Site navigation

North Korean Threat Actors Have Infiltrated UK Firms

Tom Quinn

,

north korea fake IT workers
North Korean fake IT workers are infiltrating UK companies, stealing data, and demanding ransoms in a sophisticated insider threat scheme.

A new report from cybersecurity firm Secureworks has found a pattern of ‘fake’ IT workers linked to the North Korean government exploiting their former employers in Western companies, including in the UK, with demands for ransom payouts after gaining insider access.

Secureworks says that its responders identified specific technical and behavioral characteristics associated with these schemes pointing to the Nickel Tapestry group. 

The group is made up of clusters of individuals working on behalf of North Korean interests, with IT workers infiltrating Western companies to make money illegally. These fake employees pose a severe insider threat, with cases of intellectual property theft and US government warnings that their activities are funding North Korea’s illegal weapons programs, including weapons of mass destruction (WMD).

As terrifying a prospect as that might be, the news for businesses could be worse. Secureworks detailed several tactics used by the fake IT workers and harms caused, including one instance where proprietary data was stolen and uploaded to a personal Google Drive location then ransomed for a six-figure sum in cryptocurrency with threats of publication.

Secureworks reported that their researchers had also observed threat actors using Chrome Remote Desktop and AnyDesk to remotely manage and access corporate systems. 

Other methods used included the fake contractors changing the delivery addresses for company-issued laptops and redirecting them to laptop farms, and simply requesting to use personal laptops to work in virtual environments, which Secureworks says tracks with previous Nickel Tapestry tactics to avoid leaving forensic evidence on easily traceable corporate hardware.

Investigations uncovered connections between contractors who gave references for each other, worked in similar roles, and used matching resumes and email formats, with Secureworks saying that in some cases, a single person was found using multiple identities. 

One example showed two different writing styles in the same email thread, hinting that several people were using the same email address. According to the report, this suggests that these fake IT workers often work in the same location, and may even share job responsibilities.

Businesses in the UK have already been warned about the scheme by HM Treasury, with an advisory notice issued last month saying that UK firms are actively being targeted by North Korean infiltrators using online freelance platforms or job marketplaces to advertise their services.


Recommended reading


Using their ‘Probability Yardstick’ the Treasury said they were almost certain (between a 95-100% chance) that the fakes were looking to join businesses in the IT, professional services, electronic money, and crypto sectors.

Among the many red flags that businesses should look out for are inconsistencies in names, work history, nationality, and contact information, as well as a refusal to appear on camera or conduct video interviews, and requests to be paid in cryptocurrency.

From an IT perspective, companies should be wary of anyone using a single, dedicated device for each account, being logged into an account continuously for 1+ days, and requests for hardware to be sent to an address not listed on the IT worker’s documentation.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data