Daily Blog #790: Is your new contractor from North Korea?
FBI警告称,北韩IT员工通过欺诈手段进入美国公司工作,并窃取敏感信息或资金转移回北韩政权。这些员工可能表现优秀或敷衍了事,但若有机会会窃取机密并勒索雇主。公司需警惕此类行为,并审查员工的工作和访问权限。 2025-3-28 03:1:0 Author: www.hecfblog.com(查看原文) 阅读量:19 收藏

By March 27, 2025

Hello Reader,

You may have seen alerts from the FBI like this


 Many of us working investigations have encountered one of these cases in the last year. A company finds out from multiple reasons:

1. The North Korean IT worker VPN drops and exposes a Chinese or North Korean IP

2. Someone appears on camera who does match the original photos taken

3. You get a reach out from the FBI

4. You notice suspicious activity on a new developers system

In all of these examples many times what you'll find is a North Korean citizen who has been asked to generate revenue for their government.  Many organizations have even talked about how the North Korean IT worker was a model employee, maybe even one of their best. In other cases I've seen the North Korean IT worker is just creating busy work and doing the bare minimum, like something out of the overemployed subreddit. 

In either case it can become easy to lower your guard towards this incident, especially when their actions appear to be more to gain income that encrypt your systems. However if given the opportunity the same model worker will steal all of your secrets and extort you.

 “To prop up its brutal regime, the North Korean government directs IT workers to gain employment through fraud, steal sensitive information from U.S. companies, and siphon money back to the DPRK,” said Deputy Attorney General Lisa Monaco.

So if you find yourself with employees who took work from home to a new level, make sure to carefully review their work, changes and access. You may be lucky like some of my clients and find they were just collecting a paycheck, but you may also find a trail of stolen data or code modifications. 


文章来源: https://www.hecfblog.com/2025/03/daily-blog-790-is-your-new-contractor.html
如有侵权请联系:admin#unsafe.sh