North Korean hacker got hired by US security vendor, immediately loaded malware (arstechnica.com)
from jeffw@lemmy.world to technology@lemmy.world on 25 Jul 2024 03:15
https://lemmy.world/post/17926277

#technology

threaded - newest

SpicyLizards@reddthat.com on 25 Jul 2024 08:25 next collapse

Way to break that hard earned trust guys

paridoxical@lemmy.world on 25 Jul 2024 08:43 collapse

They lost any trust when we learned they are a bunch of bat-shit scientologists.

jaybone@lemmy.world on 25 Jul 2024 14:24 collapse

North Korea?

[deleted] on 25 Jul 2024 10:43 next collapse

.

Imhotep@lemmy.world on 25 Jul 2024 10:46 next collapse

Even though the photo provided to HR was fake, the person who was interviewed for the job apparently looked enough like it to pass.

why not send an actual picture of his face?

Philippe23@lemmy.ca on 25 Jul 2024 10:52 collapse

My guess would be that they needed to get a mid-point between existing photos of the guy whose identity they stole and the guy that would show up in the video interviews.

boyi@lemmy.sdf.org on 25 Jul 2024 11:14 collapse

Very unlikely, If you read and refer to the article. The identity was stolen but the pic is a stock photo.

The two images at the top of this story are a stock photo and what KnowBe4 says is the AI fake based on the stock photo.

Philippe23@lemmy.ca on 25 Jul 2024 12:13 collapse

My thought on that is that they needed a new location so their image didn’t just look like a modified version of another of the victim’s public images, so NK searched for a stock photo for a professional looking location. Ars has just located the stock image they started from.

sugar_in_your_tea@sh.itjust.works on 26 Jul 2024 13:12 collapse

Why not just take a new one at a professional looking location in NK?

Randomgal@lemmy.ca on 26 Jul 2024 15:18 collapse

The last photographer starved to death and the guy who imported cameras got executed for not singing Kim’s praises loud enough every morning.

independantiste@sh.itjust.works on 25 Jul 2024 14:50 next collapse

This is the company that made “The Inside Man”, a series where a company gets infiltrated by not being careful enough of who they hire

thurstylark@lemm.ee on 26 Jul 2024 00:36 collapse

Oh yeah, I remember having to watch those for onboarding. They weren’t as cheesy as they could have been for an informational video.

I do appreciate how they’re handling it, though. A public post-mortem is much more reassuring than damage control PR. Plus, being honest means they gain the IT folks who actually have to use their stuff as allies.

independantiste@sh.itjust.works on 26 Jul 2024 05:02 collapse

Yeah, the series is pretty entertaining actually. And for the PR thing, they pitched it as a learning incident, and I agree with that, but they are lucky nothing truly bad happened because this company sends phishing tests, and a link could be replaced by the attackers - kind of like in a fake fake phishing email.

sharkfucker420@lemmy.ml on 26 Jul 2024 02:40 next collapse

Based <img alt="" src="https://lemmy.ml/pictrs/image/4e6f93b0-06ff-43ae-b520-4f59586f0c99.png">

piyuv@lemmy.world on 26 Jul 2024 09:38 next collapse

The scam is that they are actually doing the work, getting paid well, and give a large amount to North Korea to fund their illegal programs.

So even if you do the work and do it well, you’re not allowed to spend your money how you see fit

sugar_in_your_tea@sh.itjust.works on 26 Jul 2024 13:13 next collapse

I just wonder how many haven’t been caught…

ipkpjersi@lemmy.ml on 26 Jul 2024 13:27 collapse

How does that even happen lmao