{"id":4812,"date":"2024-08-12T08:30:00","date_gmt":"2024-08-12T13:30:00","guid":{"rendered":"https:\/\/www.darkreading.com\/remote-workforce\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds"},"modified":"2024-08-12T08:30:00","modified_gmt":"2024-08-12T13:30:00","slug":"tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/12\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds\/","title":{"rendered":"Tennessee Man Helped DPRK Workers Get Jobs at US Orgs, Fund WMDs"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt54ba861778e31037\/66b65c2be444092ffcc698b5\/DPRK_laptop-TongRO_Images-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The US Department of Justice (DoJ) charged a Tennessee resident for helping North Koreans obtain IT jobs at US companies under false pretenses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In August 2023, FBI agents raided the &#8220;laptop&#8221; farms 38-year-old Matthew Isaac Knoot operated out of his Nashville residences. From his laptops, North Korean and Chinese individuals overseas could connect to corporate networks in the US and UK, perform their jobs, and funnel their salaries back to their country&#8217;s ruling party. According to authorities, this money helps fund North Korean leader Kim Jong-Un&#8217;s nuclear weapons programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For his farming, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/usao-mdtn\/pr\/department-disrupts-north-korean-remote-it-worker-fraud-schemes-through-charges-and\" rel=\"noopener\">Knoot has been charged<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with conspiracy to cause damage to protected computers, conspiracy to launder monetary instruments, conspiracy to commit wire fraud, intentional damage to protected computers, aggravated identity theft, and conspiracy to cause the unlawful employment of aliens. Those charges carry a maximum penalty of 20 years in prison.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"North Koreans Infiltrate US Companies Across the Spectrum\">North Koreans Infiltrate US Companies Across the Spectrum<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When the COVID-19 pandemic spurred companies to go remote, the Kim regime spotted an opportunity. Since then \u2014 and in Knoot&#8217;s case, since July 2022 \u2014 DPRK government agents have been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/dprk-hackers-masquerade-as-tech-recruiters-job-seekers\" rel=\"noopener\">flooding the US job market<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with the aim of sending their lucrative earnings back to the government.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The operations have been growing more sophisticated year by year. As Mandiant\u2019s North Korean threat hunting team leader Michael Barnhart explains, &#8220;There&#8217;ll be 10 people living in a house, with each person in the house running seven, eight, 10 profiles \u2014 getting seven, eight, 10 paychecks, 70 paychecks for one apartment. That money does stack up.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another sign of improvement: Where once they mainly targeted <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/freelance-market-flooded-with-north-korean-it-actors\" rel=\"noopener\">freelance tech jobs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, recently, these workers have been earning higher-level roles at specific companies. &#8220;You see [they go for] a lot of senior lead-type engineering roles. Why? That&#8217;s who has the most access to data that you can extort, and you can sell, and you can let your buddies in to do stuff they&#8217;re looking to do,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The DoJ has observed cases across some of the largest companies in the Fortune 500, spanning industries: finance, media, technology, cybersecurity, and more. At the same time, agents have also been known to infiltrate even small mom-and-pop operations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;At Black Hat, I talked to five different executives who had hired North Korean employees,&#8221; reports Roger Grimes, data-driven defense evangelist at KnowBe4, which itself <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/security-firm-hires-north-korean-hacker-knowbe4\" rel=\"noopener\">accidentally hired a North Korean agent<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> just recently. &#8220;One was a 20-person company, one was a 12-person company. Every company is subject to this sort of attack.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Where Americans Come In\">Where Americans Come In<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When a North Korean agent living in China or Russia applies for a US job, they don a stolen identity, plus a host of assumed personal assets: a pseudonymous email, social media account, payment account, online job site account, a fake personal website, and more.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Next, they need a way to connect to corporate networks domestically. That&#8217;s where a US citizen comes into the picture. &#8220;The lures, from what we&#8217;ve seen, have never been: &#8216;Hey, I&#8217;m a North Korean. Let&#8217;s run this scam,&#8217; Barnhart explains. &#8220;It&#8217;s &#8216;You want to make a couple hundred bucks a day by just working from home?&#8217; Things like that. &#8216;We have a brand new startup company, but it&#8217;s overseas. We&#8217;d like for you to be the face of the franchise in the US.'&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Agents who worked through Knoot&#8217;s farm shared the persona of a real US citizen referred to by the DoJ as &#8220;Andrew M.&#8221; Once they landed a job, Andrew M. would direct companies to send their new work laptop to Knoot&#8217;s address. Upon receiving the laptop, Knoot would log in, connect to company networks, and, without permission, install remote desktop applications. These apps allowed North Koreans to connect from overseas, and earn more than $250,000 each per year, simply by performing their actual jobs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Knoot, in turn, earned a monthly fee from a handler who went by the name Yang Di.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The case mirrors a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/doj-targets-north-koreas-widespread-it-freelance-scam-operation\" rel=\"noopener\">larger one revealed in May<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, involving a middle-aged Arizona woman, a Ukrainian, and three other foreign nationals. That operation earned millions of dollars from more than 300 different companies.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How to Spot a North Korean Worker\">How to Spot a North Korean Worker<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There are certain characteristic signs that your applicant may not be who they claim they are.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A big commonality I&#8217;ve heard from people was that the job seeker really has a hard time getting on camera. If the company asks them, they then have some excuse about why they can&#8217;t,&#8221; Grimes explains.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides that, he adds, &#8220;They&#8217;ll say they work for some big, valid company, but their references [always have] a Gmail or Hotmail address. Their profiles on LinkedIn and other websites have a staleness to them, a simpleness to them that doesn&#8217;t look quite natural. If their company provides equipment, all of a sudden they&#8217;ll say you need to ship it to another address that wasn&#8217;t listed in their r\u00e9sum\u00e9 or their application. They make up an excuse.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To try and pick out fake applicants, companies need to be on the lookout for signs like these and others \u2014 for example, applicants who provide Voice over Internet Protocol (VoIP) phone numbers. &#8220;The number one thing for every company \u2014 I don&#8217;t care what your size is \u2014 is you need to now think about and update your HR hiring practices to take into account these potential fake employees,&#8221; Grimes says, &#8220;and try to put in controls that make it harder for them to be successful.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/remote-workforce\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US Department of Justice (DoJ) charged a Tennessee resident<\/p>\n","protected":false},"author":12,"featured_media":4813,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/tennessee-man-helped-dprk-workers-get-jobs-at-us-orgs-fund-wmds-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4812"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4813"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}