LONDON: Using fake names, sham LinkedIn profiles, counterfeit work papers and mock interview scripts, North Korean IT workers seeking employment in Western tech companies are deploying sophisticated subterfuge to get hired.
Landing a job outside North Korea to secretly earn hard currency for the isolated country demands highly-developed strategies to convince Western hiring managers, according to documents reviewed by Reuters, an interview with a former North Korean IT worker and cybersecurity researchers.
North Korea has dispatched thousands of IT workers overseas, an effort that has accelerated in the last four years, to bring in millions to finance Pyongyang's nuclear missile programme, according to the United States, South Korea, and the United Nations.
"People are free to express ideas and opinions," reads one interview script used by North Korean software developers that offers suggestions for how to describe a "good corporate culture" when asked. Expressing one's thoughts freely could be met with imprisonment in North Korea.
The scripts totalling 30 pages, were unearthed by researchers at Palo Alto Networks, a U.S. cybersecurity firm which discovered a cache of internal documents online that detail the workings of North Korea's remote IT workforce.
The documents contain dozens of fraudulent resumes, online profiles, interview notes, and forged identities that North Korean workers used to apply for jobs in software development.
Reuters found further evidence in leaked darkweb data that revealed some of the tools and techniques used by North Korean workers to convince firms to employ them in jobs as far afield as Chile, New Zealand, the United States, Uzbekistan and the United Arab Emirates.
The documents and data reveal the intense effort and subterfuge undertaken by North Korean authorities to ensure the success of a scheme that has become a vital lifeline of foreign currency for the cash-strapped regime.
North Korea's U.N. mission did not respond to a request for comment.
Remote IT workers can earn more than ten times what a conventional North Korean labourer working overseas in construction or other manual jobs earns, the U.S. Justice Department (DOJ) said in 2022, and teams of them can collectively earn more than $3 million a year.
Reuters was not able to determine how much the scheme has generated over the years.
Some of the scripts, designed to prepare the workers for interview questions, contain excuses for the need to work remotely.
"Richard", a senior embedded software developer, said "I (flew) to Singapore several weeks ago. My parents got Covid and I (decided) to be with family members for a while. Now, I am planning to go back to Los Angeles in three months. I am thinking that I could start work remotely right now, then I will be on board when I go back to LA."
A North Korean IT worker who recently defected also examined the documents and confirmed their authenticity to Reuters: "We would create 20 to 50 fake profiles a year until we were hired," he said.
He viewed the scripts, data and documents and said it was exactly the same thing he had been doing because he recognised the tactics and techniques used.
"Once I was hired, I would create another fake profile to get a second job," said the worker, who spoke on condition of anonymity, citing security concerns.
In October, the DOJ and Federal Bureau of Investigation (FBI) seized 17 website domains it said were used by North Korean IT workers to defraud businesses and $1.5 million in funds.
North Korean developers working at U.S. companies had hidden behind pseudonymous email and social media accounts and generated millions of dollars a year on behalf of sanctioned North Korean entities through the scheme, the DOJ said.
"There is a risk to the North Korea government, as these privileged workers are exposed to dangerous realities about the world and their country's enforced backwardness," said Sokeel Park of Liberty in North Korea (LINK), an organisation that works with defectors.
HARD CASH
Last year, the U.S. government said North Korean IT workers were mainly located in China and Russia, with some in Africa and Southeast Asia, and can each earn up to $300,000 annually.
According to his experience, the former IT worker said all are expected to earn at least $100,000, of which 30-40% is repatriated to Pyongyang, 30-60% spent on overhead expenses, and 10-30% pocketed by workers.
He estimated there were around 3,000 others like him overseas, and another 1,000 based within North Korea.
"I worked to earn foreign currency," he told Reuters. "It differs between people but, basically, once you get a remote job you can work for as little as six months, or as long as three to four years."
"When you can't find a job, you freelance."
The researchers, part of Palo Alto's Unit 42 cyber research division, made the discovery when examining a campaign by North Korean hackers that targeted software developers.
One of the hackers left the documents exposed on a server, Unit 42 said, indicating there are links between North Korea's hackers and its IT workers, although the defector said espionage campaigns were for a select few: "Hackers are trained separately. Those missions are not given to people like us," he said.
