1 of 23

From Application to Access: �Detecting DPRK IT Workers Before They Become Insider Threats

Jesse Buonanno

2 of 23

whoami

  • Staff CTI Sec Eng @ Snowflake
  • Threat-Informed Defense Shill
  • Spent a few years in the blockchain space following DPRK Threat Actors
  • First time at BSides Seattle :D
  • https://securitydozo.com if you want to reach out

** Opinions expressed are my own and systems discussed do not necessarily reflect Snowflake infrastructure

3 of 23

The Threat | DPRK IT Workers

What the Industry is Seeing

  • Global targeting of remote roles across industries1

�Impact to Organizations

  • Shift to ransomware and extortion when caught
  • IP theft to technologically enrich the regime
  • Customer data theft for further exploitation

5 individuals aided DPRK Workers in targeting 136 U.S. companies, generating more than $2.2 million in revenue for the DPRK regime, and compromised the identities of more than 18 U.S. persons2

4 of 23

Partnering with Recruiting | Building Alliances

How security is going to help make their lives better!

  • Save them time by filtering out fraudulent candidates as they apply
  • Prevent honest mistakes - No one wants to be the one who hired the threat actor

Establish joint accountability - Owning the risk without input controls causes friction

Applicant Tracking System(ATS) Integrations (Pull & Push)

🚩 Red Flag Education

  • Refusal to go on camera
  • Significant delayed responses
  • Call center type environment - Lots of background voices
  • Absolute aversion to any on-site requests

5 of 23

The Hiring Lifecycle & Threat Modeling

Application

Techniques

– Deceptive Profiles

– Deceptive Resumes

– Disposable Emails

– VOIP Phone Numbers

– Residential Proxy / VPN / Tunneling

Offer

Techniques

– Deceptive Identities�Gov IDs / SSN / Etc.

– Fabricated References

– Fabricated Work History

Employment

Techniques

– VPN Installation

– RMM Usage

– Mouse Jigglers

– Data Exfiltration

– Potentially Sanctioned Bank Accounts

(Out of Scope)

Techniques

– Video Filters �(Deep Fakes)

– Voice Changers

Candidate Swapping

– Tool Assisted Knowledge Deception

Interviews

6 of 23

The Hiring Lifecycle & Threat Modeling | Cont.

Pre-Onboarding, The DPRK IT Worker Threat is A Killchain Problem

Interviews

Offer

Application

7 of 23

Preventative Controls (Active)

Composite Detections (Passive)

Threat-Informed Defense

8 of 23

Preventative Controls | Visual Continuity

Is it the same person seen in each interview? �Are they also the same person on government identification?

Recruiter/Hiring Manager Screen

Technical Interviews

Offer

Peer Interviews

9 of 23

Preventative Controls | Identity Verification(IDV)

10 of 23

Preventative Controls | Identity Verification(IDV) Cont.

Is it the same person seen in each interview? �Are they also the same person on government identification?

Offer

Interviews

Ask for Selfie and ID

Verify new information against initial baseline

SOP for interviewers to visually check candidate against the selfie

11 of 23

Preventative Controls | Response

Gov ID name doesn’t match name on resume?

** Programmatically notify assigned recruiter and hiring manager for final review **

Different person on interview than took selfie?

Gov ID Found to be digitally altered?

Virtual camera and Visual Filter used during selfie?

12 of 23

Preventative Controls (Active)

Composite Detections (Passive)

Threat-Informed Defense

13 of 23

Composite Detections | Overview

Collect – Telemetry from everything they touch

Enrich – Threat Intelligence Collections

Detect – Join the data and look for TTPs

Respond

  1. Tag/Label Fraudulent Candidate(s)
  2. Notify the hiring manager and/or recruiter

Application

Top of Funnel / First Touch Focus

14 of 23

Composite Detections | Collect

Hiring Lifecycle Telemetry Sources

  • ATS Logs for submitted application(s)
    • IPs, Resume, Socials, email, phone number, etc
  • Video Conferencing Logs
    • Email, IP
  • Collaborative Coding Environments
    • IP, Deception Heuristics
  • Electronic Signature Logs
    • IP, Browser Fingerprinting

The more logs you collect the greater chance�you’ll have at catching OPSEC slip-ups

Level of effort & complexity trade off for greater detection fidelity

15 of 23

Composite Detections | Enrich

  • IP Intelligence
    • GeoLocation, VPNs, Tunneled Traffic, Residential Proxies, Cloud Hosting, etc
  • Socials Media Profile Fingerprinting
    • LinkedIn1 – Barren account activity across connections, posts, and general activity
    • GitHub2 – Forged commit dates, name and contact info changes, skill word salad
  • Many CTI vendors are offering feeds of identified DPRK IT Workers (Full Persona Dumps)
    • Infostealers have broken quite a bit of their OPSEC
  • US Gov Public/Private Partnerships - DIB Cybersecurity Services3 provided by the NSA
  • Research has shown a strong correlation to True Negative candidates having emails tied to “everyday” services. E.g. A life outside of work4

16 of 23

Composite Detections | Big ol’ List of Detections

IP Address

  • Astrill VPN
  • Residential Proxy
  • High Risk Country
  • Cloud Hosting
  • Bulletproof Hosting

Phone Numbers

  • VOIP Number
  • High fraud and spam scores
  • A few Providers Abused…
    • Onvoy
    • Level 3
    • Telnyx

Email Address

  • “First Seen” / Fresh
  • In data breaches (True Neg)
  • Suspicious Pattern
    • `fname.lname.dev###@gmail.com`
  • Match against DPRK Threat Feeds
  • High fraud and spam score

Socials

  • Github Fingerprinting
  • LinkedIn Fingerprinting

Resume Analysis

  • Metadata Analysis
  • Resume differs from info on socials

Anomaly Detection

  • Same email tied to >= 2 sufficiently different names
  • One phone number shared between >=3 candidates
    • Semantic name dedupe via LLM
  • High deception in technical interview

HUMINT

  1. Recruiter finds 🚩
  2. Labels/Tags in ATS
  3. Webhook picks up the tag
  4. Backpropagate all of that candidate’s telemetry for matches against other candidates (OPSEC slip-ups)

17 of 23

Composite Detections | Example Detector Scoring

+1 Known suspicious email pattern�+2 VOIP Phone number with high fraud score�+5 Same email used on >1 profiles with sufficiently different names�-5 Email found in Drizzly, AT&T, and Adobe breaches+3 IP associated with known residential proxy�+5 Github attributed to DPRK campaign by DPRK Threat Feed�+1 LinkedIn social graph and activity shows no activity and odd connections�+1 Email never before seen by fraud provider

18 of 23

Composite Detections | Meet Bryant Dang

19 of 23

Composite Detections | Meet Bryant Dang cont.

16 Score well above threshold to auto-reject

Indicator

Detections

Result

Score

Email�bryantdang1018@outlook.com

  1. Breach Check
  2. Email Pattern
  3. Fraud Check
  4. First Time Seen
  5. Anomaly Detection
  1. No Breaches
  2. fname.lastname### Pattern
  3. Scored 80/100 by provider
  4. TRUE - First time seen by provider
  5. None

+5

Phone Number (Redacted)�(214) 377-XXXX

  1. Fraud Check
  2. VOIP
  3. Anomaly Detection
  1. Scored 85/100 by provider
  2. TRUE - ONVOY, LLC
  3. 4 other suspicious candidates

+6

IP Address�65.87.9.177

IP Intelligence Enrichment Results

Datacenter origin / Tunneled Traffic / True client origin is from Indonesia, Philippines and Malaysia

+4

LinkedIn�/in/brdang/

LinkedIn Fingerprinting

No profile picture, no activity, low connections

+1

20 of 23

Composite Detections | Response

  1. Hit ATS API to see if candidate has been hired
    • If yes - Notify IR or Insider Threat Team to kickoff investigation playbook
  2. Label/Tag candidate profile in ATS system
  3. 🤞ATS has platform native way to add plain language notes to the candidate profile detailing the suspicious behavior detected
  4. Notify assigned recruiter and/or hiring manager
  5. Rejection - Personalize to your needs and where in the life cycle you are
    • Auto Reject - *Optional* based on risk tolerance and severity confidence
    • Have SOP for risk owner to make human in the loop final decision
      1. This is going to be difficult at scale
    • Store telemetry from candidate for future detections

21 of 23

End Suite of Mitigating Controls

Application

Composite Detections

🔎 Top of funnel detection suite

🔖Label and Notify

🙅Auto-reject

✅Save recruiting review hours AND mitigate risk

Offer

Identity Verification

🕵️‍♀️Background Check ==

🪪Government ID ==

🤳Visual Continuity

Composite Detections

🔏E-Signature Telemetry

Identity Verification

🪪ID Fraud Detection

🤳Visual Continuity

Composite Detections

👨‍💻 Deceptive Technical Interview Detections

👨‍💻Video Conferencing Telemetry

Interviews

22 of 23

Vendors Operating in the Space – Do your own Due Diligence

Top of Funnel Detections

Specialized in Fraud Detection

  • Tofu
  • Endorsed

Native ATS Controls

  • Greenhouse – Real TalentTM
    • CLEAR Backend
  • Ashby – Fraud Detection
  • Lever – Candidate Insights

Identity Verification

  • FirstAdvantage
    • ID.me backend
  • CLEAR
  • WithPersona
  • Incode

* Some integrate with your ATS

23 of 23

Link to the Deck