Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

131–140 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#131

North Korea's efforts have been evolving. In the past, they just tried to break into bank computers, then into crypto company's computers. For the last two years, they've been working on getting people into crypto companies. But now they appear to have enough people to spare than they also have groups working on "honest" employment as remote workers, who may not even have theft as the first thing on their mind. Here'…

It's not just crypto, nearly all orgs at this point. As someone building in this space, it's pretty clear the N Koreans developed a deepfake toolkit that is being used/sold amongst the N Korean hacking groups there. Apparently it is for acquiring laptops, salaries to funnel to the State, and internal systems access for further damage.

Re: We identified a North Korean hacker who tried to get a job

#132
post #50

Earlier quoted context omitted.

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

last years falcon (crowdstrike specific conference) they for the first time every showed live the interviews of 3 north koreans trying to get a job in software engineering positions at some forture 500 companies. i was baffled at every 'security' question to validate the person is actually in the US gets glossed over like: "my ID is at my home right now, and im in my office so i don't have that with me".

I mean you see that here on HN right? People claiming that any arbitrary question is something they have no idea about, like the color of their front door.

Re: We identified a North Korean hacker who tried to get a job

#133

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Between this and legit candidates cheating with AI, I think we'll soon see the return of on-site interviews - even for remote positions.

Re: We identified a North Korean hacker who tried to get a job

#134

Earlier quoted context omitted.

How do weekly 1:1 meetings with a manager not catch this very quickly? Okay, maybe the original suave interviewer comes back for those… Still feels like a good EM would pick up on discrepancies between work done and how the suave person talks about it. It depresses me, but you’re probably right about in-office work being the only guarantee against this type of scam. I wish we could just have nice things.

This isn't necessarily the issue here -- this attempt seemed to be fairly motivated and had access to resources (AI, coaches, ...) to help them get through the process. IF they can get such a 'candidate' hired... whats to say they couldn't continue the sham. One could imagine a team of hackers could easily pass of work that a single IC could reasonably have produced. If their goal is exfiltration (or some other hack)…

Do you not have regular calls with teammates?

Sure I guess someone could physically turned up to an office to collect a laptop, be onboarded, get ID checked, then dial in to a few hours of meetings a week, muddle through any questions, rely on the team back at base helping, turn up in person to team get togethers every few months and manage to bluff their way through. It's not unprecedented - Frank Abagnale was running that type of con decades ago, Russia had the "Illegals" program of deep cover spies.

That's not exactly low cost.

Re: We identified a North Korean hacker who tried to get a job

#135
post #37

Earlier quoted context omitted.

They're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly

> My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly I'm sure there were a lot of false positives with that question. If I was not reading HN and a few other sources I would likely hang up the phone too. Thinking that it couldn't be a real job,... some phishing scam or hoax, asking ridiculous q…

That's actually hilarious. Edit: Oops, accidentally responded to you instead of original quote.

Re: We identified a North Korean hacker who tried to get a job

#136

Earlier quoted context omitted.

Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…

My suspicion is that it's purely monetary and driven by the finance people. a) Don't have to pay to fly candidates out, pay for their hotel, etc. b) Don't have to pay relocation c) Get access to a larger pool of candidates, so can price the wages lower than local wages would require My last company there was a top down directive that in-person interviews were straight up not allowed, everything had to be over Zoom. E…

Only a) is valid, as you can fly candidates for interviews and have them go back to their home city to work remotely.

Re: We identified a North Korean hacker who tried to get a job

#139
post #132
post #50

Earlier quoted context omitted.

last years falcon (crowdstrike specific conference) they for the first time every showed live the interviews of 3 north koreans trying to get a job in software engineering positions at some forture 500 companies. i was baffled at every 'security' question to validate the person is actually in the US gets glossed over like: "my ID is at my home right now, and im in my office so i don't have that with me".

I mean you see that here on HN right? People claiming that any arbitrary question is something they have no idea about, like the color of their front door.

I’m not sure I know what you mean—I’m not sure I’d want to discuss the specifics of my living environment here though. Would you have any examples handy?
Post reply on HN