North Korean Hacker Infiltrates U.S. Firm: The Remote Worker Who Wasn’t
KnowBe4 discovered a North Korean threat actor posing as a remote software engineer using a stolen identity and AI-augmented images. Despite sophisticated tactics, the company detected the scam when malware was loaded onto an Apple laptop. No data was compromised, though the incident highlighted vulnerabilities in the hiring process.

Hot Take:
This is the cybersecurity equivalent of a catfishing scandal, except the catfish is a North Korean hacker and the dating app is your company’s payroll. Swipe left on shady remote hires, folks!
Key Points:
- KnowBe4 hired a remote software engineer who turned out to be a North Korean hacker.
- The hacker used a stolen identity and AI-enhanced images to pass background checks and interviews.
- Suspicious activities on a company-issued Apple laptop triggered an internal investigation.
- The hacker used a Raspberry Pi to download malware and manipulate session history files.
- KnowBe4 shared its findings with the FBI and Mandiant, concluding the hacker was operating from North Korea.
Already a member? Log in here