Google warns North Korean spies are gaining positions in Western firms


- Google’s Threat Intelligence Group has identified more threats from the DPRK
- North Korean hackers pose as IT workers to get jobs in Western firms
- This brings a host of security threats for companies
A new report by Google’s Threat Intelligence Group has warned of an expansion of operations by the Democratic People’s Republic of Korea (North Korea).
The researchers claim an increasing number of Western firms accidentally hiring North Korean IT workers who are raising funds for the regime.
These workers pose a serious security threat to organizations, which are at risk of data theft, disruption, and espionage.
Extortion tactics
This is part of a much wider campaign from the DPRK which has seen state-sponsored threat actors infiltrate dozens of Fortune 100 companies, resulting in as much as $6.8 million in revenue earned for the DPRK.
This led to the US Justice Department arresting several US citizens who were running ‘laptop farms’ which house US equipment sent to new employees – the facilitators installed remote access technology allowing workers from the DPRK to log in.
Google also located facilitators in both the US and UK sharing equipment, indicating a “complex logistical chain”.
An investigation into the campaign’s infrastructure revealed a ‘heightened interest in Europe’, and a global expansion of tactics from the DPRK and an increased volume of extortion attempts.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The threat intelligence group identified cases where recently fired IT workers “threatened to release their former employers’ sensitive data or to provide it to a competitor” including proprietary data and source code for internal projects.
To combat this phenomenon, Google reports that many companies are operating a bring your own device policy , but these often lack traditional security and logging tools and make threat detection much more difficult, dramatically increasing a risk in undetected malicious activity.
“The increase in extortion campaigns coincided with heightened United States law enforcement actions against DPRK IT workers, including disruptions and indictments. This suggests a potential link, where pressure on these workers may be driving them to adopt more aggressive measures to maintain their revenue stream.
You might also like
Google’s Threat Intelligence Group has identified more threats from the DPRK North Korean hackers pose as IT workers to get jobs in Western firms This brings a host of security threats for companies A new report by Google’s Threat Intelligence Group has warned of an expansion of operations by the…
Recent Posts
- Google warns North Korean spies are gaining positions in Western firms
- Here’s how you can preorder the Nintendo Switch 2 (or try to)
- Sony’s Latest Bravia Home Theater Gear Gets Bolder, Brighter
- Thousands of PostgreSQL servers are being hijacked to mine crypto
- Nintendo goes in-depth on Switch 2 backward compatibility
Archives
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010