Fake Remote Workers: A Growing Threat
For many security teams, the expected route into the corporate network begins with a phishing email or exploited vulnerability. However, certain techniques differ, exploiting the hiring process to gain legitimate access. In July, the US Department of State released an alert warning of North Korean IT workers impersonating nationals of other countries for the purpose of obtaining work.
Once employed, those workers then send their salaries back to parent agencies in North Korea. The FBI has also warned that fraudulent workers may use their access to copy source-code repositories, exfiltrate proprietary information, and support other cybercriminal activity. After being discovered or dismissed, some have attempted to extort their employers by threatening to publish stolen code and data.
Tactics Used by Fake Remote Workers
These operations expose a gap between checking an identity and proving who is using an account. For instance, a résumé may appear credible, and a laptop may arrive at a domestic address. But, neither of those controls, on its own, proves that the person interviewed is the person who receives the device, or the person who ultimately signs in.
- Changing their nationality or identity: This is a key tactic of North Korean IT workers, who will falsify information when registering for online platforms.
- Create fake profiles using AI: To add legitimacy to their identities, fake workers may also create professional profiles and social media accounts.
- Unorthodox payment methods: Fake workers may attempt to avoid being paid by direct deposit, instead favoring money transfers or cryptocurrency.
- Disguising their location: Tools such as VPNs and remote desktop software may be used to hide the fact that a person is working from abroad.
- Using overseas facilitators: Some fake workers will use proxies for device delivery and use.
Why Employment Checks do not Prove Who is Using the Laptop
Background checks, right-to-work checks, and identity screening are built to confirm that the details supplied by a candidate are credible. However, fake remote-worker operations exploit the gaps between several different forms of verification.
An organization may confirm that an identity exists, that the named person is eligible to work, and that a laptop was delivered to an approved address. It can still issue credentials to an account that is ultimately controlled by someone else.
Warning Signs of a Fake Remote Worker
No single indicator proves that an applicant is part of a fake worker operation. However, there are several warning signs to watch out for, as outlined by the US Department of State:
- Frequent changes to registered information.
- A mismatch between the account holder’s name and the name on the registered payment account.
- Multiple accounts created using the same ID.
- Multiple accounts accessed from the same IP address, or a single account accessed from multiple IP addresses in a short period.
- Unusually high hours logged in.
Securing the Onboarding Process Against Fake Hires
Organizations need robust vetting processes for freelance and remote hire to mitigate the risk of fake workers. Solutions like Specops Secure Onboarding allow organizations to confirm identity at a crucial point, by adding government-issued identity-document scanning and biometric liveness detection to the onboarding process.
The document check helps confirm that the identity document is genuine, while the biometric check compares the person completing onboarding with the photograph on that document. Liveness detection then establishes that a real person is physically present, rather than a photograph, recording, or manipulated video being presented to the camera.
By combining government-issued document validation with biometric liveness on day one, then requiring identity confirmation before service-desk agents act, Specops Secure Onboarding provides trusted identity-proofing checkpoints at the moments most likely to be targeted.
Source: BleepingComputer