https://www.theregister.com/2025/04/29/north_korea_worker_interview_questions/ # # Sign in / up The Register # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features AI Infrastructure Month Spotlight on RSAC AI Software Development Week Disaster Recovery Week Nvidia GTC Ransomware in Focus The Future of the Datacenter Cybersecurity Month VMware Explore Cloud Infrastructure Month Vendor Voice Vendor Voice Vendor Voice All Vendor Voice The BigQuery Difference AWS Global Partner Security Initiative RapidScale - AWS Security & Compliance SourceFuse Amazon Web Services (AWS) New Horizon in Cloud Computing Klika Tech HERE and AWS GE Vernova with AWS Google Gemini (X) Resources Resources Whitepapers Webinars & Events Newsletters [spotlighto] Spotlight on RSAC 92 comment bubble on white The one interview question that will protect you from North Korean fake workers 92 comment bubble on white FBI and others list how to spot NK infiltrators, but AI will make it harder icon Iain Thomson Tue 29 Apr 2025 // 09:15 UTC # RSAC Concerned a new recruit might be a North Korean stooge out to steal intellectual property and then hit an org with malware? There is an answer, for the moment at least. According to Adam Meyers, CrowdStrike's senior veep in the counter adversary division, North Korean infiltrators are bagging roles worldwide throughout the year. Thousands are said to have infiltrated the Fortune 500. They're masking IPs, exporting laptop farms to America so they can connect into those machines and appear to be working from the USA, and they are using AI - but there's a question during job interviews that never fails to catch them out and forces them to drop out of the recruitment process. [spotlighto] "My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly, because it's not worth it to say something negative about that," he told a panel session at the RSA Conference in San Francisco Monday. [spotlighto] [spotlighto] Meyers explained the North Koreans will use generative AI to develop bulk batches of LinkedIn profiles and applications for remote work jobs that appeal to Western companies. During an interview, multiple teams will work on the technical challenges that are part of the interview while the "front man" handles the physical side of the interview, although sometimes rather ineptly. "One of the things that we've noted is that you'll have a person in Poland applying with a very complicated name," he recounted, "and then when you get them on Zoom calls it's a military age male Asian who can't pronounce it." But it works enough that quite a few score the job and millions of dollars are being funneled back to North Korea via this route. [spotlighto] Once placed in the coveted role, such workers are usually very successful in the company, since they have multiple people working on one job to produce the best work possible - with the hope of getting a promotion and more access to the business' systems - explained panelist FBI Special Agent Elizabeth Pelker. "I think more often than not, I get the comment of 'Oh, but Johnny is our best performer. Do we actually need to fire him?" she said. The aims of these phony workers are two-fold, she explained. Firstly, they earn a wage and use their access to steal intellectual property from the victim. This is usually exfiltrated in tiny chunks so as to not trigger security systems. [spotlighto] One mitigation strategy, she said, was to insist that any interviewee performed coding tests within the corporate environment. These allow the actual IP being used to get checked, interviewers to see how often the prospect is switching between screens, and can allow other clues to leak out that all is not as it seems. If the interloper is exposed and fired, however, they will usually have already collected login details, planted unactivated malware, and will then attempt to extort the maximum they can from the victim. She urged anyone who spots a fake employee to contact their local FBI field office immediately. The Red Queen's race But the attackers are getting smarter, and in some ways the FBI is a victim of its own success. The agency has been distributing advice to US companies but these memos are also being read in Pyongyang and the workers are adapting their tactics. This sometimes involves using both aware and unwitting accomplices. For example, to get around the IP address problem, laptop farms are springing up all over America. If an applicant gets a job, the firm will usually send him a laptop, at which point the interviewee explains that they've moved or have a family emergency, so could they send it to a new address please? * North Korea's fake tech workers now targeting European employers * Arizona laptop farmer pleads guilty for funneling $17M to Kim Jong Un * US 'laptop farm' man accused of outsourcing his IT jobs to North Korea to fund weapons programs * North Korean dev who renamed himself 'Bane' accused of IT worker fraud caper * Security biz KnowBe4 hired fake North Korean techie, who got straight to work ... on evil * I'm a security expert, and I almost fell for a North Korea-style deepfake job applicant ...Twice * North Koreans clone open source projects to plant backdoors, steal credentials This is most likely a laptop farm, where someone in the US agrees to run the laptop from a legitimate address for a fee, typically around $200 a computer, according to Meyers. Last year the FBI busted one such operation in Nashville, Tennessee, and charged the operator with conspiracy to cause damage to protected computers, conspiracy to launder monetary instruments, conspiracy to commit wire fraud, intentional damage to protected computers, aggravated identity theft, and conspiracy to cause the unlawful employment of aliens. Rather than creating identities, the North Korean workers have now taken to either stealing the ones they want, or fooling people into handing them over for a good cause. There's a growing business in Ukraine of convincing people to share their identity with third parties under the pretext of using them against Chinese agents who are propping up Russia. "Unfortunately, because this is supporting North Koreans, the money then goes back through to filter through to North Korea regime," said Chris Horne, senior director at jobs site Upwork. "Then, in turn, it goes to support the troops that come back in through Russia. So they're basically paying for their own demise in Ukraine right now." We've also seen deepfake job interviewees that are good enough to fool IT professionals, sometimes more than once. This technology is only improving and will get more and more convincing, Pelker warned. The key to fixing this, the panelists agreed, was to educate everyone in the interview process - right down to the lowest staffer - and to be hyper vigilant for warning signs. If possible, they said, one should have someone local swing around for a personal meeting, and maybe also avoid hiring fully remote employees. (r) Editor's note: This article was updated to correctly state Chris Horne's employer, namely Upwork rather than Upworthy. We regret the error. Get our Tech Resources # Share More about * FBI * North Korea * Security More like these x More about * FBI * North Korea * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * CHERI * CISO * Common Vulnerability Scoring System * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Encryption * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Infrastructure Security * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust Broader topics * APAC * United States Department of Justice More about # Share 92 comment bubble on white COMMENTS More about * FBI * North Korea * Security More like these x More about * FBI * North Korea * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * CHERI * CISO * Common Vulnerability Scoring System * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Encryption * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Infrastructure Security * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust Broader topics * APAC * United States Department of Justice TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Ransomware scum and other crims bilked victims out of a 'staggering' $16.6B last year, says FBI Biggest threat to America's critical infrastructure? Ransomware Cyber-crime24 Apr 2025 | 7 China is using AI to sharpen every link in its attack chain, FBI warns RSAC Artificial intelligence is helping Beijing's goons break in faster and stay longer Spotlight on RSAC29 Apr 2025 | 10 America's cyber defenses are being dismantled from the inside Opinion The CVE system nearly dying shows that someone has lost the plot CSO23 Apr 2025 | 92 AI revolution driving datacenter network investment surge Why more companies are recognizing the need to make infrastructure fit for purpose in the brave new world of AI Sponsored Feature [spotlighto] We're calling it now: Agentic AI will win RSAC buzzword Bingo RSAC All aboard the hype train Spotlight on RSAC23 Apr 2025 | 8 Ex-NSA chief warns AI devs: Don't repeat infosec's early-day screwups Bake in security now or pay later, says Mike Rogers AI Software Development Week23 Apr 2025 | 6 Signalgate lessons learned: If creating a culture of security is the goal, America is screwed Opinion Infosec is a team sport ... unless you're in the White House Public Sector25 Apr 2025 | 97 How Amazon red-teamed Alexa+ to keep your kids from ordering 50 pizzas RSAC Will the personal assistant shop for groceries? Or get hijacked by a teen? Spotlight on RSAC1 May 2025 | 14 Google's got a hot cloud infosec startup, a new unified platform -- and its eye on Microsoft's $20B+ security biz Cloud Next How Chocolate Factory hopes to double down on enterprise-sec CSO9 Apr 2025 | 7 Watch out for any Linux malware sneakily evading syscall-watching antivirus Google dumped io_uring after $1M in bug bounties CSO29 Apr 2025 | 13 China now America's number one cyber threat - US must get up to speed RSAC Former Rear Admiral calls for National Guard online deployment and corporates to be held accountable Spotlight on RSAC29 Apr 2025 | 20 Uncle Sam kills funding for CVE program. Yes, that CVE program Updated Because vulnerability management has nothing to do with national security, right? CSO16 Apr 2025 | 179 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2025 no-js