We found North Korean engineers in our application pile. Here's what our ex-CIA co founders did about it.
2024-08-14 • Cinder •
https://www.cinder.co/blog-posts/north-korean-engineers-in-our-application-pile
Cinder reported repeated attempts by suspected North Korean IT workers to obtain remote software engineering roles at the company under false or fabricated identities. The applicants often used newly created professional profiles, AI-edited or obscured profile photos, fabricated job histories, weak supporting online footprints, scripted interview answers, and strong preferences for fully remote work without travel. The excerpt describes a known tradecraft pattern in which a worker may have a company laptop shipped to a US-based partner, who installs remote desktop software so the North Korean engineer can control it from abroad while appearing to work from a US location. Cinder frames the activity as revenue generation for the North Korean government, with potential sanctions and insider-risk implications for US technology companies.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2024-08-14 | 2024-08-14 | |
| DOMAIN | cndr.io | 2024-08-14 | 2024-08-14 |