Still, there is crossover. The DOJ and FBI have warned that North Korean IT workers may use access to hack their employers, and some of the leaked resumes indicated experience at cryptocurrency firms, an industry that has been long-targeted by North Korean hackers.
FAKE IDENTITIES
Data from Constella Intelligence, an identity investigation firm, showed that one of the workers had accounts at over 20 freelancing websites in the United States, Britain, Japan, Uzbekistan, Spain, Australia and New Zealand.
The worker did not respond to an emailed request for comment.
The data, collated from leaks on the darkweb, also revealed an account on a website selling digital templates to create realistic-looking fake identification documents, including U.S. driving licences, visas and passports, Reuters found.
The documents unearthed by Unit 42 included resumes for 14 identities, a forged U.S. green card, interview scripts, and evidence that some workers had bought access to legitimate online profiles in order to appear more genuine.
The "Richard" in Singapore who was seeking remote IT work appeared to refer to a forged profile by the name of "Richard Lee" – the same name on the green card. The U.S. Department of Homeland Security did not respond to a request for comment.
Reuters found a LinkedIn account for a Richard Lee with the same profile photo who listed experience at Jumio, a digital identity verification company.
"We do not have any records of Richard Lee having been a current or former employee of Jumio," a Jumio spokesperson said. “Jumio does not have any evidence to suggest the company has ever had a North Korean employee within its workforce.”
Reuters messaged the LinkedIn account seeking comment, but received no response. LinkedIn removed the account after receiving requests from Reuters for comment.
"Our team uses information from a variety of sources to detect and remove fake accounts, as we did in this case," a spokesperson said.
Reuters
Sat Nov 25 2023
A redacted online resume of a North Korean IT worker is shown in this screenshot of a report obtained by Reuters. -Palo Alto Networks Unit 42 /via REUTERS
Malaysia perlu bersedia penuhi keperluan TBB yang semakin meningkat - Fadillah
Keperluan tenaga boleh baharu (TBB) di negara ini semakin meningkat seiring dengan keyakinan pelabur asing khususnya untuk mewujudkan pusat-pusat data.
Belanjawan 2025: Kesalinghubungan internet di sekolah, kampus jadi keutamaan - Fahmi
Fahmi berkata ia termasuk isu Internet di kawasan terpencil, pedalaman dan pulau-pulau dalam memastikan akses Internet berkelajuan tinggi lebih meluas.
Pelajar tahfiz perlu teroka bidang teknologi
Kira-kira 200,000 pelajar tahfiz di negara ini, perlu dipastikan untuk mempunyai kemampuan dan peluang menjadi tenaga penggerak kepada umat Islam Malaysia dalam meneroka bidang yang dahulu dilihat sebagai asing., tegas Perdana Menteri Datuk Seri Anwar Ibrahim.
Perpaduan rakyat prasyarat ekonomi mampan
Tidak semua negara Islam mempunyai ruang dan kesempatan untuk terus aman dan damai, dan mempunyai peluang untuk menikmati ekonomi yang kukuh dan berkembang seperti Malaysia, tegas Perdana Menteri Datuk Seri Anwar Ibrahim.
Beliau berkata, rakyat Malaysia perlu mempunyai tekad untuk memahami maksud dan keperluan perpaduan di kalangan mereka, serta kekuatan dalaman yang seterusnya dapat dijadikan tonggak untuk negara membuat langkah seterusnya.
Beliau berkata, rakyat Malaysia perlu mempunyai tekad untuk memahami maksud dan keperluan perpaduan di kalangan mereka, serta kekuatan dalaman yang seterusnya dapat dijadikan tonggak untuk negara membuat langkah seterusnya.
Tidak perlu tergesa-gesa tukar ke lesen B - JPJ
Pemegang Lesen Memandu Malaysia (LMM) Kelas B2 dan B1 tidak perlu tergesa-gesa mendaftar Program Khas Peralihan LLM Kelas B2/B1 Kepada LMM Kelas B kerana tiada had masa ditetapkan untuk permohonan.
KPWKM teruskan lapan inisiatif bantu warga emas
Kementerian Pembangunan Wanita, Keluarga dan Masyarakat (KPWKM) akan terus menggerakkan lapan inisiatif utama dalam memenuhi keperluan jagaan dan sistem sokongan terhadap warga emas.
