LIVE · cybersecurity feed
Live wire
security

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. [...]

zeroday.news ·

North Korean IT workers are reportedly exploiting vulnerabilities in remote hiring processes to gain employment with foreign companies, exfiltrate sensitive data, and funnel salaries back to North Korea. These operations leverage sophisticated tactics to bypass standard identity verification and onboarding controls, according to a July alert from the US Department of State and warnings from the FBI.

The scheme involves impersonating nationals of other countries and falsifying credentials to secure remote IT positions. Once embedded within an organization, these fraudulent workers may copy source code repositories, steal proprietary information, and support broader cybercriminal activities. In some instances, after being discovered or dismissed, they have attempted to extort former employers by threatening to publish stolen data.

A key tactic involves creating fake professional profiles and social media accounts, often using artificial intelligence to mimic the tone and language of legitimate IT professionals. They may also forge identification documents or use proxies to register accounts on online platforms. To disguise their true location, these individuals often employ VPNs and remote desktop software.

Further complicating detection, some operations utilize overseas facilitators. Employer-issued computers are shipped to an address in the country where the worker claims to reside. The facilitator then keeps these devices powered on and connected, enabling the overseas worker to control them remotely. Payment methods can also be unorthodox, with a preference for money transfers or cryptocurrency over direct deposits, and some North Korean workers have been observed using third parties for salary deposits.

Standard employment checks, such as background checks, right-to-work verifications, and identity screenings, are often insufficient to counter these sophisticated tactics. While these checks confirm the credibility of supplied details, they fail to verify that the person interviewed is the same individual who receives the equipment and ultimately logs into the system. The operations are designed to satisfy specific controls: a stolen or proxy-supplied document for identity, a fabricated resume for initial review, a proxy or skilled worker for the interview, a facilitator's address for equipment delivery, a "laptop farm" for location and device expectations, and a third-party account for payroll.

Warning signs of a potential fake remote worker include frequent changes to registered information, a mismatch between the account holder's name and the registered payment account, multiple accounts created with the same ID, or a single account accessed from multiple IP addresses in a short period. Unusually high logged hours can also be an indicator.

The FBI has noted that stolen credentials are a significant factor in data breaches, involved in 44.7% of incidents according to one report. This underscores the importance of robust identity verification throughout the employment lifecycle.

To mitigate these risks, organizations are advised to implement more stringent vetting processes for remote and freelance hires. This includes incorporating government-issued identity document scanning and biometric liveness detection into the onboarding process. Document checks confirm the authenticity of the identity document, while biometric checks compare the person completing onboarding with the photograph on that document. Liveness detection further ensures that a real person is physically present, rather than a photograph, recording, or manipulated video.

Even with these measures, a stolen or third-party-supplied identity document remains a possibility, and advanced deepfakes could potentially bypass facial recognition. Therefore, a combination of document validation and biometric liveness detection provides stronger evidence than either control alone. The core lesson is that identity should not be treated as a one-time record but as an ongoing access control, requiring re-verification when access is recovered or changed.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]