Google warns North Korean spies are gaining positions in Western firms
- Google’s Threat Intelligence Group has identified more threats from the DPRK
- North Korean hackers pose as IT workers to get jobs in Western firms
- This brings a host of security threats for companies
A new report by Google’s Threat Intelligence Group has warned of an expansion of operations by the Democratic People’s Republic of Korea (North Korea).
The researchers claim an increasing number of Western firms accidentally hiring North Korean IT workers who are raising funds for the regime.
These workers pose a serious security threat to organizations, which are at risk of data theft, disruption, and espionage.
Extortion tactics
This is part of a much wider campaign from the DPRK which has seen state-sponsored threat actors infiltrate dozens of Fortune 100 companies, resulting in as much as $6.8 million in revenue earned for the DPRK.
This led to the US Justice Department arresting several US citizens who were running ‘laptop farms’ which house US equipment sent to new employees – the facilitators installed remote access technology allowing workers from the DPRK to log in.
Google also located facilitators in both the US and UK sharing equipment, indicating a “complex logistical chain”.
An investigation into the campaign’s infrastructure revealed a ‘heightened interest in Europe’, and a global expansion of tactics from the DPRK and an increased volume of extortion attempts.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The threat intelligence group identified cases where recently fired IT workers “threatened to release their former employers’ sensitive data or to provide it to a competitor” including proprietary data and source code for internal projects.
To combat this phenomenon, Google reports that many companies are operating a bring your own device policy , but these often lack traditional security and logging tools and make threat detection much more difficult, dramatically increasing a risk in undetected malicious activity.
“The increase in extortion campaigns coincided with heightened United States law enforcement actions against DPRK IT workers, including disruptions and indictments. This suggests a potential link, where pressure on these workers may be driving them to adopt more aggressive measures to maintain their revenue stream.
You might also like
Google’s Threat Intelligence Group has identified more threats from the DPRK North Korean hackers pose as IT workers to get jobs in Western firms This brings a host of security threats for companies A new report by Google’s Threat Intelligence Group has warned of an expansion of operations by the…
Recent Posts
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
- This HP Omen 16 deal with RTX 5050 graphics is a steal for video editing — and I can’t find it cheaper anywhere else
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023