Warga emas maut ditikam anak kandung yang berhalusinasi
Seorang pesara guru maut ditikam anak kandungnya sendiri di sebuah rumah dekat Kampung Senaling, di sini, petang Sabtu.
Menurut Ketua Polis Daerah Kuala Pilah, Superintendan Amran Mohd Ghani, siasatan awal mendapati warga emas berusia 65 tahun itu cuba memujuk anak lelakinya yang juga pemegang kad orang kurang upaya (OKU) mental yang dikatakan mahu membunuh diri.
Menurut Ketua Polis Daerah Kuala Pilah, Superintendan Amran Mohd Ghani, siasatan awal mendapati warga emas berusia 65 tahun itu cuba memujuk anak lelakinya yang juga pemegang kad orang kurang upaya (OKU) mental yang dikatakan mahu membunuh diri.
Berita tempatan pilihan sepanjang hari ini
Berikut adalah berita yang paling menjadi tumpuan sepanjang Sabtu, 5 Oktober 2024.
Berita antarabangsa pilihan sepanjang hari ini
Antara pelbagai berita luar negara yang disiarkan di Astro AWANI, berikut adalah yang paling menjadi tumpuan sepanjang hari ini.
Hezbollah lancar serangan peluru berpandu ke atas kompleks industri ketenteraan di utara Israel
Pergerakan Hezbollah di Lubnan berkata mereka telah melancarkan serangan peluru berpandu ke atas kemudahan ATA Defence Industries.
Berita antarabangsa pilihan sepanjang hari ini
Antara pelbagai berita luar negara yang disiarkan di Astro AWANI, berikut adalah yang paling menjadi tumpuan sepanjang hari ini.
Berita antarabangsa pilihan sepanjang hari ini
Antara pelbagai berita luar negara yang disiarkan di Astro AWANI, berikut adalah antara yang paling menjadi tumpuan sepanjang hari ini.
Usaha pujuk Korea Utara henti program senjata nuklear gagal - Biden
Rumusan ini dibuat selepas penelitian dasar luar Amerika Syarikat (AS) ke atas Pyongyang.
Mendepani krisis Malaysia-Korea Utara: Teladan kebitaraan diplomasi Melayu
Seiring berjalannya waktu, krisis dengan Korea Utara boleh secara berperingkat diselesaikan menerusi kebitaraan diplomasi Malaysia yang tidak mahu memusuhi mana-mana negara di dunia.
Malaysia tutup pejabat di Pyongyang, semua kakitangan diplomatik Korea Utara diarah pulang
Semua staf diplomatik negara itu yang berada di Kuala Lumpur akan diarahkan untuk meninggalkan Malaysia dalam tempoh 48 jam bermula Jumaat.
Korea Utara sah putuskan hubungan diplomatik dengan Malaysia
Keputusan itu diambil selepas Mahkamah Persekutuan tolak rayuan akhir seorang rakyat Korea Utara terhadap perintah ekstradisi ke atasnya.
Berita antarabangsa pilihan sepanjang hari ini
Antara pelbagai berita luar negara yang disiarkan di Astro AWANI, berikut adalah yang paling menjadi tumpuan sepanjang hari ini, Ahad, 11 Oktober 2020.
Murid prasekolah Korea Utara kini diwajib ambil subjek cerita kehebatan Kim Jong-un
Pelajar prasekolah di Korea Utara dipaksa untuk mengikuti mata pelajaran Greatness Education yang menceritakan mengenai kehebatan pemimpin negara itu, Kim Jong-un selama 90 minit pada setiap hari.
Korea Utara dakwa bangunkan vaksin COVID-19, bakal laksana fasa 3 ujian klinikal
Saintis di Suruhanjaya Sains dan Teknologi berkata pihaknya telah mengesahkan keselamatan vaksin berkenaan menerusi ujian ke atas haiwan.
Korea Utara sambut ulang tahun ke-26 kematian Kim II Sung
Ribuan rakyat Korea Utara berkumpul sempena ulang tahun ke-26 pemergian bekas pemimpin negara berkenaan, Kim Il-Sung