North Korean hacker got hired by US security vendor, immediately loaded malware
https://arstechnica.com/tech-policy/2024/07/us-security-firm-unwittingly-hired-apparent-nation-state-hacker-from-north-korea/
297 points · 16 comments · view on lemmy.world
16 Comments
Imhotep@lemmy.world · 41 pts · 2y
why not send an actual picture of his face?
Philippe23@lemmy.ca · 23 pts · 2y
My guess would be that they needed to get a mid-point between existing photos of the guy whose identity they stole and the guy that would show up in the video interviews.
boyi@lemmy.sdf.org · 6 pts · 2y
Very unlikely, If you read and refer to the article. The identity was stolen but the pic is a stock photo.
Philippe23@lemmy.ca · 3 pts · 2y
My thought on that is that they needed a new location so their image didn't just look like a modified version of another of the victim's public images, so NK searched for a stock photo for a professional looking location. Ars has just located the stock image they started from.
sugar_in_your_tea@sh.itjust.works · 1 pts · 2y
Why not just take a new one at a professional looking location in NK?
Randomgal@lemmy.ca · 2 pts · 2y
The last photographer starved to death and the guy who imported cameras got executed for not singing Kim's praises loud enough every morning.
independantiste@sh.itjust.works · 33 pts · 2y
This is the company that made "The Inside Man", a series where a company gets infiltrated by not being careful enough of who they hire
thurstylark@lemm.ee · 10 pts · 2y
Oh yeah, I remember having to watch those for onboarding. They weren't as cheesy as they could have been for an informational video.
I do appreciate how they're handling it, though. A public post-mortem is much more reassuring than damage control PR. Plus, being honest means they gain the IT folks who actually have to use their stuff as allies.
independantiste@sh.itjust.works · 4 pts · 2y
Yeah, the series is pretty entertaining actually. And for the PR thing, they pitched it as a learning incident, and I agree with that, but they are lucky nothing truly bad happened because this company sends phishing tests, and a link could be replaced by the attackers - kind of like in a fake fake phishing email.
SpicyLizards@reddthat.com · 15 pts · 2y
Way to break that hard earned trust guys
paridoxical@lemmy.world · 10 pts · 2y
They lost any trust when we learned they are a bunch of bat-shit scientologists.
jaybone@lemmy.world · 3 pts · 2y
North Korea?
piyuv@lemmy.world · 14 pts · 2y
So even if you do the work and do it well, you’re not allowed to spend your money how you see fit
sugar_in_your_tea@sh.itjust.works · 11 pts · 2y
I just wonder how many haven't been caught...
sharkfucker420@lemmy.ml · 8 pts · 2y
Based
ipkpjersi@lemmy.ml · 4 pts · 2y
How does that even happen lmao
Imhotep@lemmy.world · 1 pts · 2y