North Korea's efforts have been evolving. In the past, they just tried to break into bank computers, then into crypto company's computers. For the last two years, they've been working on getting people into crypto companies. But now they appear to have enough people to spare than they also have groups working on "honest" employment as remote workers, who may not even have theft as the first thing on their mind. Here'…
We identified a North Korean hacker who tried to get a job
131–140 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#132Earlier quoted context omitted.
The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.
last years falcon (crowdstrike specific conference) they for the first time every showed live the interviews of 3 north koreans trying to get a job in software engineering positions at some forture 500 companies. i was baffled at every 'security' question to validate the person is actually in the US gets glossed over like: "my ID is at my home right now, and im in my office so i don't have that with me".
Re: We identified a North Korean hacker who tried to get a job
#133Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
Re: We identified a North Korean hacker who tried to get a job
#134Earlier quoted context omitted.
How do weekly 1:1 meetings with a manager not catch this very quickly? Okay, maybe the original suave interviewer comes back for those… Still feels like a good EM would pick up on discrepancies between work done and how the suave person talks about it. It depresses me, but you’re probably right about in-office work being the only guarantee against this type of scam. I wish we could just have nice things.
This isn't necessarily the issue here -- this attempt seemed to be fairly motivated and had access to resources (AI, coaches, ...) to help them get through the process. IF they can get such a 'candidate' hired... whats to say they couldn't continue the sham. One could imagine a team of hackers could easily pass of work that a single IC could reasonably have produced. If their goal is exfiltration (or some other hack)…
Sure I guess someone could physically turned up to an office to collect a laptop, be onboarded, get ID checked, then dial in to a few hours of meetings a week, muddle through any questions, rely on the team back at base helping, turn up in person to team get togethers every few months and manage to bluff their way through. It's not unprecedented - Frank Abagnale was running that type of con decades ago, Russia had the "Illegals" program of deep cover spies.
That's not exactly low cost.
Re: We identified a North Korean hacker who tried to get a job
#135Earlier quoted context omitted.
They're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly
> My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly I'm sure there were a lot of false positives with that question. If I was not reading HN and a few other sources I would likely hang up the phone too. Thinking that it couldn't be a real job,... some phishing scam or hoax, asking ridiculous q…
Re: We identified a North Korean hacker who tried to get a job
#136Earlier quoted context omitted.
Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…
My suspicion is that it's purely monetary and driven by the finance people. a) Don't have to pay to fly candidates out, pay for their hotel, etc. b) Don't have to pay relocation c) Get access to a larger pool of candidates, so can price the wages lower than local wages would require My last company there was a top down directive that in-person interviews were straight up not allowed, everything had to be over Zoom. E…
Re: We identified a North Korean hacker who tried to get a job
#137https://koliber.com/articles/how-to-avoid-hiring-a-north-kor...
Re: We identified a North Korean hacker who tried to get a job
#138Re: We identified a North Korean hacker who tried to get a job
#139Earlier quoted context omitted.
last years falcon (crowdstrike specific conference) they for the first time every showed live the interviews of 3 north koreans trying to get a job in software engineering positions at some forture 500 companies. i was baffled at every 'security' question to validate the person is actually in the US gets glossed over like: "my ID is at my home right now, and im in my office so i don't have that with me".
I mean you see that here on HN right? People claiming that any arbitrary question is something they have no idea about, like the color of their front door.
Re: We identified a North Korean hacker who tried to get a job
#140So basic HR processes?