Video summary
The speaker, Simon, founder of a cybersecurity company called Seaside, explains how his organization discovered a sophisticated campaign involving North Korean state actors attempting to infiltrate the global workforce through remote job applications. Initially appearing as legitimate candidates with impressive backgrounds and high scores on coding assessments, these applicants exhibited numerous red flags upon deeper investigation. Simon noticed significant network latency, the use of AstralVPN—a service known for bypassing China's Great Firewall—and browser artifacts indicating a virtual machine environment rather than a genuine home setup. Furthermore, linguistic analysis revealed that despite claiming to be native English speakers, their speech patterns were inconsistent, and their responses to technical questions about networking protocols like BGP were nonsensical, suggesting they were relying on AI tools or pre-written scripts rather than actual knowledge.
The investigation uncovered that these individuals were part of an organized operation where North Korean officials are sent abroad in groups to work as "hacker mercenaries" to generate revenue for the regime's weapons programs. To bypass standard identity verification processes, many applicants used fake identities, stolen credentials, or even projected images of ID cards onto green screens during video calls. The speaker highlighted a critical failure point in the hiring process: background check vendors often flagged these applications as suspicious but ultimately approved them due to the high cost and liability associated with false positives. Consequently, bad actors slipped through the cracks, eventually receiving laptops shipped to addresses in countries like the US, UK, and Switzerland, which they would then operate remotely, sometimes even filing taxes under false names to legitimize their presence.
The scale of this operation became evident when authorities raided a "laptop farm" in Arizona, seizing over 90 devices and arresting individuals who had unknowingly become part of the supply chain by filing tax returns for these foreign entities. These raids revealed that North Korean agents were utilizing hardware IP KVMs to remotely control computers from their home countries while physically sitting in apartments abroad, effectively turning unsuspecting locals into mules. The financial incentive for these actors is substantial; while a typical worker in North Korea earns roughly $1,300 annually, the remote jobs offered salaries around £112,000, providing access to valuable intellectual property and cryptocurrency funds that they would quickly cash out before disappearing. Once inside a target system, their training allows them to move rapidly through defenses, plant malicious dependencies, and exfiltrate data or funds with standardized efficiency.
In conclusion, the video serves as a stark warning about the evolving risks of remote hiring in an era where AI tools have empowered state-sponsored bad actors to bypass traditional security measures more effectively than ever before. The speaker emphasizes that digital footprints, such as non-standard fonts, unusual network behavior, and metadata inconsistencies, can reveal the true origin of an applicant, but these signals are often overlooked by automated systems under pressure. To mitigate these threats, the company adopts a policy of never hiring anyone without meeting them in person first, acknowledging that some agents will simply not show up for interviews. The overarching message is that while technology like AI makes deception easier for adversaries, human verification and creative investigative techniques remain essential to identifying and stopping nation-state actors from infiltrating critical infrastructure and stealing valuable assets.
Read the full video transcript
WOO!
>> EMF camp, how are we doing? Come on. No.
[screaming]
>> Perfect. Awesome. Okay, cool. Uh, slight
change of tone coming in. Hi, everybody.
Um as much as we are fun, flimsy and
look to be quite like hilarious, uh do
not do what we are going to discuss in
this uh like session today at home, uh
we are security researchers. We have
done this research together with
international law enforcement uh and
also with international crime reporters.
So we had support and backing throughout
this entire journey. Do not just start
doing things with North Koreans. You
might be putting yourself in danger.
Anyway, speaking about putting yourself
in danger, in the back is my intern
right there while I'm driving a van. Um,
I'm Simon. I'm the founder and CEO of
Seaside. Um, I'm a starter founder. Uh,
like there are many, that's not special.
Um, I am the chair of the uh, anti-fraud
division of the W3C, which is a small
community group. Um, I run a small cyber
security company um, around web
security. Um, and kind of the starting
story is very simple. I realized that
firewall vendors were claiming to know
things about browsers when unfortunately
they didn't. and there wasn't really
enough of a browser level security
company in the world. Um, anyway, I'm
originally from Belgium. Um, I used to
live here in the UK. Um, but since a
little while now, I've been based in San
Francisco. All right. So, what do you do
when you start a startup? You do
fundraising. And as is always the case
with fundraising, there is of course
mandatory press coverage that comes as
part of that. And what do you do when
you get given money? You have to deploy
that money and hire people to go build
that thing, build that vision. So, I put
a bunch of jobs online. I used a very
well-known applicant tracking system
that then posted that job on various
platforms. Um, LinkedIn, Indeed, X jobs,
that's a thing nowadays. Uh, bunch of
those platforms. And then, of course,
our investors were nice and reposted
that on their platforms and kind of bit
expected. Um, there were quite some
press articles out there. People were
somewhat interested in what we were
doing and there you go. We started
getting job applicants in tool. We
received thousands. Now, how do you go
to um like sorry, I'm going to start
there. On paper, all these candidates
looks great. They had very relevant
backgrounds, worked at the right
companies before. Um they had an active
GitHub account. It just made sense. So,
these profiles were almost too good to
be true. Um and then how do you sift
through so many of these applications?
Well, you start filtering for the best
ones and then you send them a homework
assessment. do a coding assessment, fill
out this Q&A, um, let's do this
personality assessment to understand how
you are. And then that only should
really only take you an hour or so. And
then here's what came back. Flying
colors. People got 94%. There were some
signs of cheating, which is tolerable.
Um, they slashed it 10 out of 10 out of
10 out of everything. And somehow they
were also interested in learning
speltic, which is not that unpopular.
Um, now then another candidate. Here's
another one. Similar thing, 92%.
However, our React weather app was a bit
too much to ask. [sighs]
Well, what do you do with candidates
like this? Well, you have a call, right?
And they were a little awkward. I'll let
you judge.
Um, so in this question that's going to
come up now, like in the response I'm
going to give, I asked about the border
gateway protocol. The reason why I asked
that is because when you ask people how
does it work to get a web page in a
browser? Well, networking is part of
that. They often forget it and I ask and
kind of what I'm hoping to get here is
people saying I don't know and asking
questions or either giving me a perfect
answer and then we'll dig deeper. The
border gateway protocol is the thing
that makes the internet route. I have a
server in LA that I need to reach. How
do I get there? Right? That's what the
BGP uh like BGP does.
This is going to hurt your brain. It did
to me as well. And I had to sit through
the whole thing. I'm not going to have
you do that. But here we go.
>> Uh actually the regarding this world
protocol, it just uh it just combination
of the uh operator of the border. So uh
actually uh the potential context where
the uh term might apply in this kind of
the uh in this kind of policy then uh
the border management and then also the
um political um commentary is really
important is important.
>> Needless to say none of this made any
sense. Um and so if you think that was
bad uh I kind of doubled down and I
asked it's quite high level. Can you
just be more precise? I really just want
to hear about the networking side of
things.
>> Um well actually this is just what I
told you is just what I provide you is
just a um big picture of the uh options
for each u management and then also
maybe the uh policies. So uh
maybe if I can give you some kind of the
examples then uh for example uh the
agencies like the um like the government
and then also border protection or the
maybe organizations and other countries
uh then it is just they're just
responsible for
>> so this guy was talking about border
protection. Um so clearly border gateway
protocol using his AI tool um meant
border enforcement the physical people
at the airport um asking you if you
brought any chocolate from abroad.
Anyway um what did you notice? Well, a
few initial signs, right? And if you
start having a bunch of these calls,
they're quite clear signs. Uh there's
really significant lag. He claimed to be
a native English speaker. Now I really
don't want to be go using that too much
as a vector, but was he? It didn't
really sound like that. Um, and
honestly, nothing he said made any
sense. Now, this particular recording
was made in 2024 before AI got good
nowadays, he would probably give you a
better answer. Um, but as I said at the
end of that thing, I wasn't going to
have you sit through that whole thing.
At the end, I say, let's move on, which
is like the line, if any interviewer
ever says, let's move on, you know,
you're basically screwed. You've been
caught bullshitting. Anyway, uh, this
was another one of those candidates. I
found this one particularly funny
because um in his glasses you can see
that he was getting some let's put it
external help. Um anyway um and then
well every good employer needs to know
who they're talking to and if you're
trying to be sock 2 compliant which
pretty much every B2B company needs to
do you have to do u background checks.
So we use a platform that does identity
verification for us criminal record
checks tax evasion employment
educational social media blah blah blah
blah blah a bunch of checks very
standard stuff. Now, here's what that
platform returned.
All bueno, nothing to worry about. Uh,
pretty weird. Now, what I found
particularly interesting was the fact,
and you can see that here, there's a
Gmail address. So, they were sending a
Gmail um employment verification emails,
which is not fully like illegal or
weird, but using an Gmail means they can
just create an email address for
someone. Um, so I got a little bit
weirded out by that and I reached out to
this person on LinkedIn. I said, "Hey,
uh, what's up?" Like, "Do you know this
guy?" The answer was, "No."
I'm on to something. So then I checked
the identity card. Now, I can show you
this because it's fake. Um, as you can
see, uh, it looks a little bit way out
of like it looks too perfect of a
picture, doesn't it? Um there's a number
of indicators here that there's an issue
with this but honestly the technology to
make fake identity cards got better
since as well um this past identity
verification initially.
Now then we dug deeper. I reached out to
this identity verification platform and
we actually became good friends
throughout this process. Um and uh it
turned out that their systems did flag
this as a weird application. um there
were all types of issues and they called
this person into a zoom call asking to
show that uh identity card. Now what
this person is using is a green screen
card like any hotel PVC key cards you
can get these in green and he was using
computer vision to project these ID
cards on there. Now this was detected
they immediately spotted that this was
not normal. However, identity
verification is usually done by a bunch
of people in like low-wage countries.
Um, and they're under insane pressure.
So, what happened here was the cost of a
false positive is so high, these people
don't want to bear the responsibility
for it. If a company is trying to
recruit someone and all the way at the
end of the process, it comes back as
this is not legit. You may want to
verify further. That slows down the
recruiting process and it's just
generally not worth it for them. So,
they gave it stamp of approval and a bad
actor got away with it. So that shows
identity verification unfortunately
isn't all it. And there were so many of
these guys. Um we started giving them
Jane do numbers. So on the bottom right
is Jane do 26. Jane do 26 and I we go
way back. Um it's actually uh quite a
warm relationship. We have emojis made
out of his face because he's got a very
expressive uh face. Um there's some like
uh memes about that that I also post on
Twitter every now and then. Anyway, but
Jane do is also known for his um
impeccable um reports on Upwork. So,
these people are actively doing other
things in other places as well. Upwork
being one of those platforms. I'll get
back to that in a bit. Okay, so now they
got me annoyed. There's clearly some
really organized campaign happening out
there with a bunch of honestly nation
state actors trying to get into
companies. And then I remembered the
[ __ ] I'm running this company like we
can do this like we can do browser
forensics and probably we can pull a
bunch of data out of that. So the first
thing that I did was make a job
application portal where if they pressed
the button to start the application
process some fun stuff would happen. You
may want to lower the audio ever so
slightly on my laptop in a second
because it does get quite loud but
dramatic effect. Here we go.
You can buff it for a more dramatic
effect, I think. Yeah. Yeah. So, it um I
actually did it I called one of my
friends who made this open source a
while ago. Um I wasn't going to spend my
company money and time on it. Um but
yeah, when you moved your mouse, the
window would move as well. And when you
were unlucky to then click on it, it
would open more windows and it would put
things in your downloads folder. It
would mess with your clipboards, call
all types of legacy APIs to do weird
[ __ ] in your browsers. open a cat
because why not? Um yeah, that was my
first response and then well then by the
way if you want to check this out
interview LTD do not send it to your
friends or colleagues. Um and then I
thought okay let's behave let's actually
take this thing seriously. So uh we got
some data out of these guys' browsers.
We sent them a little thing to hey can
you please confirm your job application
here? And then we have this fancy
dashboard in our product. Uh it's not a
marketing pitch but you get it. We
gather a bunch of data about these
people and then kind of the dimensions
that we look at it is the user, the
browser, the device, the network. Now,
I'll start with the network. The network
hella high latency. Woohoo. Like you
could go out and like get yourself a
little cup of tea set up by the time the
web page loaded. Um, they were also
using the mother of all signals,
AstralVPN. Has anybody here heard of
AspilVPN? AstralVPN is one of the only
VPN providers that works from inside the
great firewall in China. Uh which is
usually an indicator that there's some
fishy stuff happening. Um now when it
comes to the browser/ the device, well
it was a Windows virtual machine. Um
very clearly a virtual machine and it
had some non-standard range fonts on
them. For example, Shiona by all means
look it up. Um that's kind of a a very
common Korean but towards a North Korean
dialect font. Um, they're usually not
dumb enough to use Red Star OS, but it
does happen. Um, so yeah, there we go.
To those of you that don't know, Red
Star OS is a kind of an old Linux-based
operating system that they use in the
DPRK. Anyway, um, browser signals. Um,
the other thing that we noticed is there
was a really significant amount of
latency between the rendering of the
page and them actually doing something.
So usually when you go through a form
for example, you would do a thing and
something else would come up and then
you'd respond to that and then there you
go. And another clear one is when you
type something usually it comes in
relatively consistently with some level
of like movement between it. If you have
a bad network connection with a lot of
latency then usually comes in in a
freaking chunk like right and you've
observed that there. So it was very
clear um that like that was not a normal
somebody sitting behind their computer
doing their work thing. the homework
assessments as well. These tools that we
use for these homework assessments, they
provide you with like 800 or a,000 or
5,000 or so different questions you can
ask your candidates, but they are
standardized. So these people have made
their own standardized library of
answers on their side and just copy
paste them in. Um, so that's all very
standardized and clean on their end. And
then of course nowadays, and this is
more of like a last year thing, um, more
and more AI automations using browser
use. So actually using the browser and
doing mouse movements and stuff and and
basically filling out an assessment um I
must say a little bit faster than is
reasonable. Uh so you can still have it
as a thing. Now here comes our fun
secret sauce. We were able to locate
some of these people. Um so neighboring
countries of uh like North Korea, you'll
find a few cities like Dan Dong uh but
also Shenyang, Yanji um and uh there's
another one Vanji anyway. and then also
in Russia, a neighboring city there.
Now, uh then also spreads to other
countries like Laos, uh which is a
beautiful between Vietnam and um
Thailand. Beautiful place to go, but I
can never um and then uh North America
uh and like London and and Switzerland
and and like numerous places they were
acting as if they were there. That being
said, it was all quite obvious.
Okay, now this is where kind of the
deeper research uh that we did with
agencies came in. What we know about how
these actors work to become a North
Korean official and be able to leave the
country, you have to really climb the
ranks. And so what happens is they sent
these people out in groups of eight,
usually to two or threebedroom
apartments. Um basically making them
into a sweat shop and kind of forcing
them to work as hard as they possibly
can and bring back as much as re revenue
as possible. they know their family is
being watched and if they do anything
out of line that is their family on the
line. Um they have some standardized
process. So for example the identity
verification program that I explained
they definitely have an internal
handbook on how to do that. Um and they
get very organized at like bypassing
these tools because there is just so
many of them. But they do have their own
freedom when they're kind of little club
on how to do things. Um they rarely I
would say do things outside of the US
because of the logistics of it. and I'll
talk about that as well. Um, they have
laptop mules, but most of them are in
the US. Um, if they are hired within any
of these other countries, then they're
very likely make up some story and ask
you to send the laptop to the US anyway.
Um, and actually, this is a fun one. I'm
not going to claim any credit for this.
There's a bunch of people on Twitter
that managed to get access to these
people's laptops, break in. Um, and
there's some interesting data out of
there. Um, they clearly just use a range
of identities that are either stolen or
completely made up. It's verified that
they've been using Upwork as a source of
income when revenue inflow is slow. Um,
and they have been using Gmail. Um,
which well better than Microsoft Teams.
So, we'll give them that as a taste uh
benefit. Anyway, uh, Zack Xbate is the
name of that Twitter person. Here's a
great example of it. As you can see,
they also come up with their own
nicknames. These people's identities are
very difficult to find out. Hence, Jane
Do. Uh, these are North Korean
officials, right? So, there is a
question how much that piece of paper
their identity is actually like. Yeah,
how they even go about that anyway.
And here's the question. Why is this a
thing? Well, um they are fundamentally
out there to create revenue for the
regime to fuel that weapons program that
they have. Um in general, the DPRK is a
major weapon supplier to all of their
friends. Um and so since the Russia
North Korea conflict happened, their
economy has also grown. This is a very
well-known thing. Uh, in fact, there was
a I think a Hungarian researcher that
managed to befriend the North Koreans uh
and traveled to North Korea to see one
of those arsenal showrooms for lack of
better words. Uh, there is a bunch of
research on that if you ever want to uh
get more info on that. I'll happily give
it to you. But like this is a thing. And
so what they're trying to achieve is
well plaid mercies in places. And you
may remember these two faces. These were
two frontline uh soldiers that were
captured by the Ukrainians uh in Russia.
Well, guess what they're trying to
achieve? They're trying to create hacker
mercenaries. Um, and they have many
tiers within this. We've all heard of
the like the Pegasus organization. There
are multiple organizations and this is
one of those movements. Okay. Now, the
real what's in it for them is even
simpler. The worst case scenario uh for
uh them really is that they can only
manage to get an US style wage out of
you which is about 150k USD. I asked
this question, what's your salary range?
it would be like a little bit below
market range to make it easy of a
decision, right? You'll be like, "Huh, I
can't understand them, but they're 20%
cheaper." Anyway, um so it's about 112K
British pounds. Uh to give you an idea,
the o like the average North Korean
worker in uh like North Korea itself
makes about $1,300
uh a year. So this is a lot of money for
them. Um they obviously get access to
valuable intellectual property. Some of
that is easily resold to their allies or
reused themselves. that is a valuable
asset to them. Um so they get that
salary plus that. Now if they can go
further than that they'll try to get
access to internal systems, plant
malicious npm dependencies, get access
to internal IT and do a bunch of weird
things. Now in fact there have been all
types of reports around this already
publicly that is a standardized thing.
They basically have a script that just
goes through whatever they can uh to
find stuff and then in the worst case
and this has happened a significant
amount of times uh they basically get
access to APIs that hold some kind of
funds. uh whether that's real human
currency or virtual currency crypto um
they just basically try to cash out as
fast as possible and then disappear.
Make no mistake, these are trained
nation state actors. The second they get
access, their training kicks in and it
moves super quickly and it is very
standardized. Now I mentioned the laptop
mules earlier. Um the laptop mules are
basically just people living in random
places in the Midwest. In fact, the
address that they put on the application
is often the one that they'll ask you to
send the laptop to as well. Um, so what
they do is they literally receive the
box, take the laptop. Uh, they take it
out of the box, go through setup, they
plug in a hardware IP KVM. Now, that's
kind of a new thing that came out in the
last few years that people have been
using. It's literally just HDMI, USB,
chuck it in over the network, shabbam.
Um, you can't see that they have remote
control software running on it. It's
just that, right? And you can get those
super cheap on Amazon now. uh which
probably is partly because of them. Um
anyway, then they open it in the morning
and they close laptop in the evening and
that is done, right? Um even some of
them do their taxes, which is funny
because that's how this individual
person was caught. A lady in Arizona um
became such good friends with the North
Koreans that she started filing their
tax paperwork. And during the raid uh
they found over what is it how many? I
think 90 laptops. Yeah. When you have a
living room like that, try claim you
don't know you're doing something
sketchy. Well, she did exactly that. Um,
so the defense, oh, the laptops just
showed up. I had no clue. I thought I
had a legit job. Um, but in the reality,
she was filing taxes for people uh to
have actual documentation to send in.
Uh, often under those false identities.
Uh, and she literally just had a laptop
room that looked like this. Now,
obviously, she was jailed uh for that.
And after that a further 90 of these
laptop farms were raided. Uh sorry yeah
no 29 of them were raided. Five arrests
were made and 200 laptops were seized.
So this was a rather big breakthrough.
[sighs]
Anyway, and that's when I linked up uh
with one of my journalist friends at
Wired and we put a whole article out and
it came out the same day. We kind of
timed it as another large company Kraken
in the crypto space uh to talk about it.
um because that way I wouldn't have a
red dot on my face when I walked out my
front door. Um but yes, the thing is
this is real. This is happening. Um
remote hiring has significant risks um
as we've all unfortunately came to learn
over the last few years. Um and it's
unfortunately not going away with AI.
These bad actors became way more
powerful, way more capable at bypassing
all of your usual tricks and questions.
Uh so you got to get creative. Um what
we do within the company is nobody gets
hired without having a coffee. meaning
meet them in person and if they start
like, "Oh, my grandmother died." Like
the the moment before, give them a
second chance. But there's probably
going to be a few uh like these agents
are never going to show up. Of course.
Anyway, I'm I'm leaving you with two
more things. Actually, I said one more
thing, but I couldn't help myself.
Interesting. Cool. All right. Um can you
tell me something about North Korea?
>> Actually, I have no idea. Okay. Can you
tell me something about Kimongun?
>> Okay. So then you wouldn't have a
problem with saying that Kimongun is a
dictator.
>> Can you say those words? There we go. H
we broke them. Y cool. We'll recap
somewhere else.
>> Yeah, that was the
>> journalist. There we go. Anyway, thank
you so much for your time. Um, we have
nice stickers for you. Uh, unparalleled
security standards. Uh, we are doing a
scavenger hunt as well. We have a van.
We're all the way at the end of the
event, like all the way at Null Sector.
Uh, and CSI is the sponsor of this
event. So, thank you so much for coming.
Thanks for making the best out of EMF.
[applause]