Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » North Korean IT workers at Western firms are now demanding ransom for stolen data
Global Security

North Korean IT workers at Western firms are now demanding ransom for stolen data

AdminBy AdminOctober 18, 2024No Comments3 Mins Read
North Korean IT Workers
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 18, 2024Ravi LakshmananInsider Threat / Cyber ​​Espionage

IT workers of North Korea

North Korean information technology (IT) workers working for Western companies under false identities are not only stealing intellectual property, but demanding ransoms to keep it from leaking, marking a new twist in their financially motivated attacks.

“In some cases, fraudulent workers demanded ransom from their former employers after gaining access to insider information, a tactic not seen in previous schemes,” Secureworks Threat Unit (CTU) said in an analysis published this week. “In one case, a contractor stole proprietary data almost immediately after work began in mid-2024.”

The activity, the cybersecurity firm added, bears similarities to a threat group it tracks as Nickel Tapestry, also known as The famous Cholima and UNC5267.

Cyber ​​security

The IT worker fraud scheme, organized to advance North Korea’s strategic and financial interests, refers to an insider threat operation that involves infiltrating companies in the West to generate illegal income for the sanctioned country.

These North Korean workers are usually sent to countries like China and Russia, from where they pose as freelancers looking for potential employment opportunities. Alternatively, they have been found to steal the identities of legal US residents to achieve the same goals.

They are also known to request shipping address changes for company-issued laptops, often redirecting them to resellers in laptop farmswho are compensated for their efforts by foreign intermediaries and are responsible for installing remote desktop software that allows North Korean actors to connect to computers.

Moreover, multiple contractors may end up being employed by the same company, or alternatively, one person may take on multiple individuals.

Secureworks said it has also seen cases of fake contractors requesting permission to use their personal laptops and even causing organizations to cancel a laptop shipment entirely because they changed the shipping address while it was in transit.

Ransom for stolen data

“This behavior is consistent with the Nickel Tapestry trade, which attempts to avoid corporate laptops, potentially eliminating the need for an in-country intermediary and limiting access to forensic evidence,” it said. “This tactic allows contractors to use their personal laptops to remotely access the organization’s network.”

In a sign that threat actors are evolving and taking their activities to the next level, evidence has emerged that a contractor who was fired by an unnamed company for poor work turned to sending extortion emails including ZIP attachments that contain evidence of data theft.

Cyber ​​security

“This shift significantly changes the risk profile associated with inadvertently hiring North Korean IT workers,” said Rafe Pilling, Director of Threat Intelligence at Secureworks CTU. “They are no longer just after a stable salary, they are looking for higher sums, rather through data theft and extortion, from within the protection of the company.”

To combat the threat, organizations are urged to be vigilant in the hiring process, including conducting thorough background checks, conducting face-to-face or video interviews, and monitoring attempts to divert corporate IT equipment sent by contractors with a declared home address, sending checks to services money transfers and access to the corporate network by unauthorized means of remote access.

“This escalation and the behavior listed in the FBI alert demonstrate the sophisticated nature of these schemes,” Secureworks CTU said, pointing to the employees’ suspicious financial behavior and their attempts to avoid turning on video during calls.

“The emergence of buyback requirements marks a marked departure from previous Nickel Tapestry schemes. However, the activity observed prior to the extortion is consistent with previous schemes involving North Korean workers.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.