Full Report
KnowBe4 had been searching for a principal-level developer and posted this job online. At the end of it, the employee hired was North Korean. The individual had stolen the identity of an American, allowing background checks and other procedures to pass. Upon being onboarded, they were sent a MacBook at a different location than their resume stated. Once they accessed their computer, they attempted to add password-stealing Malware. The EDR on the laptop quickly noticed this, and the SOC team asked the new hire if everything was alright. He made confusing excuses, refused to hop on a call and then stopped responding on Slack altogether. Because of this weird behavior, the laptop was completely locked down from the network after only 25 minutes from the first alert. Upon analyzing the laptop remotely, they realized that the Raspberry Pi was being used to access the keyboard, video, and mouse. This was to ensure that the laptop didn't have any weird TCP/IP traffic for remote access running that could be detected. The sophistication has ramped up on this in the last 4 years, and the work-from-home (WFM) boom of COVID made this easier as well. Instead of flat-out fake identities, they decided to steal identities. NK started jumping on calls, which hadn't happened before. As such, they have documented some of these changes in this report. There are four parties involved: North Korean Program leaders, North Korean employees in other countries, non-Korean assistants, such as laptop farms and infrastructure for falsifying identities. The criminal ecosystem assists the NKs with their fake-employee schemes. They will use fake, stolen, and purchased identities when applying for jobs. They have used forged/stolen driver's licenses, passports, diplomas, credit card statements and many other things. Stolen or purchased identities are preferred because they easily pass background checks. Sometimes, an individual gets involved to get paid even. When operating these jobs, they run laptop farms in the same country and then give the NK's remote access to the devices. One of these laptop farms will sometimes have 90 different laptops from various employers. Instead of using the location on their resume, they almost always ship to this address, making it a tell-tale sign of a NK actor. Fake employers are also problematic. They will give you a fantastic job, only to compromise your work or personal laptop in the process with malicious software they ask you to download. The main purpose of all of this is to bring in illegal money for North Korea. At the end is a huge list of red flags. The ones for the hiring phase are as follows: Asian descent with an English-looking name, went to a US university, but speaks English poorly with a heavy accent. Identity information, work information and other checks will fail, unless stolen. When interacting with them, there are a few signs as well. All connections will come from VPNs, the interview will be in a noisy call-center-like location, phone numbers they use are VOIP, and they may hesitate to be on camera. Their Internet presence will only be for the links that they sent. It is common for information to contradict itself. After hiring, a few things are noticable: IP address doesn't match expected location. If it does, there's a remote login software on the laptop or other malware. Work hours are inconsistent with company hours, and they won't jump on calls/respond promptly. Inconsistent product quality, especially if it doesn't seem like the person who had actually been interviewed. Payment requests are strange. Either weird banks or cryptocurrency. Korean language support found on the laptop. To prevent these types of attacks, check all of the information above. For instance, check references, if the numbers are VOIP, use cameras, etc. Asking questions about normal country things, such as "What is the name of that mascot of the college you went to?" is a good way to trip them up. Overall, a great and informative post on NK fake employee/employer scams.
Analysis Summary
# Incident Report: Insider Threat via Falsified Identity (North Korean Actor)
## Executive Summary
KnowBe4 unwittingly hired a North Korean operative for a principal-level developer position using a stolen U.S. identity. The threat actor attempted to deploy password-stealing malware immediately upon onboarding, which was detected by Endpoint Detection and Response (EDR) software. The incident resulted in no known data loss due to a rapid response that isolated the device within 25 minutes of the initial alert.
## Incident Details
- **Discovery Date:** Not specified (Post-onboarding)
- **Incident Date:** Recent (Post-COVID WFH era)
- **Affected Organization:** KnowBe4
- **Sector:** Cybersecurity/Security Awareness Training
- **Geography:** United States (Remote)
## Timeline of Events
### Initial Access
- **Date/Time:** Onboarding phase
- **Vector:** Recruitment Fraud / Stolen Identity
- **Details:** The actor used a stolen U.S. identity and forged documents (ID, diplomas) to pass background checks. They were hired as a principal developer.
### Lateral Movement
- **Details:** None reported. The actor was contained before moving beyond the local workstation.
### Data Exfiltration/Impact
- **Details:** No data exfiltration reported. The primary impact was the attempted installation of info-stealing malware and unauthorized remote access infrastructure.
### Detection & Response
- **T+0:** Actor accesses the company MacBook and attempts to download password-stealing malware.
- **T+5 (approx):** EDR triggers an alert on the malicious activity.
- **T+10:** SOC team contacts the "employee" via Slack; the actor provides evasive excuses and refuses to join a call.
- **T+25:** SOC team completely locks down the laptop and removes it from the network due to suspicious behavior.
- **Post-Incident:** Remote forensic analysis reveals a Raspberry Pi setup for KVM (Keyboard, Video, Mouse) remote control.
## Attack Methodology
- **Initial Access:** Recruitment fraud using stolen/purchased identities and forged credentials.
- **Persistence:** Maintaining a physical "laptop farm" in the U.S. to host the corporate device.
- **Defense Evasion:** Use of a hardware-based Raspberry Pi KVM to control the laptop, avoiding detection of software-based remote desktop protocol (RDP) or suspicious TCP/IP traffic.
- **Credential Access:** Attempted installation of password-stealing malware.
- **Impact:** Attempted financial gain/espionage for North Korean state interests.
## Impact Assessment
- **Financial:** Minimal; limited to hiring costs and hardware loss.
- **Data Breach:** None confirmed.
- **Operational:** Low; 25 minutes of unauthorized workstation access.
- **Reputational:** Moderate; serves as a public case study on high-sophistication recruitment fraud.
## Indicators of Compromise
- **Behavioral:** Shipping address for hardware differs from resume address; refusal to join video calls; inconsistent English proficiency/accents compared to resume; use of VOIP numbers.
- **Hardware:** Presence of unauthorized Raspberry Pi/KVM devices.
- **Software:** Unauthorized VPN usage; Korean language support packs on a U.S.-based workstation.
## Response Actions
- **Containment:** Full network isolation of the affected laptop within 25 minutes.
- **Eradication:** Remote wiping/lockdown of the device and termination of the fraudulent contract.
- **Recovery:** Forensic analysis of the hardware to identify the "laptop farm" methodology.
## Lessons Learned
- **Background Checks are Not Infallible:** Stolen identities of real people can bypass standard verification processes.
- **Shipping Anomalies:** Requesting equipment be sent to a location other than the verified home address is a critical red flag.
- **Hardware-Level Evasion:** Threat actors are moving away from software RDP to hardware KVMs to bypass network-based remote access detection.
## Recommendations
- **Enhanced Vetting:** Conduct video interviews and require candidates to answer culturally specific or "localized" questions (e.g., college mascots) to verify identity.
- **Device Security:** Enforce strict EDR policies that alert on the first sign of unauthorized software installation.
- **Logistics Verification:** Strictly prohibit shipping corporate hardware to addresses not verified during the background check process.
- **Identity Verification:** Use specialized services to verify the validity of government-issued IDs during the "I-9" or onboarding phase.