12 ms·
We identified a North Korean hacker who tried to get a job
- crorella 1y agoI think they detected instead of identified, as far as I know they didn't get the identity of the hacker.
- rvz 1y ago> Not all attackers break in, some try to walk through the front door. Now made even easier for fraudsters and including state actors thanks to Generative AI. Also: > Generative AI is making deception easier, but isn’t foolproof. Attackers can trick parts of the hiring process, like a technical assessment, but genuine candidates will usually pass real-time, unprompted verification tests. This is why Leetcode / Hackerrank and other (online assessments) OA in the technical interview is unfit for use in the age of AI. > In the modern era, it’s an organizational mindset. Security is a way of life for this company, but it would have easily fooled a less security-oriented company and it will just only get worse.
- spacebanana7 1y ago> genuine candidates will usually pass real-time, unprompted verification tests. I wonder these are similar to the "tests" in Suits, where they (somewhat inadvertently) check whether someone went to Harvard by asking about the food places students typically went to.
- xyzhut 1y agoIts a pretty standard thing to do when you suspect someone of being not who they say they are. WW2 German spies would claim to be from New York, and OSS or MPs would ask them who the Yankees lead pitcher was. Not really a unique or new way of doing things.
- cosmicgadget 1y agoAnd in Ronin when Deniro asks Sean Bean the color of the boathouse at Hereford.
- Dachande663 1y agoFrom somewhere in the depths of an old reddit thread, someone recommended asking candidates "How fat is Kim Jong Un?" Instant hang-up.
- the_af 1y agoWhy would this work? Spies are trained to behave like the host country would expect, why wouldn't hackers? If hackers have access to the outside world (something they would need to be effective), they'd know the world thinks Kim is fat. "He's very fat, haha!", end of story. Edit: wait, or better yet: "how on earth would I know, and why are you asking this in a job interview? Is this because I'm Korean? I'd like to file a complaint with HR, what was your name again?"
- smallnix 1y agoNot sure some rank and file 50ct army "hacker" wants to take the risk to insult their god-dictator.
- the_af 1y agoIf he's acting under NK command, this wouldn't be insulting, it's just doing a hacker's work. Besides, you cannot have it both ways: either North Korean hackers are a "50ct army" or they are a credible threat. Most seem to be arguing they are a credible threat. Also, he can always take the second option: "why are you asking about this in a job interview?", something many legitimate Korean candidates could ask.
- smallnix 1y ago> If he's acting under NK command, this wouldn't be insulting, it's just doing a hacker's work. I understand where you are coming from, I wanted to express my idea that their person cult shaped culture might be so alien to us, that what seems obvious to us, might be a non-option to them. At least at the level where I imagine such operators. > you cannot have it both ways: either North Korean hackers are a "50ct army" or they are a credible threat I assume the people performing the en-masse long term infiltration are not the same with technical skills who the execute technical attacks.
- donnachangstein 1y agoThey used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean without uncovering it somewhere in the hiring process, and all my jobs have been especially uninteresting. What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken.
- corytheboyd 1y ago> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
- ta1243 1y agoThey're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_interview_questions/ https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly
- jwilber 1y agoHired left and right != interviewed left and right != interviewed quite a few at Crowdstrike. Maybe you’re contributing to the narrative with the posts like above. It’ll certainly drive engagement.
- ductsurprise 1y ago> My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly I'm sure there were a lot of false positives with that question. If I was not reading HN and a few other sources I would likely hang up the phone too. Thinking that it couldn't be a real job,... some phishing scam or hoax, asking ridiculous questions like that. Depending on the job, it is quite likely the real talent would not be able to take the interview seriously after hearing suck a question. Seriously weird times...
- stavros 1y agoThis is an interesting article, but doesn't this: > our Red Team launched an investigation using Open-Source Intelligence gathering (OSINT) methods. basically mean "some guys in the company googled him"?
- spacebanana7 1y agoYou can go further. Reach out to data brokers and see whether they've got any information from ad tracking / leaks.
- BoredPositron 1y agoSophisticated.
- stavros 1y agoIs that OSINT, at that point? I guess maybe if you get a free trial, but isn't that stretching the definition a bit?
- Multiplayer 1y agoHere's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote work has amazing upsides and tremendous security implications.
- dboreham 1y agoAnd yet: do the same thing with AI and you're a cutting edge genius.
- ferguess_k 1y agoSome people did this with in-office too I think, some years ago. Some people actually had two jobs, both sort of in-office. It's still possible to pull the tricks.
