惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Security Latest
Security Latest
S
Security @ Cisco Blogs
L
LINUX DO - 热门话题
T
Threatpost
W
WeLiveSecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
腾讯CDC
雷峰网
雷峰网
Cyberwarzone
Cyberwarzone
V
V2EX - 技术
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Proofpoint News Feed
T
Tailwind CSS Blog
Cisco Talos Blog
Cisco Talos Blog
人人都是产品经理
人人都是产品经理
罗磊的独立博客
P
Privacy International News Feed
The Register - Security
The Register - Security
T
Threat Research - Cisco Blogs
IT之家
IT之家
T
True Tiger Recordings
SecWiki News
SecWiki News
V
Vulnerabilities – Threatpost
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 司徒正美
月光博客
月光博客
P
Privacy & Cybersecurity Law Blog
N
News | PayPal Newsroom
Google DeepMind News
Google DeepMind News
The Cloudflare Blog
美团技术团队
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - Franky
V
Visual Studio Blog
E
Exploit-DB.com RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
F
Future of Privacy Forum
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Commits to openclaw:main
Recent Commits to openclaw:main
C
Cisco Blogs
AWS News Blog
AWS News Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
I
InfoQ
U
Unit 42

WeLiveSecurity

Foul play: Scams target soccer fans with fake World Cup tickets, merchandise Webworm: New burrowing techniques The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE
Recruitment red flags: Can you spot a spy posing as a job seeker?
2025-10-28 · via WeLiveSecurity

Business Security

Here’s what to know about a recent spin on an insider threat – fake North Korean IT workers infiltrating western firms

28 Oct 2025  •  , 5 min. read

Recruitment red flags: Can you spot a spy posing as a job seeker?

Back in July 2024, cybersecurity vendor KnowBe4 began to observe suspicious activity linked to a new hire. The individual began manipulating and transferring potentially harmful files, and tried to execute unauthorized software. He was subsequently found out to be a North Korean worker who had tricked the firm’s HR team into gaining remote employment with the firm. In all, the individual managed to pass four video conference interviews as well as a background and pre-hiring check.

The incident underscores that no organization is immune from the risk of inadvertently hiring a saboteur. Identity-based threats aren’t limited to stolen passwords or account takeovers, but extend to the very people joining your workforce. As AI gets better at faking reality, it’s time to improve your hiring processes.

The scale of the challenge

You might be surprised at just how widespread this threat is. It’s been ongoing since at least April 2017, according to an FBI wanted poster. Tracked as WageMole by ESET Research, the activity overlaps with groups labelled UNC5267 and Jasper Sleet by other researchers. According to Microsoft, the US government has uncovered more than 300 companies, including some in the Fortune 500, that have been victimized in this way between 2020 and 2022 alone, The tech firm was forced in June to suspend 3,000 Outlook and Hotmail accounts created by North Korean jobseekers.

Separately, a US indictment charged two North Koreans and three “facilitators” with making over $860,000 from 10 of 60+ companies they worked at. But it’s not just a US problem. ESET researchers warned that the focus has recently shifted to Europe, including France, Poland and Ukraine. Meanwhile, Google has warned that UK companies are also being targeted.

How do they do it?

Thousands of North Korean workers may have found employment in this way. They create or steal identities matching the location of the targeted organization, and then open email accounts, social media profiles and fake accounts on developer platforms like GitHub to add legitimacy. During the hiring process, they may use deepfake images and video, or face swapping and voice changing software, to disguise their identity or create synthetic ones.

According to ESET researchers, the WageMole group is linked to another North Korean campaign it tracks as DeceptiveDevelopment. This is focused on tricking Western developers into applying for non-existent jobs. The scammers request that their victims participate in a coding challenge or pre-interview task. But the project they download to take part actually contains trojanized code. WageMole steals these developer identities to use in its fake worker schemes.

The key to the scam lies with the foreign facilitators. First, they help to:

  • create accounts on freelance job websites
  • create bank accounts, or lend the North Korean worker their own
  • buy mobile numbers of SIM cards
  • validate the worker’s fraudulent identity during employment verification, using background check services

Once the fake worker has been hired, these individuals take delivery of the corporate laptop and set it up in a laptop farm located in the hiring firm’s country. The North Korean IT worker then uses VPNs, proxy services, remote monitoring and management (RMM) and/or virtual private servers (VPS) to hide their true location.

The impact on duped organizations could be massive. Not only are they unwittingly paying workers from a heavily sanctioned country, but these same employees often get privileged access to critical systems. That’s an open invitation to steal sensitive data or even hold the company to ransom.

How to spot – and stop – them

Unknowingly funding a pariah state’s nuclear ambitions is almost as bad as it gets in terms of reputational damage, not to mention the financial exposure to breach risk that compromise entails. So how can your organization avoid becoming the next victim?

1. Identify fake workers during the hiring process

  • Check the candidate’s digital profile, including social media and other accounts online, for similarities with other individuals whose identity they may have stolen. They may also set up several fake profiles to apply for jobs under different names.
  • Look out for mismatches between online activities and claimed experience: A “senior developer” with generic code repositories or recently created accounts should raise red flags.
  • Ensure they have a legitimate, unique phone number, and check their resume for any inconsistencies. Verify that the listed companies actually exist. Contact references directly (phone/video call), and pay special attention to any employees of staffing companies.
  • As many applicants may use deepfake audio, video and images, insist on video interviews and perform them multiple times during recruitment.
  • During the interviews, consider any claims of a malfunctioning camera to be a major warning. Ask the candidate to turn off background filters to have a better shot at identifying deepfakes. (The giveaways could include visual glitches, facial expressions that feel stiff and unnatural and lip movements that don’t sync with the audio.) Ask them location- and culture-based questions about where they “live” or “work” concerning, for example, local foods or sports.

2. Monitor employees for potentially suspicious activity

  • Be alert to red flags such as Chinese phone numbers, immediate downloading of RMM software to a newly-issued laptop, and work performed outside of normal office hours. If the laptop authenticates from Chinese or Russian IP addresses, this should also be investigated.
  • Keep tabs on employee behavior and system access patterns such as unusual logins, large file transfers, or changes in working hours. Focus on context, not just alerts: the difference between a mistake and malicious activity could lie in intent.
  • Use insider threat tools to monitor for anomalous activity.

3. Contain the threat

  • If you think you have identified a North Korean worker in your organization, tread carefully at first to avoid tipping them off.
  • Limit their access to sensitive resources, and review their network activity, keeping this project to a small group of trusted insiders from IT security, HR and legal.
  • Preserve evidence and report the incident to law enforcement, while seeking legal advice for the company.

When the dust has settled, it’s also a good idea to update your cybersecurity awareness training programs. And ensure that all employees, especially IT hiring managers and HR staff, understand some of the red flags to watch out for in future. Threat actor tactics, techniques and procedures (TTPs) are evolving all the time, so this advice will also need to change periodically.

The best approaches to stop fake candidates becoming malicious insiders combine human know-how and technical controls. Make sure you cover all bases.


Let us keep you
up to date

Sign up for our newsletters