Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

191–200 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#191
post #168

Earlier quoted context omitted.

I don't think this has anything to do with remote vs. onsite work. It has more to do with remote vs. onsite interviews . A thorough onsite interview should catch all of these fake candidates. Companies should be doing at least one onsite interview regardless of whether the role itself is remote or onsite.

A very easy way to verify a remote candidate's identity is to buy them a plane ticket to an in person interview. If they cannot board a plane using their claimed identity from their claimed city of origin, you can stop there.

Only if they are 100% fake as opposed to farming out work to someone else. I can turn up to an interview in person no problem. When hired I just have the person in India use my name/picture and do the work.

Of course if they hire me as opposed to that person in India directly there is likely a reason they wanted someone in the US. Often those reasons are legal and somewhere a law is being broken.

Re: We identified a North Korean hacker who tried to get a job

#192

Earlier quoted context omitted.

I have worked in places where this would work...all terrible places that usually had someone with a "maverick" view of how organizations worked derived from reading Warhammer books or something.

> with a "maverick" view of how organizations worked derived from reading Warhammer books or something Did they want to serve the god emperor of SAAS?

We all believe that using recruitment software is sufficient to prevent fraudulent candidates from being hired and that's what makes it true.

Re: We identified a North Korean hacker who tried to get a job

#193

Earlier quoted context omitted.

Well they claim the final interview involved asking the candidate very specific questions about the town they claimed to be living in, and hold up government issued ID to the camera. My assumption based on this was they weren't certain it was someone malicious and they were double checking their own conclusion. If not it makes no sense to tip the candidate off that you're suspicious about them. At that point I'd say…

> Name 5 restaurants not on Google maps in the town you live in". I'm definitely a US based human and no way I get this right.

[deleted]

Re: We identified a North Korean hacker who tried to get a job

#194
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

[deleted]

Re: We identified a North Korean hacker who tried to get a job

#195
post #145
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI... Good. I hope the whole hiring process gets blown up. The root cause of this is transactional hiring. Companies treat applicants like commodities, and now bad actors have found out how to game…

If you think this is going to lead to better treatment of candidates in the industry then i got really bad news for you

Re: We identified a North Korean hacker who tried to get a job

#196
In 2024 i’ve conducted a lot of interviews to recruit some frontend and backend engineers in full remote roles.

And at one point i was getting a lot of candidates with european names, no picture, good resume.

And when I met them over a call it was very strange: they were all asian(with really typical nordic names), they were like clones in the way they talked and answered questions exactly the same. They also claimed to be from Sweeden/Finland/Norway for most of them but yet they had a strong asian accent. Not nordic at all.

This was really fishy and since the fit wasn’t there I stopped the interview without thinking about it too much. but the more I think about it, the more i tend to lean on North Corean candidates.

Re: We identified a North Korean hacker who tried to get a job

#197
post #65

Earlier quoted context omitted.

These aren't spies first. They are often children of well to do, high loyalty group North Koreans. It's just a privileged job. The skill and IQ level varies widely, from super smart to super unskilled. And these roughly get sorted out into different groups with different MO's. North Koreans aren't some uniformly skilled group. You could be targeted by a team of world class bytecode exploit geniuses who rehearses ever…

I find this answer highly implausible, not the least because maintaining cover doesn't count as dissing ("I infiltrated the org by telling them the lies they wanted to hear" is hacking 101). Also, North Koreans aren't dumb. I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? > Dissing Kim is something that is not currently widely…

> I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it?

I have no clue whether the proposed approach works, but there's a pretty coherent model that explains how it could, no schizophrenia needed: They are competent people in a cult.

Being unable/unwilling to diss Dear Leader even when it's advantageous to do so is very typical cult stuff. In fact, it's sort of why cults are dangerous. They compel people to do maladaptive things in service of the "ideals" of the group/leader.

This applies both to the spy directly (perhaps they would personally be unwilling to say such a thing), but also to their entire chain of command. Cults by their nature are not good at passing nuanced instruction like "you can say bad things about Dear Leader under these circumstances." Just because you're willing to diss KJU to get in the door doesn't mean you know your entire chain of superiors are cool with it.

Re: We identified a North Korean hacker who tried to get a job

#198
post #100

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

The funny part is that in these stories about fake candidates using a whole team of people, it sounds like they are actually successful in doing the work, something that had not been achieved in software dev outsourcing before

Are they? I suspect someone I used to work with was outsourcing. They did great on the interview but their on the job performance wasn't nearly as good.

Re: We identified a North Korean hacker who tried to get a job

#199
post #100

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

The funny part is that in these stories about fake candidates using a whole team of people, it sounds like they are actually successful in doing the work, something that had not been achieved in software dev outsourcing before

It's only "successful" because there's an alternative, presumably-nefarious funding stream from a third party who wants to gain access to IP/user data/influential functionality.

It's essentially a subsidy heavily distorting a very specific market.

Re: We identified a North Korean hacker who tried to get a job

#200
post #65

Earlier quoted context omitted.

I find this answer highly implausible, not the least because maintaining cover doesn't count as dissing ("I infiltrated the org by telling them the lies they wanted to hear" is hacking 101). Also, North Koreans aren't dumb. I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? > Dissing Kim is something that is not currently widely…

I am saying they are both a credible threat and many are amateurs. Those are not mutually exclusive. You are talking about North Korea attackers from a theoretical point of view. For many people dealing with them is just a normal part of work. It's not an unknown that needs to be worked out logically from an armchair. I'm saying this as someone who personally chatted with a North Korea persona that later tried to dro…

I don't consider screenshots evidence of anything, so I'll completely disregard that bit.

I'm curious about your personal experience though. Did you try this tactic, and did it work? And how sure are you these weren't random hackers or trolls, but actual NK agents?

> many are amateurs

So basically this would only get rid of the amateurs, low hanging fruit that would have been caught soon enough anyway, and do a "natural selection" of only the non-stupid NK hackers to infiltrate your org?

Post reply on HN