Security researchers warned at Cyberwarcon, a conference focused on threats in cyberspace, of North Korea’s sustained attempt to steal cryptocurrency and secrets by posing as prospective employees of multinational corporations.
One of the tactics used by North Korean hackers is to create false identities and masks to hide their IP addresses, disguise their real locations and continue to operate discreetly across the world.
The cyber attack method used by North Koreans was to create a falsified LinkedIn profile, a GitHub page combined with AI-generated facial and voice-deep learning technology, then link a fake identity with genuine employment credentials.
Infiltration into remote working at US companies was enabled by home addresses in America run by facilitators that set up farms of company-issued laptops, which include remote access software to allow commands to give the impression that hackers are located in America.
North Korean groups can extort money from or blackmail companies by threatening to release skimmed sensitive information, establish multiple artificial accounts or backdoor accounts that can evade crucial access controls or dupe banks into laundering Bitcoins.
Infiltration into industries such as aerospace and defense allowed knowledge necessary to advance further development in the laser-guided missile industry.
North Korean hackers masqueraded as venture capitalists and recruiters to steal cryptocurrency via malware using an illusory meeting trick to encourage the victim to download ransom-demanding malware.
Microsoft reported that the North Korean hackers stole $10m in cryptocurrency over a six-month period alone.
Researchers have called for better background checking of possible employees by companies and recommended companies should introduce two-step verification and should manage company data via cloud-based systems.
The dangers posed by North Koreans despite sanctions and US-imposed fines have prompted the FBI to warn of the threat while the US government has levied sanctions against North Korean-linked organisations.