- financypants 1y agoThe rate of this happening has got to be so low it's negligible.
- ferguess_k 1y agoI agree. It's kinda hard to pull this off. Just saying.
- aoanevdus 1y agoThe common pattern of requiring three days a week of in-office time makes it much harder.
- pokstad 1y agoDon’t forget remote workers who are required to work in one area and then travel to restricted areas and continue to work.
- 1y ago
- Jcampuzano2 1y agoIf people are hiring this sort of applicant I'm of the opinion they kind of deserve to be "pwned". The most basic of process should have weeded this dude out instantly at any modern company. I'm sure this wasn't a case of the most advanced/sophisticated attempt from North Korea and other bad actors, and probably just a case of them casting a wide net. But regardless based off of this writeup and the video shown dude should have never been given the time of day.
- sltr 1y agoReminds me of the Lazarus Heist [1] [1] https://www.bbc.co.uk/programmes/w13xtvg9 https://www.bbc.co.uk/programmes/w13xtvg9
- mystraline 1y agoIts quite saying, that in order to get interviews, you have to basically lie your way with various generative AI. Whereas, I've been looking for quite a while, with very few bites. And nobody so far on HN Who's hiring responds, except for a place that seems to want 60h/week and pay for 40h/week. Being genuine and truthful in the age of generative AI, LLMs, quiet quitting, /r/overemployed (on the sly working multiple 40h week jobs).... Being honest in this environment seems to be a losing endeavor.
- klodolph 1y agoI’m a little skeptical that generative AI is an effective way to land a job. It doesn’t really seem like it helps that much in résumé generation. Are people applying to enough hundreds of jobs that generative AI helps you keep up with the sheer volume of text you need to send? Some people are… but these aren’t people who know what good résumés look like, because those people write their own résumés, and these people aren’t people who are good with LLMs, because that skill is in-demand. I think it’s just a tight, tough market. What I’ve seen is job searches that take longer and have higher standards. You’re competing with a larger pool of experienced candidates. And various companies are worsening the work conditions because the market favors it (and they want “unregretted attrition”). It’s hard not to be cynical. But I think it’s just a shitty market to be looking for a job, it’s not a paradigm shift that favors dishonesty.
- JumpCrisscross 1y ago> confirming the signal chat leaks were real To the degree I skim resumes for anything nowadays, it’s AI slop. Automatic bin.
- deleted 1y ago[deleted]
- wnevets 1y agoThanks to AI this problem will only get much worse.
- stackedinserter 1y agoYou can't AI if in person.
- wnevets 1y agothey just out source the in person parts > It turns out there is a burgeoning sub-industry of college-aged males of Asian ancestry who cannot wait to get paid for participating in these schemes. There are Discord channels all around the world just for this. They make a few hundred to a few thousand dollars for allowing their identity to be misused or participating in the scheme. That way, they can interview in person or take drug tests if the job requires that. https://blog.knowbe4.com/our-interview-of-a-north-korean-fake-employee https://blog.knowbe4.com/our-interview-of-a-north-korean-fak...
- stackedinserter 1y agoThen what? It should be the same person at day 1, no?
- dabber21 1y agoI wonder if something like eIDAS could help here (at least in EU countries)
- wakeywakeywakey 1y agoThis is cool, but we'd be naive to think the other side is not also learning from this operation. The "gotcha" questions that foiled them at the end will likely make it into their playbook for next go around, and these attacks are going to be more sophisticated.
- TheGCMadeMeDoIt 1y agoI fail to understand the whole "advancing the candidate through the interview to learn more about how they do this" plan. They already knew the candidate's name, email, and GitHub were all part of past beaches. I could understand if they were fishing for more information to contribute to a shared list, but it seems like they knew virtually everything they needed to know. Asking the candidate to justify the inconsistencies outright would've been just as helpful as the final interview IMO. Is there something I'm missing there?
- klodolph 1y agoDollars to donuts the NK team is reading this article and adapting their strategies. IMO, rather than ask candidates to justify inconsistencies, you should forward the information to law enforcement and tell the candidate you’re hiring somebody else.
- renewiltord 1y agoRight, so if you have a tell-tale sign, you concoct a story around other things instead. Parallel construction. They fix all the silly things but you still have the tell-tale.
- TheGCMadeMeDoIt 1y agoWell they claim the final interview involved asking the candidate very specific questions about the town they claimed to be living in, and hold up government issued ID to the camera. My assumption based on this was they weren't certain it was someone malicious and they were double checking their own conclusion. If not it makes no sense to tip the candidate off that you're suspicious about them. At that point I'd say asking the candidate outright is better than playing a weird game of "Name 5 restaurants not on Google maps in the town you live in". But if they were sure, then yeah, skip the interview altogether and forward the information to law enforcement.
- CharlieDigital 1y ago> Name 5 restaurants not on Google maps in the town you live in". I'm definitely a US based human and no way I get this right.
- notlive 1y agoThe article says they received a list of known NK hackers' emails in advance and the hacker used one of those addresses to apply. Pretty big red flag there if you ask me. Is it really unfair to halt the process at that point?
- ThinkBeat 1y agoSomeone said that North Koreas are trying to get jobs. Ok Then they had a candidate who was trying to cheat the systemeat How did they establish and verify that the candidate was North Korean? Are North Koreans the only ones who try to remote work byt lying about their whereabouts? Not at all. If you live in a country outside of the US and you see the money software poeple make in the US it is mighty tempting to land a gig. The fact that the persdon made simple mistakes and needed to be coached does not sound like a North Korean state operation. If someone had told them Russian hackers are trying to get jbos. Would they have asummed the person was Russian?
- layer8 1y agoThe article notes the following as the establishing link: > We received a list of email addresses linked to the [North Korean] hacker group, and one of them matched the email the candidate used to apply to Kraken.
- charlieyu1 1y agobut how legit is the list?
- paradite 1y agoI wonder what if this is just a decoy to get the more sophisticated candidate in.
- deleted 1y ago[deleted]
- danielvf 1y agoNorth Korea's efforts have been evolving. In the past, they just tried to break into bank computers, then into crypto company's computers. For the last two years, they've been working on getting people into crypto companies. But now they appear to have enough people to spare than they also have groups working on "honest" employment as remote workers, who may not even have theft as the first thing on their mind. Here's a federal case where a US woman was convicted of helping North Korea steal the identities of 70 people, and then remote in as them, to do remote work: https://www.justice.gov/usao-dc/pr/arizona-woman-pleads-guilty-fraud-scheme-illegally-generated-17-million-revenue-north https://www.justice.gov/usao-dc/pr/arizona-woman-pleads-guil...
- jborden13 1y agoIt's not just crypto, nearly all orgs at this point. As someone building in this space, it's pretty clear the N Koreans developed a deepfake toolkit that is being used/sold amongst the N Korean hacking groups there. Apparently it is for acquiring laptops, salaries to funnel to the State, and internal systems access for further damage.
- waltercool 1y ago[dead]
- noitpmeder 1y agoBefore this interview, industry partners had tipped us off that North Korean hackers were actively applying for jobs at crypto companies. We received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken. This doesn't sound so impressive? This single red flag should invalidate the candidate immediately, end of story.
- sam-cop-vimes 1y agoThe article explains why they didn't invalidate the candidate immediately. They wanted to learn how they operate.
- appleaday1 1y agoI got interviewed by Kraken lol
- ninjazee124 1y agoThis is pretty common stuff I saw with just even regular startups with remote applicants -- I take their claim that it was NK hacker with a grain of salt.
- junon 1y agoThe interview a friend conducted a few weeks ago had a rich GitHub account of shoddy code across what was no less than 15 different languages, and a lot of it, all with names related to interview questions (many having the company name in them). The interview call over zoom was clearly an AI avatar, and the answers were verbally spoken but constructed in a "bulleted" way that an LLM might produce. All of the timestamps in the commits were made with the KST timezone.
- joejoo 1y agoThese elite state hackers seemed a little careless from the start, to say the least…
- yieldcrv 1y agoAll you have to do is ask them to say "Fuck Kim Jong Un" this is a tongue in cheek test in crypto circles for like a year now
- deleted 1y ago[deleted]
- rs186 1y ago> asking the candidate to verify their location, hold up a government-issued ID, and even recommend some local restaurants in the city they claimed to be in. I don't know, if I run into these questions in a job interview, especially with a small, less known company, I would be having serious questions about what this company is doing
- TechDebtDevin 1y ago"yeah, could you just hold up that ID please... Thanks, also a few more questions..Who was your favorite teacher, and what was the first car you owned ?"
- 65 1y ago"Hah, I love software engineering, like my mother did. After all, her maiden name is Smith, and she used to be called a codesmith! What's your mother's maiden name? Maybe it also makes a funny engineering pun!"
