more about their work culture and not actually connecting with co workers. Perhaps the manager was just garbage who knows.
On their first day, they will get a lot of accounts, if they syphon data and m set up backdoors quickly, one day could be enough to cause a good chunk of the damage. Saddens me a bit. I like to trust hires and give them pretty wide access to everything. For my own company, I've so far only hired people I worked with in the past, but when hiring strangers remotely, I'll probably have to rethink my trust-first model.
Re: We identified a North Korean hacker who tried to get a job
#113Earlier quoted context omitted.
Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…
My suspicion is that it's purely monetary and driven by the finance people. a) Don't have to pay to fly candidates out, pay for their hotel, etc. b) Don't have to pay relocation c) Get access to a larger pool of candidates, so can price the wages lower than local wages would require My last company there was a top down directive that in-person interviews were straight up not allowed, everything had to be over Zoom. E…
But yes, that directive to interview local candidates over zoom does seem very silly.
Re: We identified a North Korean hacker who tried to get a job
#114They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
Get a new CISO? You'll probably be buying the software from the last company he worked with and spending the next 3 years installing it all over just in time for them to declare mission accomplished you are secure and move on to the next square in the C-suite game of Life these dudes play. Then there's the people beneath them who want to be them mucking up the system playing get to the c-suite and not 'secure the company' or 'build good things'
Oh and if you've gone public your core business is probably on auto pilot with some gremlins keeping it running while your execs placate shareholders with layoffs and introducing AI.
People who actually want to do things, help people, and understand why the work needs done and is worth doing (the work that is anyway) are burnt the fuck out.
Re: We identified a North Korean hacker who tried to get a job
#115Thanks to AI this problem will only get much worse.
You can't AI if in person.
> It turns out there is a burgeoning sub-industry of college-aged males of Asian ancestry who cannot wait to get paid for participating in these schemes. There are Discord channels all around the world just for this. They make a few hundred to a few thousand dollars for allowing their identity to be misused or participating in the scheme. That way, they can interview in person or take drug tests if the job requires that.
https://blog.knowbe4.com/our-interview-of-a-north-korean-fak...
Re: We identified a North Korean hacker who tried to get a job
#116Earlier quoted context omitted.
Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…
And similarly forbid them from using AIs while they code on that work laptop in person? Are employees forbidden from using AIs for work? If not, why require that during evaluation? If it's not required during evaluation in person, why require it remotely? (I don't know the answers to how to interview in this brave new world, but I'm increasingly skeptical of forbidding tools that people will be using for the job.)
Re: We identified a North Korean hacker who tried to get a job
#117Earlier quoted context omitted.
The thing I'm always curious about with this is: What is the actual bad thing happening here? Is the subcontracted work not good enough? Well, then the problem is that the work is not good enough. Is the person not contributing in other ways that you want them to contribute because they have other jobs? (eg. chat conversations, meetings, team building, etc.) Well, then the problem is that they aren't making those con…
Where I work, it would be sharing of credentials and lying (or at least being dishonest) about who did the work.
Re: We identified a North Korean hacker who tried to get a job
#118If I were able to predict the future I would say that soon GitHub, GitLab and others will release inproved security sensors.
Re: We identified a North Korean hacker who tried to get a job
#119Earlier quoted context omitted.
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
They're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly
I'm sure there were a lot of false positives with that question.
If I was not reading HN and a few other sources I would likely hang up the phone too.
Thinking that it couldn't be a real job,... some phishing scam or hoax, asking ridiculous questions like that.
Depending on the job, it is quite likely the real talent would not be able to take the interview seriously after hearing suck a question.
Seriously weird times...
Re: We identified a North Korean hacker who tried to get a job
#120Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…
For developers I share my screen on MS Teams so everyone can watch, then hand them my laptop with Visual Studio. They've got 90 minutes to complete a small assignment while we look at them code - Google is allowed, so is copying and pasting from Stack Overflow, and we'll probably allow Copilot as well. The code needs to run and return the expected results. One candidate said, "this was great, it felt like real work".
For cloud admins, our Devops lead creates a new resource group, hands over his laptop, and we ask them to create a few resources and do the network and authentication to make them talk to each other. Most candidates can't do that anymore - we're finding they've become Terraform operators that don't know how the underlying technology works.