started · updated
North Korean actors target developers and infiltrate agencies via remote work
North Korean state-sponsored actors are employing increasingly sophisticated methods to infiltrate organizations and fund the regime’s weapons programs. Security researchers at Proofpoint have identified a new cluster, dubbed ‘UNK_DeadDrop,’ which targets developers through phishing campaigns. These attacks use malicious Visual Studio Code extensions (VSIX) and GitHub repositories to deploy cross-platform malware across Windows, macOS, and Linux, specifically targeting assets like API tokens and cryptocurrency wallets.
Beyond technical exploits, North Korean operatives are utilizing remote work culture and artificial intelligence to impersonate foreign nationals. A joint statement from the United States and ten allies warned that these workers use identity theft and fraudulent banking to secure employment on global platforms. This strategy aims to bypass international sanctions and generate revenue for North Korea’s nuclear and ballistic missile programs.
In a notable instance of this infiltration strategy, the FBI is reportedly investigating how a North Korean national managed to secure remote employment with an unnamed U.S. federal agency. This case highlights vulnerabilities in the recruiting and identity verification processes used by government and private institutions.
Entities
FBI · North Korea · Proofpoint · United Nations · United States · Visual Studio Code
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The FBI is investigating how a North Korean national may have secured remote employment with an unnamed U.S. federal agency. www.it-boltwise.de
- [○ 1 SOURCE] The infection chain begins with emails containing links to attacker-controlled GitHub repositories. b2b-cyber-security.de
- [○ 1 SOURCE] Attackers are using malicious Visual Studio Extensions (VSIX) to execute cross-platform malware on macOS, Linux, and Windows. b2b-cyber-security.de
- [○ 1 SOURCE] Income earned by these covert workers is used to fund North Korea’s nuclear weapons and ballistic missile programs. editorials.voa.gov
- [○ 1 SOURCE] Proofpoint has identified a new threat actor cluster named ‘UNK_DeadDrop’ conducting phishing campaigns against developers. b2b-cyber-security.de
- [○ 1 SOURCE] The United States and ten allies issued a joint warning regarding North Korean IT workers using identity theft and AI to impersonate other nationals. editorials.voa.gov