From Application to Access: �Detecting DPRK IT Workers Before They Become Insider Threats
Jesse Buonanno
whoami
** Opinions expressed are my own and systems discussed do not necessarily reflect Snowflake infrastructure
The Threat | DPRK IT Workers
What the Industry is Seeing
�Impact to Organizations
5 individuals aided DPRK Workers in targeting 136 U.S. companies, generating more than $2.2 million in revenue for the DPRK regime, and compromised the identities of more than 18 U.S. persons2
Partnering with Recruiting | Building Alliances
How security is going to help make their lives better!
Establish joint accountability - Owning the risk without input controls causes friction
Applicant Tracking System(ATS) Integrations (Pull & Push)
🚩 Red Flag Education
The Hiring Lifecycle & Threat Modeling
Application
Techniques
– Deceptive Profiles
– Deceptive Resumes
– Disposable Emails
– VOIP Phone Numbers
– Residential Proxy / VPN / Tunneling
Offer
Techniques
– Deceptive Identities�Gov IDs / SSN / Etc.
– Fabricated References
– Fabricated Work History
Employment
Techniques
– VPN Installation
– RMM Usage
– Mouse Jigglers
– Data Exfiltration
– Potentially Sanctioned Bank Accounts
(Out of Scope)
Techniques
– Video Filters �(Deep Fakes)
– Voice Changers
– Candidate Swapping
– Tool Assisted Knowledge Deception
Interviews
The Hiring Lifecycle & Threat Modeling | Cont.
Pre-Onboarding, The DPRK IT Worker Threat is A Killchain Problem
Interviews
Offer
Application
Preventative Controls (Active)
Composite Detections (Passive)
Threat-Informed Defense
Preventative Controls | Visual Continuity
Is it the same person seen in each interview? �Are they also the same person on government identification?
Recruiter/Hiring Manager Screen
Technical Interviews
Offer
Peer Interviews
Preventative Controls | Identity Verification(IDV)
Preventative Controls | Identity Verification(IDV) Cont.
Is it the same person seen in each interview? �Are they also the same person on government identification?
Offer
Interviews
The FBI also recommends this → https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-worker-threats-to-u-s-businesses
Ask for Selfie and ID
Verify new information against initial baseline
SOP for interviewers to visually check candidate against the selfie
Preventative Controls | Response
Gov ID name doesn’t match name on resume?
** Programmatically notify assigned recruiter and hiring manager for final review **
Different person on interview than took selfie?
Gov ID Found to be digitally altered?
Virtual camera and Visual Filter used during selfie?
Preventative Controls (Active)
Composite Detections (Passive)
Threat-Informed Defense
Composite Detections | Overview
Collect – Telemetry from everything they touch
Enrich – Threat Intelligence Collections
Detect – Join the data and look for TTPs
Respond
Application
Top of Funnel / First Touch Focus
Composite Detections | Collect
Hiring Lifecycle Telemetry Sources
The more logs you collect the greater chance�you’ll have at catching OPSEC slip-ups
Level of effort & complexity trade off for greater detection fidelity
Composite Detections | Enrich
[1] https://nisos.com/research/dprk-github-employment-fraud/
[2] https://www.okta.com/blog/threat-intelligence/the-north-korean-on-your-payroll
[3] https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/�[4] https://hiretofu.com/blog/the-humanness-signal-why-it-might-be-one-of-the-best-indicator-in-resume-fraud-detection
Composite Detections | Big ol’ List of Detections
IP Address
Phone Numbers
Email Address
Socials
Resume Analysis
Anomaly Detection
HUMINT
Composite Detections | Example Detector Scoring
+1 Known suspicious email pattern�+2 VOIP Phone number with high fraud score�+5 Same email used on >1 profiles with sufficiently different names�-5 Email found in Drizzly, AT&T, and Adobe breaches�+3 IP associated with known residential proxy�+5 Github attributed to DPRK campaign by DPRK Threat Feed�+1 LinkedIn social graph and activity shows no activity and odd connections�+1 Email never before seen by fraud provider
Composite Detections | Meet Bryant Dang
Composite Detections | Meet Bryant Dang cont.
❌ 16 Score well above threshold to auto-reject�
Indicator | Detections | Result | Score |
Email�bryantdang1018@outlook.com |
|
| +5 |
Phone Number (Redacted)�(214) 377-XXXX |
|
| +6 |
IP Address�65.87.9.177 | IP Intelligence Enrichment Results | Datacenter origin / Tunneled Traffic / True client origin is from Indonesia, Philippines and Malaysia | +4 |
LinkedIn�/in/brdang/ | LinkedIn Fingerprinting | No profile picture, no activity, low connections | +1 |
Composite Detections | Response
End Suite of Mitigating Controls
Application
Composite Detections
🔎 Top of funnel detection suite
🔖Label and Notify
🙅Auto-reject
✅Save recruiting review hours AND mitigate risk
Offer
Identity Verification
🕵️♀️Background Check ==
🪪Government ID ==
🤳Visual Continuity
Composite Detections
🔏E-Signature Telemetry
Identity Verification
🪪ID Fraud Detection
🤳Visual Continuity
Composite Detections
👨💻 Deceptive Technical Interview Detections
👨💻Video Conferencing Telemetry
Interviews
Vendors Operating in the Space – Do your own Due Diligence
Top of Funnel Detections
Specialized in Fraud Detection
Native ATS Controls
Identity Verification
* Some integrate with your ATS
Link to the Deck
Also on https://securitydozo.com