Not So Secure: Cybersecurity Firm Hired North Korean Hacker who Faked Identity with AI

KnowBe4, a prominent cybersecurity firm, recently uncovered a sophisticated infiltration attempt by a North Korean “threat actor” who posed as a remote software engineer on their internal IT team. The North Korean spy, after being hired, immediately began uploading malware to the company’s systems. CyberScoop reports that KnowBe4, a leading cybersecurity firm, has exposed an intricate
Not So Secure: Cybersecurity Firm Hired North Korean Hacker who Faked Identity with AI

KnowBe4, a prominent cybersecurity firm, recently uncovered a sophisticated infiltration attempt by a North Korean “threat actor” who posed as a remote software engineer on their internal IT team. The North Korean spy, after being hired, immediately began uploading malware to the company’s systems.

CyberScoop reports that KnowBe4, a leading cybersecurity firm, has exposed an intricate scheme by a North Korean threat actor who successfully infiltrated the company by posing as a remote software engineer. The incident, detailed in a blog post by KnowBe4’s founder and CEO Stu Sjouwerman, highlights the evolving sophistication of cyber threats and the pressing need for enhanced security measures in hiring processes.

The threat actor managed to bypass KnowBe4’s seemingly thorough interview process, which included background checks, verified references, and four video conference-based interviews. The deception was executed using a valid identity stolen from a U.S.-based individual, further enhanced by the use of a stock image augmented by artificial intelligence.

The ruse began to unravel when KnowBe4’s InfoSec Security Operations Center team detected suspicious activities from the new hire. On July 15, the company flagged malware loaded onto an Apple laptop sent to the remote worker. Simultaneously, the AI-filtered photo used by the imposter was identified by the company’s Endpoint Detection and Response software.

Quick action by the SOC team led to the containment of the fake worker’s systems after they ceased responding to outreach. During a brief 25-minute window, the attacker engaged in various malicious activities, including manipulating session history files, transferring potentially harmful files, and executing unauthorized software. Sjouwerman noted that the attacker utilized a single-board computer Raspberry Pi to download the malware.

Following the incident, KnowBe4 shared its findings with the FBI and Mandiant, a Google-owned cyber firm. Their collaborative investigation concluded that the worker was a fictional persona operating from North Korea.

The sophisticated scam involved connecting the fake employee’s workstation to an “IT mule laptop farm” and using a VPN to work night shifts, creating the illusion of being logged on during normal U.S. business hours. This setup allowed the threat actor to perform actual work while funneling a significant portion of the earnings to North Korea to fund illegal programs.

Despite the intrusion’s complexity, Sjouwerman assured that no illegal access was gained, and no data was compromised or exfiltrated from KnowBe4’s systems. He attributed the incident to a highly sophisticated threat actor who exploited weaknesses in the hiring and background check processes.

Read more at CyberScoop here.

Lucas Nolan is a reporter for Breitbart News covering issues of free speech and online censorship.

Total
0
Shares
Leave a Reply
Related Posts
GRAHAM GRANT: Our police force is being turned into a laughing stock while the public suffer from a service on its knees
Read More

GRAHAM GRANT: Our police force is being turned into a laughing stock while the public suffer from a service on its knees

It should come as no surprise that crime increases when the number of police officers is cut – for proof, just take a look around. Scotland’s biggest city has descended into something approaching squalor - and anti-social behaviour is endemic. Drug sales and abuse in the street are fuelled by police inaction - meaningless warnings
Sydney socialite Liz Kemp who moved into dead ex-lover Andrew Findlay’s home and took over ownership of his luxury car loses $14million estate battle with his family
Read More

Sydney socialite Liz Kemp who moved into dead ex-lover Andrew Findlay’s home and took over ownership of his luxury car loses $14million estate battle with his family

A Sydney socialite has lost her battle to keep her ex-partner's mansion and Mercedes AMG after a protracted and bitter legal battle with his family over duelling wills. Elizabeth Kemp, who had three children with late businessman Andrew Findlay, 50,  before they split, attempted in the Supreme Court of NSW to have the tech entrepreneur's 2015 will upheld
‘Deadpool & Wolverine’ smashes R-rated record with $205 million debut, 8th biggest opening ever
Read More

‘Deadpool & Wolverine’ smashes R-rated record with $205 million debut, 8th biggest opening ever

Marvel is back on top with “Deadpool & Wolverine.” ‘Deadpool & Wolverine’ smashes R-rated record with $205 million debut, 8th biggest opening everBy LINDSEY BAHRAP Film WriterThe Associated Press Marvel is back on top with “ Deadpool & Wolverine.” The comic-book movie made a staggering $205 million in its first weekend in North American theaters
Ryu fires 64 to lead by one at LPGA Canadian Women’s Open
Read More

Ryu fires 64 to lead by one at LPGA Canadian Women’s Open

South Korea’s Ryu Hae-ran birdied the first four holes on her way to an eight-under 64, seizing a one-stroke lead after Saturday’s third round of the LPGA Canadian Women’s Open. Ryu, whose only LPGA title came in last October’s Northwest Arkansas Championship, stood on 13-under 203 after 54 holes at Earl Grey Golf Club in