In today’s digital world, where remote work is becoming more and more common, it is vital for companies to verify the origins of their employees. A new report from Mandiant, a threat intelligence company, provides valuable clues on how to spot North Korean IT workers who may be involved in illegal activities.

Important findings

  • Companies should ensure that applicants turn on their cameras during interviews.
  • Check the match between identification and online profile.
  • Watch for signs like using remote management tools.

How to Avoid Hiring North Korean IT Workers

The U.S. government has been warning since 2022 about the risks associated with hiring North Korean IT workers. These employees could not only receive illegal salaries, but also use their positions to support hacking campaigns for the regime in Pyongyang. Mandiant recommends the following steps:

  1. Enable camera during interview: This helps to check the visual match with the online profile.
  2. Identity verification: Ensure that the provided identification documents match the applicant.
  3. Check consistency of answers: Ask questions that test the consistency of the applicant’s answers in relation to their background.

Signs for North Korean IT Workers

Some specific signs may indicate that a new team member may be from North Korea:

  • Use of IP based keyboard video mouse systems.
  • Installation of remote-management tools such as AnyDesk or Chrome Remote Desktop.
  • Strong reluctance to join video calls.
  • Use of Voice over Internet Protocol (VoIP) telephone numbers.
  • Multiple remote admin tools installed on a single system.
  • Use of software that simulates mouse movements to keep the laptop active.

Quality of work

Mandiant describes the programming skills of North Korean workers as “below average.” This could indicate that companies hiring such employees may not receive the desired quality.

Ransomware Attacks Rise Dramatically

In addition to the risks posed by North Korean IT workers, the ransomware threat increased by 73% that year. According to the Ransomware Task Force, 6,670 attacks were recorded worldwide. Most targeted high-value organisations, highlighting the need to strengthen security measures.

Conclusion

Identifying and avoiding the hiring of North Korean IT workers is critical for companies to minimize legal and security risks. By implementing simple but effective verification measures, companies can ensure that they are not unwittingly contributing to the financing of a totalitarian regime.

Sources

  • Breach Roundup: How to Spot North Korean IT Workers, GovInfoSecurity.