HomeSecurityNorth Korean hackers defrauded KnowBe4 with "alleged employee"

North Korean hackers defrauded KnowBe4 with a “supposed employee”

KnowBe4 , a company that educates and raises awareness about cybersecurity issues, revealed that it was tricked into hiring an IT employee who belonged to a group of North Korean hackers.

KnowBe4 North Korean hackers employee

It is said that the malicious activity was detected and prevented before illegal access was gained and without any data being compromised from KnowBe4's systems.

The company explained how North Korean hackers managed to create an extremely realistic persona, capable of passing an extensive interview and vetting process.

The case highlights North Korea's ongoing efforts to infiltrate Western companiesthrough alleged employees. These campaigns are primarily aimed at generating revenue for the government of the Democratic People's Republic of Korea (DPRK) but also to conduct intrusions for espionage and data theft.

See also: CoinStats: North Korean hackers breached 1,590 crypto wallets

Stu Sjouwerman, CEO and President of KnowBe4, noted: “This is a well-organized and large criminal ring with extensive resources, funded by the state. The case highlights the critical need for stronger audit procedures, continuous security monitoring and improved coordination between HR, IT and security teams to protect against advanced threats.”

A fake IT worker won a job at KnowBe4

KnowBe4 had posted an ad seeking a software engineerto join its internal IT AI team. The company received a resume from an individual using a valid but stolen ID . The photo displayed was “artificially altered.”

Four videoconference interviews were conducted at different times, confirming that the individual matched the photo on their application.

were conducted prior to hiring. As previously stated, the identity was genuine, so no problem was identified.

After the North Korean hacker was selected for the role, KnowBe4 sent him a Mac workstation for remote work.

See also: North Korean hackers target Brazil

KnowBe4's EDR software quickly detected suspicious activities from the device (on July 15), including downloading malware, modifying session history files, transferring potentially harmful files, executing unauthorized software, etc. A raspberry pi was used to download the malware. 

The company's Security Operations Center (SOC) was immediately notified and assessed that these activities were suspicious. The SOC contacted the employee and he said that he was following the steps in router to address a speed issue and that it may have caused a breach.

The SOC also tried to contact the employee by phone, but he stated that he was unavailable and then did not respond. Thus, the experts gained access to the hacker’s device. KnowBe4 shared its findings with threat intelligence firm Mandiant and the FBI. It was determined that the alleged employee was a member of a North Korean-funded hacking group that specializes in such scams.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“The scam goes like this: the hackers actually do the work, get paid well, and give a large sum to North Korea to fund its illegal programs,” Sjouwerman explained.

See also: Dora RAT Malware Targets South Korean Institutes

North Korean hackers defrauded KnowBe4 with "alleged employee"

How to spot fraudulent job candidates

Following this adventure, KnowBe4 provided advice on how companies can avoid similar scams:

  • Stronger background checks, with an emphasis on potential minor discrepancies, such as inconsistencies in address and date of birth across different sources
  • Continuous review of the candidate's career
  • Verify that remote workers are physically where they are supposed to be
  • Communication via telephone and video calls
  • Scan remote devices for control
  • Implement improved monitoring for any persistent attempts to access systems
  • Strengthening authentication processes
  • Cybersecurity training for employees and executives, including HR teams.

The KnowBe4 incident serves as a reminder that no organization is immune to insider threats. Investing in cybersecurity training can go a long way in preventing such incidents. It is important for organizations to prioritize training HR teams to recognize potential fraudsters trying to gain a position on staff. With the right combination of technology and human awareness, organizations can significantly strengthen their overall security posture and protect themselves from threats.

North Korean hackers pose a threat to global security through their attacks and sophisticated tactics, and organizations must be very careful.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS