Submind YouTube summaries
Thumbnail for North Korean agent looking for a job - EMF 2026

North Korean agent looking for a job - EMF 2026

Watch on YouTube

Video summary

The speaker, Simon, founder of a cybersecurity company called Seaside, explains how his organization discovered a sophisticated campaign involving North Korean state actors attempting to infiltrate the global workforce through remote job applications. Initially appearing as legitimate candidates with impressive backgrounds and high scores on coding assessments, these applicants exhibited numerous red flags upon deeper investigation. Simon noticed significant network latency, the use of AstralVPN—a service known for bypassing China's Great Firewall—and browser artifacts indicating a virtual machine environment rather than a genuine home setup. Furthermore, linguistic analysis revealed that despite claiming to be native English speakers, their speech patterns were inconsistent, and their responses to technical questions about networking protocols like BGP were nonsensical, suggesting they were relying on AI tools or pre-written scripts rather than actual knowledge. The investigation uncovered that these individuals were part of an organized operation where North Korean officials are sent abroad in groups to work as "hacker mercenaries" to generate revenue for the regime's weapons programs. To bypass standard identity verification processes, many applicants used fake identities, stolen credentials, or even projected images of ID cards onto green screens during video calls. The speaker highlighted a critical failure point in the hiring process: background check vendors often flagged these applications as suspicious but ultimately approved them due to the high cost and liability associated with false positives. Consequently, bad actors slipped through the cracks, eventually receiving laptops shipped to addresses in countries like the US, UK, and Switzerland, which they would then operate remotely, sometimes even filing taxes under false names to legitimize their presence. The scale of this operation became evident when authorities raided a "laptop farm" in Arizona, seizing over 90 devices and arresting individuals who had unknowingly become part of the supply chain by filing tax returns for these foreign entities. These raids revealed that North Korean agents were utilizing hardware IP KVMs to remotely control computers from their home countries while physically sitting in apartments abroad, effectively turning unsuspecting locals into mules. The financial incentive for these actors is substantial; while a typical worker in North Korea earns roughly $1,300 annually, the remote jobs offered salaries around £112,000, providing access to valuable intellectual property and cryptocurrency funds that they would quickly cash out before disappearing. Once inside a target system, their training allows them to move rapidly through defenses, plant malicious dependencies, and exfiltrate data or funds with standardized efficiency. In conclusion, the video serves as a stark warning about the evolving risks of remote hiring in an era where AI tools have empowered state-sponsored bad actors to bypass traditional security measures more effectively than ever before. The speaker emphasizes that digital footprints, such as non-standard fonts, unusual network behavior, and metadata inconsistencies, can reveal the true origin of an applicant, but these signals are often overlooked by automated systems under pressure. To mitigate these threats, the company adopts a policy of never hiring anyone without meeting them in person first, acknowledging that some agents will simply not show up for interviews. The overarching message is that while technology like AI makes deception easier for adversaries, human verification and creative investigative techniques remain essential to identifying and stopping nation-state actors from infiltrating critical infrastructure and stealing valuable assets.
Read the full video transcript
WOO! >> EMF camp, how are we doing? Come on. No. [screaming] >> Perfect. Awesome. Okay, cool. Uh, slight change of tone coming in. Hi, everybody. Um as much as we are fun, flimsy and look to be quite like hilarious, uh do not do what we are going to discuss in this uh like session today at home, uh we are security researchers. We have done this research together with international law enforcement uh and also with international crime reporters. So we had support and backing throughout this entire journey. Do not just start doing things with North Koreans. You might be putting yourself in danger. Anyway, speaking about putting yourself in danger, in the back is my intern right there while I'm driving a van. Um, I'm Simon. I'm the founder and CEO of Seaside. Um, I'm a starter founder. Uh, like there are many, that's not special. Um, I am the chair of the uh, anti-fraud division of the W3C, which is a small community group. Um, I run a small cyber security company um, around web security. Um, and kind of the starting story is very simple. I realized that firewall vendors were claiming to know things about browsers when unfortunately they didn't. and there wasn't really enough of a browser level security company in the world. Um, anyway, I'm originally from Belgium. Um, I used to live here in the UK. Um, but since a little while now, I've been based in San Francisco. All right. So, what do you do when you start a startup? You do fundraising. And as is always the case with fundraising, there is of course mandatory press coverage that comes as part of that. And what do you do when you get given money? You have to deploy that money and hire people to go build that thing, build that vision. So, I put a bunch of jobs online. I used a very well-known applicant tracking system that then posted that job on various platforms. Um, LinkedIn, Indeed, X jobs, that's a thing nowadays. Uh, bunch of those platforms. And then, of course, our investors were nice and reposted that on their platforms and kind of bit expected. Um, there were quite some press articles out there. People were somewhat interested in what we were doing and there you go. We started getting job applicants in tool. We received thousands. Now, how do you go to um like sorry, I'm going to start there. On paper, all these candidates looks great. They had very relevant backgrounds, worked at the right companies before. Um they had an active GitHub account. It just made sense. So, these profiles were almost too good to be true. Um and then how do you sift through so many of these applications? Well, you start filtering for the best ones and then you send them a homework assessment. do a coding assessment, fill out this Q&A, um, let's do this personality assessment to understand how you are. And then that only should really only take you an hour or so. And then here's what came back. Flying colors. People got 94%. There were some signs of cheating, which is tolerable. Um, they slashed it 10 out of 10 out of 10 out of everything. And somehow they were also interested in learning speltic, which is not that unpopular. Um, now then another candidate. Here's another one. Similar thing, 92%. However, our React weather app was a bit too much to ask. [sighs] Well, what do you do with candidates like this? Well, you have a call, right? And they were a little awkward. I'll let you judge. Um, so in this question that's going to come up now, like in the response I'm going to give, I asked about the border gateway protocol. The reason why I asked that is because when you ask people how does it work to get a web page in a browser? Well, networking is part of that. They often forget it and I ask and kind of what I'm hoping to get here is people saying I don't know and asking questions or either giving me a perfect answer and then we'll dig deeper. The border gateway protocol is the thing that makes the internet route. I have a server in LA that I need to reach. How do I get there? Right? That's what the BGP uh like BGP does. This is going to hurt your brain. It did to me as well. And I had to sit through the whole thing. I'm not going to have you do that. But here we go. >> Uh actually the regarding this world protocol, it just uh it just combination of the uh operator of the border. So uh actually uh the potential context where the uh term might apply in this kind of the uh in this kind of policy then uh the border management and then also the um political um commentary is really important is important. >> Needless to say none of this made any sense. Um and so if you think that was bad uh I kind of doubled down and I asked it's quite high level. Can you just be more precise? I really just want to hear about the networking side of things. >> Um well actually this is just what I told you is just what I provide you is just a um big picture of the uh options for each u management and then also maybe the uh policies. So uh maybe if I can give you some kind of the examples then uh for example uh the agencies like the um like the government and then also border protection or the maybe organizations and other countries uh then it is just they're just responsible for >> so this guy was talking about border protection. Um so clearly border gateway protocol using his AI tool um meant border enforcement the physical people at the airport um asking you if you brought any chocolate from abroad. Anyway um what did you notice? Well, a few initial signs, right? And if you start having a bunch of these calls, they're quite clear signs. Uh there's really significant lag. He claimed to be a native English speaker. Now I really don't want to be go using that too much as a vector, but was he? It didn't really sound like that. Um, and honestly, nothing he said made any sense. Now, this particular recording was made in 2024 before AI got good nowadays, he would probably give you a better answer. Um, but as I said at the end of that thing, I wasn't going to have you sit through that whole thing. At the end, I say, let's move on, which is like the line, if any interviewer ever says, let's move on, you know, you're basically screwed. You've been caught bullshitting. Anyway, uh, this was another one of those candidates. I found this one particularly funny because um in his glasses you can see that he was getting some let's put it external help. Um anyway um and then well every good employer needs to know who they're talking to and if you're trying to be sock 2 compliant which pretty much every B2B company needs to do you have to do u background checks. So we use a platform that does identity verification for us criminal record checks tax evasion employment educational social media blah blah blah blah blah a bunch of checks very standard stuff. Now, here's what that platform returned. All bueno, nothing to worry about. Uh, pretty weird. Now, what I found particularly interesting was the fact, and you can see that here, there's a Gmail address. So, they were sending a Gmail um employment verification emails, which is not fully like illegal or weird, but using an Gmail means they can just create an email address for someone. Um, so I got a little bit weirded out by that and I reached out to this person on LinkedIn. I said, "Hey, uh, what's up?" Like, "Do you know this guy?" The answer was, "No." I'm on to something. So then I checked the identity card. Now, I can show you this because it's fake. Um, as you can see, uh, it looks a little bit way out of like it looks too perfect of a picture, doesn't it? Um there's a number of indicators here that there's an issue with this but honestly the technology to make fake identity cards got better since as well um this past identity verification initially. Now then we dug deeper. I reached out to this identity verification platform and we actually became good friends throughout this process. Um and uh it turned out that their systems did flag this as a weird application. um there were all types of issues and they called this person into a zoom call asking to show that uh identity card. Now what this person is using is a green screen card like any hotel PVC key cards you can get these in green and he was using computer vision to project these ID cards on there. Now this was detected they immediately spotted that this was not normal. However, identity verification is usually done by a bunch of people in like low-wage countries. Um, and they're under insane pressure. So, what happened here was the cost of a false positive is so high, these people don't want to bear the responsibility for it. If a company is trying to recruit someone and all the way at the end of the process, it comes back as this is not legit. You may want to verify further. That slows down the recruiting process and it's just generally not worth it for them. So, they gave it stamp of approval and a bad actor got away with it. So that shows identity verification unfortunately isn't all it. And there were so many of these guys. Um we started giving them Jane do numbers. So on the bottom right is Jane do 26. Jane do 26 and I we go way back. Um it's actually uh quite a warm relationship. We have emojis made out of his face because he's got a very expressive uh face. Um there's some like uh memes about that that I also post on Twitter every now and then. Anyway, but Jane do is also known for his um impeccable um reports on Upwork. So, these people are actively doing other things in other places as well. Upwork being one of those platforms. I'll get back to that in a bit. Okay, so now they got me annoyed. There's clearly some really organized campaign happening out there with a bunch of honestly nation state actors trying to get into companies. And then I remembered the [ __ ] I'm running this company like we can do this like we can do browser forensics and probably we can pull a bunch of data out of that. So the first thing that I did was make a job application portal where if they pressed the button to start the application process some fun stuff would happen. You may want to lower the audio ever so slightly on my laptop in a second because it does get quite loud but dramatic effect. Here we go. You can buff it for a more dramatic effect, I think. Yeah. Yeah. So, it um I actually did it I called one of my friends who made this open source a while ago. Um I wasn't going to spend my company money and time on it. Um but yeah, when you moved your mouse, the window would move as well. And when you were unlucky to then click on it, it would open more windows and it would put things in your downloads folder. It would mess with your clipboards, call all types of legacy APIs to do weird [ __ ] in your browsers. open a cat because why not? Um yeah, that was my first response and then well then by the way if you want to check this out interview LTD do not send it to your friends or colleagues. Um and then I thought okay let's behave let's actually take this thing seriously. So uh we got some data out of these guys' browsers. We sent them a little thing to hey can you please confirm your job application here? And then we have this fancy dashboard in our product. Uh it's not a marketing pitch but you get it. We gather a bunch of data about these people and then kind of the dimensions that we look at it is the user, the browser, the device, the network. Now, I'll start with the network. The network hella high latency. Woohoo. Like you could go out and like get yourself a little cup of tea set up by the time the web page loaded. Um, they were also using the mother of all signals, AstralVPN. Has anybody here heard of AspilVPN? AstralVPN is one of the only VPN providers that works from inside the great firewall in China. Uh which is usually an indicator that there's some fishy stuff happening. Um now when it comes to the browser/ the device, well it was a Windows virtual machine. Um very clearly a virtual machine and it had some non-standard range fonts on them. For example, Shiona by all means look it up. Um that's kind of a a very common Korean but towards a North Korean dialect font. Um, they're usually not dumb enough to use Red Star OS, but it does happen. Um, so yeah, there we go. To those of you that don't know, Red Star OS is a kind of an old Linux-based operating system that they use in the DPRK. Anyway, um, browser signals. Um, the other thing that we noticed is there was a really significant amount of latency between the rendering of the page and them actually doing something. So usually when you go through a form for example, you would do a thing and something else would come up and then you'd respond to that and then there you go. And another clear one is when you type something usually it comes in relatively consistently with some level of like movement between it. If you have a bad network connection with a lot of latency then usually comes in in a freaking chunk like right and you've observed that there. So it was very clear um that like that was not a normal somebody sitting behind their computer doing their work thing. the homework assessments as well. These tools that we use for these homework assessments, they provide you with like 800 or a,000 or 5,000 or so different questions you can ask your candidates, but they are standardized. So these people have made their own standardized library of answers on their side and just copy paste them in. Um, so that's all very standardized and clean on their end. And then of course nowadays, and this is more of like a last year thing, um, more and more AI automations using browser use. So actually using the browser and doing mouse movements and stuff and and basically filling out an assessment um I must say a little bit faster than is reasonable. Uh so you can still have it as a thing. Now here comes our fun secret sauce. We were able to locate some of these people. Um so neighboring countries of uh like North Korea, you'll find a few cities like Dan Dong uh but also Shenyang, Yanji um and uh there's another one Vanji anyway. and then also in Russia, a neighboring city there. Now, uh then also spreads to other countries like Laos, uh which is a beautiful between Vietnam and um Thailand. Beautiful place to go, but I can never um and then uh North America uh and like London and and Switzerland and and like numerous places they were acting as if they were there. That being said, it was all quite obvious. Okay, now this is where kind of the deeper research uh that we did with agencies came in. What we know about how these actors work to become a North Korean official and be able to leave the country, you have to really climb the ranks. And so what happens is they sent these people out in groups of eight, usually to two or threebedroom apartments. Um basically making them into a sweat shop and kind of forcing them to work as hard as they possibly can and bring back as much as re revenue as possible. they know their family is being watched and if they do anything out of line that is their family on the line. Um they have some standardized process. So for example the identity verification program that I explained they definitely have an internal handbook on how to do that. Um and they get very organized at like bypassing these tools because there is just so many of them. But they do have their own freedom when they're kind of little club on how to do things. Um they rarely I would say do things outside of the US because of the logistics of it. and I'll talk about that as well. Um, they have laptop mules, but most of them are in the US. Um, if they are hired within any of these other countries, then they're very likely make up some story and ask you to send the laptop to the US anyway. Um, and actually, this is a fun one. I'm not going to claim any credit for this. There's a bunch of people on Twitter that managed to get access to these people's laptops, break in. Um, and there's some interesting data out of there. Um, they clearly just use a range of identities that are either stolen or completely made up. It's verified that they've been using Upwork as a source of income when revenue inflow is slow. Um, and they have been using Gmail. Um, which well better than Microsoft Teams. So, we'll give them that as a taste uh benefit. Anyway, uh, Zack Xbate is the name of that Twitter person. Here's a great example of it. As you can see, they also come up with their own nicknames. These people's identities are very difficult to find out. Hence, Jane Do. Uh, these are North Korean officials, right? So, there is a question how much that piece of paper their identity is actually like. Yeah, how they even go about that anyway. And here's the question. Why is this a thing? Well, um they are fundamentally out there to create revenue for the regime to fuel that weapons program that they have. Um in general, the DPRK is a major weapon supplier to all of their friends. Um and so since the Russia North Korea conflict happened, their economy has also grown. This is a very well-known thing. Uh, in fact, there was a I think a Hungarian researcher that managed to befriend the North Koreans uh and traveled to North Korea to see one of those arsenal showrooms for lack of better words. Uh, there is a bunch of research on that if you ever want to uh get more info on that. I'll happily give it to you. But like this is a thing. And so what they're trying to achieve is well plaid mercies in places. And you may remember these two faces. These were two frontline uh soldiers that were captured by the Ukrainians uh in Russia. Well, guess what they're trying to achieve? They're trying to create hacker mercenaries. Um, and they have many tiers within this. We've all heard of the like the Pegasus organization. There are multiple organizations and this is one of those movements. Okay. Now, the real what's in it for them is even simpler. The worst case scenario uh for uh them really is that they can only manage to get an US style wage out of you which is about 150k USD. I asked this question, what's your salary range? it would be like a little bit below market range to make it easy of a decision, right? You'll be like, "Huh, I can't understand them, but they're 20% cheaper." Anyway, um so it's about 112K British pounds. Uh to give you an idea, the o like the average North Korean worker in uh like North Korea itself makes about $1,300 uh a year. So this is a lot of money for them. Um they obviously get access to valuable intellectual property. Some of that is easily resold to their allies or reused themselves. that is a valuable asset to them. Um so they get that salary plus that. Now if they can go further than that they'll try to get access to internal systems, plant malicious npm dependencies, get access to internal IT and do a bunch of weird things. Now in fact there have been all types of reports around this already publicly that is a standardized thing. They basically have a script that just goes through whatever they can uh to find stuff and then in the worst case and this has happened a significant amount of times uh they basically get access to APIs that hold some kind of funds. uh whether that's real human currency or virtual currency crypto um they just basically try to cash out as fast as possible and then disappear. Make no mistake, these are trained nation state actors. The second they get access, their training kicks in and it moves super quickly and it is very standardized. Now I mentioned the laptop mules earlier. Um the laptop mules are basically just people living in random places in the Midwest. In fact, the address that they put on the application is often the one that they'll ask you to send the laptop to as well. Um, so what they do is they literally receive the box, take the laptop. Uh, they take it out of the box, go through setup, they plug in a hardware IP KVM. Now, that's kind of a new thing that came out in the last few years that people have been using. It's literally just HDMI, USB, chuck it in over the network, shabbam. Um, you can't see that they have remote control software running on it. It's just that, right? And you can get those super cheap on Amazon now. uh which probably is partly because of them. Um anyway, then they open it in the morning and they close laptop in the evening and that is done, right? Um even some of them do their taxes, which is funny because that's how this individual person was caught. A lady in Arizona um became such good friends with the North Koreans that she started filing their tax paperwork. And during the raid uh they found over what is it how many? I think 90 laptops. Yeah. When you have a living room like that, try claim you don't know you're doing something sketchy. Well, she did exactly that. Um, so the defense, oh, the laptops just showed up. I had no clue. I thought I had a legit job. Um, but in the reality, she was filing taxes for people uh to have actual documentation to send in. Uh, often under those false identities. Uh, and she literally just had a laptop room that looked like this. Now, obviously, she was jailed uh for that. And after that a further 90 of these laptop farms were raided. Uh sorry yeah no 29 of them were raided. Five arrests were made and 200 laptops were seized. So this was a rather big breakthrough. [sighs] Anyway, and that's when I linked up uh with one of my journalist friends at Wired and we put a whole article out and it came out the same day. We kind of timed it as another large company Kraken in the crypto space uh to talk about it. um because that way I wouldn't have a red dot on my face when I walked out my front door. Um but yes, the thing is this is real. This is happening. Um remote hiring has significant risks um as we've all unfortunately came to learn over the last few years. Um and it's unfortunately not going away with AI. These bad actors became way more powerful, way more capable at bypassing all of your usual tricks and questions. Uh so you got to get creative. Um what we do within the company is nobody gets hired without having a coffee. meaning meet them in person and if they start like, "Oh, my grandmother died." Like the the moment before, give them a second chance. But there's probably going to be a few uh like these agents are never going to show up. Of course. Anyway, I'm I'm leaving you with two more things. Actually, I said one more thing, but I couldn't help myself. Interesting. Cool. All right. Um can you tell me something about North Korea? >> Actually, I have no idea. Okay. Can you tell me something about Kimongun? >> Okay. So then you wouldn't have a problem with saying that Kimongun is a dictator. >> Can you say those words? There we go. H we broke them. Y cool. We'll recap somewhere else. >> Yeah, that was the >> journalist. There we go. Anyway, thank you so much for your time. Um, we have nice stickers for you. Uh, unparalleled security standards. Uh, we are doing a scavenger hunt as well. We have a van. We're all the way at the end of the event, like all the way at Null Sector. Uh, and CSI is the sponsor of this event. So, thank you so much for coming. Thanks for making the best out of EMF. [applause]