Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

nk flag
nk flag - Photo by VCG/VCG via Getty Images

As North Koreans continue to infiltrate companies by securing remote IT jobs, a pair of cybersecurity researchers hit back by creating a fake startup to trap them and monitor their activities.

NorthScan's Heiner García and Mauro Eldritch from Birmingham Cyber Arms LTD managed to hire a trio of suspected North Korean IT workers, who ultimately revealed all their tactics. Footage of their job interviews, video meetings, and activities has also been published online.

As bait, the researchers created a fake startup, Ballena Azul, which pretended to focus on decentralized finance for large holders of cryptocurrency , which North Koreans have been known to target to fund the country's regime. 

Advertisement
Advertisement

Researchers then reached out to a recruiter on the software platform GitHub, known for helping North Koreans land remote IT positions. Ballena Azul then interviewed and hired three suspected North Koreans, who claimed to reside in the US. As evidence, they provided state driver's licenses and Social Security numbers. But they appeared to have been faked or stolen. For example, one of the IDs appeared to be a forgery generated by an AI image generator. Another state ID was likely stolen from a real person in New York. 

During the interview process, the suspected North Koreans also refrained from using AI deepfakes to change and mask their real appearance. Still, one of the hired workers was caught repeatedly glancing off-screen during the interview "as if reading from a second monitor running a live translation tool," the researchers said. 

To monitor the hired North Korean workers, the cybersecurity researchers gave them access to a virtual desktop tool as part of the job. But it was actually remote monitoring software from Any.Run, which was able to record every file opened and every click made. 

The monitoring showed the North Koreans were hiding their true whereabouts using the VPN service AstrillVPN. They also relied heavily on ChatGPT to help them answer questions and complete coding tasks. Saved AI prompts were stored and accessed from several browser extensions.

Advertisement
Advertisement

Another interesting find was that the hired North Koreans struggled to perform their jobs. "They googled the basics, like how to build upgradeable smart contracts, imported an existing MetaMask wallet, and then struggled to scrape together some crypto from testnet faucets," the researchers wrote. 

García and Eldritch presented the findings during a talk at the DEF CON hacking convention last week. To conclude their investigation, the researchers confronted two of the hired North Korean workers about their forged work documents via  video meeting ; the two workers promptly left the meeting once they realized they had been exposed.

Although the cybersecurity industry has been warning about North Korean IT workers infiltrating jobs for years now, the threat continues to persist. An FBI assistant director revealed last month that the North Koreans were able to recently secure a job at a federal government agency, according to the Federal News Network.

PCMag and Yahoo may earn commission from links in this article.

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: