CyberzSOC

Publication detail
← Back to advisories & guidance

Democratic People's Republic of Korea Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue ↗ source

May 16, 2024 FBI Alert

Summary

Share on X X.com Share on Facebook Facebook Email Email The Federal Bureau of Investigation (FBI) is warning the public and private sector of the threat posed to U.S. businesses by information technology (IT) workers from the Democratic People's Republic of Korea (North Korea). North Korea is evading U.S. and U.N. sanctions by targeting private companies to illicitly generate substantial revenue for the regime. North Korean IT workers use a variety of techniques to obfuscate their identities, including leveraging U.S.-based individuals, both witting and unwitting, to gain fraudulent employment and access to U.S. company networks to generate this revenue. These witting and unwitting U.S.-based individuals provide a U.S.-based location for companies to send devices, enabling North Korean IT workers to circumvent controls companies may have in place to prevent the hiring of illicit, overseas workers as well as controls intended to prevent unauthorized access to company networks by North Korean IT workers, including through the unauthorized installation of remote access software. North Korean IT workers' activities illegally violate U.S. and U.N. sanctions and threaten the security of the targeted companies. Companies that outsource IT work support to third-party vendors can face additional vulnerabilities since these companies are removed from the direct hiring process.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.