North Korean IT professionals who trick Western companies into hiring them steal data from the organization's network and demand ransom to keep it from leaking.
See also: Cisco investigates data breach allegations

Sending IT workers to seek employment at companies in wealthier countries is a tactic North Korea has used for years as a means to gain privileged access for cyberattacks or to generate revenue for the country's weapons programs.
Researchers at cybersecurity firm Secureworks uncovered the blackmail element during multiple investigations into such scams. After terminating the employment of a North Korean national with access to proprietary data, the company would receive the first blackmail email, the researchers explain
In order to get the job and avoid raising suspicion thereafter, the North Korean IT professionals used a fake or stolen identity and relied on laptop farms to route traffic between their actual location and the company via a point based in the USA.
They also avoided video calls or resorted to various tricks while at work to hide their faces during video conferences, such as using artificial intelligence tools.
In July, US cybersecurity firm KnowBe4 revealed that it was among hundreds of companies that were victimized, and in their case, the malicious actor attempted to install an infostealer on the company's computer.
See also: Casio confirms data breach by Underground
Secureworks tracks the group that organizes and coordinates North Korea's army of IT workers as "Nickel Tapestry," while Mandiant uses the name UNC5267.

One example of a mid-2024 Nickel Tapestry campaign investigated by Secureworks involved a company that experienced data theft almost immediately after hiring an external partner. The data was transferred to a personal Google Drive using the company’s virtual desktop infrastructure (VDI).
After the North Korean IT professional was terminated for poor performance, the company began receiving extortionate emails from external Outlook and Gmail addresses containing samples of the stolen data in ZIP files. The malicious actors demanded a six-figure ransom to be paid in cryptocurrency in exchange for not leaking the stolen data.
Secureworks' investigation revealed that Nickel Tapestry had used Astrill VPN and home servers to hide its real IP address during malicious activities, while AnyDesk was used to remotely access the systems.
See also: AI call center data breach exposes 10 million conversations
Data theft is a serious security issue that affects both individuals and organizations. It involves the unauthorized access and extraction of sensitive information, such as personal information, financial data, or confidential material. It is often carried out through sophisticated techniques, such as phishing, malware, or hacking. The consequences of data theft can be devastating, causing financial loss, loss of trust, and privacy issues. To protect themselves from this threat, users should implement strong security measures, such as complex passwords, strong encryption , and regular software updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