- Havoc 1y agoIs there an uptick in this feels like there are suddenly multiple stories about it
- seasongs 1y ago[flagged]
- deleted 1y ago[deleted]
- stackedinserter 1y agoI would hire this person, set up a very basic work environment, forced him to run a spyware, learn something about them and made more interesting blogpost. Actually, that's a job for counter-intelligence agencies (NSA? RCMP?), but I guess they will just laugh you call them.
- ecocentrik 1y agoI'm surprised it wasn't the government sanctioned haircut.
- s-mon 1y agohttps://www.wired.com/story/north-korea-stole-your-tech-job-ai-interviews/ https://www.wired.com/story/north-korea-stole-your-tech-job-... - same day, what a coincidence!
- deleted 1y ago[deleted]
- anonymousiam 1y agoCommenting on the events, CSO Nick Percoco, said: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto, or U.S. corporate, issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.” It's funny to see the CSO of a crypto firm say this. It's the opposite of the whole way crypto works. In crypto, the transaction is processed (trusted) if all the credentials and keys are correct, regardless of who's behind it.
- udev4096 1y agoApart from that, he is running a crypto exchange which is completely against the whole ideology of bitcoin and other notable crypto. The guy is a fucking joke. Every crypto exchange has been extremely shady, from coinbase to binance to tether. Kraken is no different
- gouggoug 1y agoNot to mention the silliness of this statement: "This core crypto principle is more relevant than ever in the digital age" I wonder what crypto-currency looked like before the digital age... Edit: added -currency suffix to crypto :p
- arandomhuman 1y agoOne time pads, enigma machines, Caesar ciphers :p
- taeorg74 1y agoI mean if the credentials are correct than they transaction is by design verified and trusted.
- orbital-decay 1y agoI don't see anything about the guy being North Korean in the article. It's pure clickbait full of bragging about "our DNA". > Their resume was linked to a GitHub profile containing an email address exposed in a past data breach. How is it an indicator of anything? Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.
- moshegramovsky 1y ago100%. There is a bragging tone that felt completely unwarranted. Like being on a date with someone who is really insecure.
- layer8 1y agoThe establishing link was this: > We received a list of email addresses linked to the [North Korean] hacker group, and one of them matched the email the candidate used to apply to Kraken.
- udev4096 1y ago> Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned. Which is why everyone needs to switch to passkeys. It's crazy that we still use passwords for authentication
- ls612 1y agoDon't passkeys still have tons of vendor lock-in attached? A password I can put into any password manager I want and transfer it to a different password manager and neither the password manager company nor the company for which I made the account is any the wiser.
- taeorg74 1y agoSome PW managers can store a passkey, but when tied to a device, if the device is compromised then all of your accounts are unless you're also using a yubikey or third device 2fa
- 1y ago
- lmeyerov 1y agoWe had similar earlier on at Graphistry. It was pretty obvious, especially by the time of video screens. We are still unsure if whether a hacker or just someone avoiding their history/nationality - online history was sparse and somewhat mismatching, and weird profile image reuse - unexpectedly strong accent in calls, does not show video - background reference checks a mess
- iJohnDoe 1y agoThere are so many talented people trying to get their first or second job in the cybersecurity industry. Legit, honest, hard-working individuals want to get their chance in cybersecurity. So many posts from cybersecurity companies saying, "Meet us at conferences! Write content! Get to know us, then we'll hire you!" Then in their article they write this. Companies that are even letting these resumes or candidates get a second look are disgraceful. Companies need to get their shit together. What happened to standard procedures? 1. Phone interview. 2. Video interview. 3. In-person interview. 4. Job offer and hired. Heck, even standard was 1. Phone interview. 2. In-person interview. 3. Job offer and hired. > From the outset, something felt off about this candidate. During their initial call with our recruiter, they joined under a different name from the one on their resume...
- aussieguy1234 1y agoApparently they're white brainwashed around Kim Jong Un and simply can't process any discussions that are even remotely negative about their dear leader. Use this to your advantage during the interview process to weed them out: https://news.ycombinator.com/item?id=43853382 https://news.ycombinator.com/item?id=43853382
- ianhawes 1y agoThis is pretty boring. Let me know when you drop an implant on their host device and move laterally to other attackers devices or engage in a long-con and get them to travel to a US-extraditable country.
- Geee 1y agoSeems like they wanted to be obvious. At the same time they got their real hacker in. Typical diversion tactic.
- wslh 1y agoIn my lesser known company, we've been receiving leads who share their codebase repositories which contain malware or buggy dependencies, even though we offer cybersecurity services. If I were able to predict the future I would say that soon GitHub, GitLab and others will release inproved security sensors.
- tsukikage 1y agoTLDR: "We received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken."
- koliber 1y agoI’ve had 4 such people interview. These guys were much easier to spot than the one at Kraken. I wrote up an article about how to spot these fake North Korean devs. https://koliber.com/articles/how-to-avoid-hiring-a-north-korean-spy-on-your-dev-team https://koliber.com/articles/how-to-avoid-hiring-a-north-kor...
- lawgimenez 1y agoThe lack of proof is disturbing, a redacted screenshot would be nice.
- seasluggy 1y agoOSINT? So basic HR processes?
- abhisek 1y agoThis is happening with high value crypto companies with large security teams. Imagine what happens when OSS maintainers are asked to work on GitHub repositories with malicious code as part of fake job interviews? If its not insider access then might as well hack an OSS maintainer and publish malicious open source package that everyone depends on to reach your target organization.
- eunos 1y ago> The candidate used remote colocated Mac desktops but interacted with other components through a VPN, a setup commonly deployed to hide location and network activity. How can Kraken found this out based only on Videocall?
- nikcub 1y agoThe North Korean efforts are amateur compared to government intel ops either placing or recruiting employees at large tech firms.
- tough 1y agoJust ask them to badmouth their leader on interview.
- codecraze 1y agoIn 2024 i’ve conducted a lot of interviews to recruit some frontend and backend engineers in full remote roles. And at one point i was getting a lot of candidates with european names, no picture, good resume. And when I met them over a call it was very strange: they were all asian(with really typical nordic names), they were like clones in the way they talked and answered questions exactly the same. They also claimed to be from Sweeden/Finland/Norway for most of them but yet they had a strong asian accent. Not nordic at all. This was really fishy and since the fit wasn’t there I stopped the interview without thinking about it too much. but the more I think about it, the more i tend to lean on North Corean candidates.
- stainablesteel 1y agotheir strategy honestly says a lot of crazy things about their worldview
- woutersf 1y agoWhat do you mean by this (genuinely curious).
- stainablesteel 1y agoi'm scared to explain it, you could be north korean
- ForOldHack 1y ago"A candidates Red Flags..." These guys are funny.
- Aloisius 1y agoThis level of applicant checking at a financial institution does not inspire confidence. At a previous remote job for a financial institution, they required a full background check with fingerprinting, reference checking, past employment verification, drug testing and in-person verification of identity and employment authorization. This was done for everyone, not just people they found "suspicious." Frankly, the laws against applicant discrimination also makes having different processes or demanding different information from candidates because of national origin/ancestry/accent/etc. legally questionable.
- fracus 1y ago"During their initial call with our recruiter, they joined under a different name from the one on their resume, and quickly changed it." The article could have been this short. This article also helps the Korean hackers by providing in depth commentary on how they were caught and how to improve.
- g42gregory 1y agoAnd his name was Jimmy… On a serious note, as a Kraken customer, I am very happy that they take security issues seriously. Reassuring.
- iagooar 1y ago> We received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken. Sounds like you had to really push the boundaries of what is humanly possible to uncover this one.
- sjs382 1y ago> From the outset, something felt off about this candidate. During their initial call with our recruiter, they joined under a different name from the one on their resume, and quickly changed it. Even more suspicious, the candidate occasionally switched between voices, indicating that they were being coached through the interview in real time. > Before this interview, industry partners had tipped us off that North Korean hackers were actively applying for jobs at crypto companies. We received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken. Unless you were working in conjunction with law enforcement (with some guarantee re: the security of customer assets), it should have ended there. Going further may have piqued your interest, but... > Instead of tipping off the applicant, our security and recruitment teams strategically advanced them through our rigorous recruitment process – not to hire, but to study their approach. ... you likely gave them more actionable data than they gave you. This behavior was reckless, amateurish and I'd be pulling out my assets right away if someone acting as a custodian to my finances acted like this.
- DavidD 1y agoCongratulations you just provided source material to deepfake your staff.
- aryan14 1y agoCross checked known malicious mail list with applicants, found a match and made a blog about it lol
- deleted 1y ago[deleted]
- NatalieKrylova 1y ago[dead]
- wendy4151 1y ago[dead]
- Dmarcus8786 1y ago[dead]