Go back

Chandana Seshadri: How North Korean IT workers exploit remote hiring systems

14m 8s

Chandana Seshadri: How North Korean IT workers exploit remote hiring systems

In an exclusive episode of the NK News podcast, Chandana Sashadri highlights the exploitation of identity management vulnerabilities by North Korean IT workers to earn hard currency and support cyber operations. Strategies discussed include verifying identities through methods like turning on cameras during remote hiring and auditing recruitment processes. The discussion delves into the intricate connection between North Korean IT workers and cyber operations, emphasizing the need for a broader perspective to understand their role within the larger cyber network. The interview touches upon the challenges faced by companies in authenticating remote workers and the importance of robust recruitment methodologies that can be audited for compliance. The conversation provides insights into the evolving landscape of North Korean IT workers, their revenue-generating activities, and the potential risks they pose to organizations.

Transcription

2274 Words, 13122 Characters

You're listening to an exclusive episode of the NK News podcast available only to subscribers. You can listen to this and other episodes from your preferred podcast player by accessing the private podcast feed. For more detailed instructions, please see the step-by-step guide on the NK News website at www.nkenews.org/private-feed. Hello listeners and welcome to the NK News podcast. I'm your host, Jacko's Wetsuit and today I'm recording this episode via StreamYard It is Tuesday, Wednesday, the 3rd of September 2025 and today I'm joined on the NK News podcast by Chandana Sashadri, non-resident fellow at the Stimson Center's 38 North and former research analyst at RUSI specializing in the intersection of sanctions, financial crimes and cyber threats with a focus, of course, on North Korea. Chandana's recently published RUSI journal article "How DPRK IT Workers Exploit Identity Management Vulnerabilities" shows how North Korean information technology workers slip through remote hiring systems to earn hard currency and open doors for bigger cyber operations. This is a topic that you will have heard us mention in this shorter Tuesday episodes with my in-house colleague at NK News, but today we're going to do a really deep dive. So welcome on the show, Chandana. Thank you for having me. It's a pleasure to be here. So if Human Resources is the new sort of front line against North Korean sanctions evasion, what is the one stat or the one recent case that you would use to turn a skeptical CEO from HR problem to national security threat in 60 seconds? I think the most recent conviction of this US citizen called Christina Chapman. I think that's one particular case that everybody should be looking into because it's the first conviction case where it was discovered that she was running laptop farms for these North Korean IT workers. And because of that, she was able to facilitate around jobs for 300 companies to these IT workers. So in 60 seconds, I think that's enough. Yeah. And we're definitely going to get into the details of what a laptop farm, how that works and Christina Chapman. But yeah, that's a good case there. Now, you say at the start of your paper that this is "a strategic deployment of information technology workers to generate revenue for North Korea's weapons of mass destruction program." That's a big and a bold claim. We're going to go through parts of that claim in this interview. But for now, could you identify one red flag that you wish HR and hiring managers would learn to spot this year, to avoid being part of that program? Definitely. One strategy that these North Korean IT workers are employing is to specifically look for remote work. And when HR or any team are trying to hire people, they usually don't switch on their cameras when they're hiring anybody through remote work because it's not necessary to see my face or your face as long as you do the work. So there are these simple tricks that HR companies could improve by doing cold calling or switching on asking them to switch on cameras, et cetera. That's probably a very simple and easy thing that could be used as a mitigation strategy. Very good. So switch on your cameras and have your interviewees switch on their cameras too, yeah. And what would be one metric that a board of directors at a company should look at monthly to sort of gauge identity risk exposure? I don't know if there is one exact metric for that. It's a very tough question, but I think it's more on if they have good auditing systems as to how many people have been hired quite recently and how many people have moved on, the turnover rate depending on how many remote workers have been hired and how long they stay. In the company doing the work, I think that's quite important. And one interesting thing about this case is or the issue of North Korean IT workers is how they're getting paid. So if payment or salary is happening via cryptocurrency or through doji accounts, et cetera, if there's a way to identify these suspicions through auditing, I think that's where these boards or CEOs must have an understanding. There's a way to report this. I think that would be one step to improve compliance or even just to have an idea about this issue. Okay. Good advice. All right. So let's now get into sort of drawing the big picture of the threat. How big and how organized is the DPRK IT worker ecosystem today? And where does it sit inside the wider North Korean cyber program and revenue generation? That is a good question, but it's a very difficult question to address very linearly. So a DPRK IT workers is not a very new issue. It's been going on for a while as remote work started or after COVID-19, you suddenly started to see a lot of freelance opportunities, remote work opportunities. So you could potentially say that the magnitude or the impact kind of spread because of COVID or after COVID, but if you were to talk about personally as a DPRK financial crime researcher, if I were to look at the historic transition of how North Korean IT, North Korean actors have improved their activities or come up with new sophisticated ways, this seems like a very natural progression for them. But if you were to put it into a structure as to where they actually sit, I think you could see that they do come under the larger cyber network of DPRK actors. Whether they are right at the top or right at the bottom, it's a bit hard to say. You can to an extent, but I think that a lot of overlaps between North Korean IT workers and North Korean cyber actors, who's actually responsible for what activity per se. And then there is another aspect to North Korean IT workers, whether they are malicious actors or whether they are only revenue generating actors. What is their motivation or what is their purpose? Like you initially mentioned, I have written it in the beginning as well. Most of the revenue that is generated ends up in the weapons of mass destruction program or even to sustain their day to day living, et cetera. So it's a bit hard to concretely say that, yes, the money earned from this North Korean IT worker A ends up going back to the regime into that particular account, et cetera. But the idea behind all this is that it sits within the larger cyber network. But if you want to go deep into the detail, I think it'll take a longer time to do the research around that specifically. Right. Now, we've talked about the Lazarus heist before on this podcast with the massive theft of money, first of all, from the, I think the Bank of Bank of Deshif, I'm not mistaken. And then later on through ATMs worldwide, just using people stolen bank details. Would you imagine just sort of in the real worker day world of North Korean IT workers that the people who did the Lazarus heist would know some of the people who are doing the IT work, remote work that we're talking about today, are they in the same ecosystem? Let's take a bird's eye view of this ecosystem. So if you zoom out completely, yes, they're all under the same network, technically speaking, because there are some certain very transferable skills that could be used to maintain certain IT systems or get a job, do put your head down and do venial work. But if I were to take a guess, whether they do know, or there are certain actors who might do odd jobs here and there be with the Lazarus group, if you say, or be a revenue raising activity that one random IT worker does potentially, but you can't concretely say that yes, they are both these actors are the same. But there over there could be overlaps in terms of their activities or their timing, what their boss asked them to do. So in that sense, if you take a zoom out view, yes, they're probably under the same network. And as you point out, many of these skills are certainly transferable so they can be used across multiple teams. Now the United Nations panel of experts before it was shut down, estimated that illegal cyber operations provided about 40% of the revenue that North Korea needs for its weapons of mass destruction program. Do we have any idea what portion IT workers likely contributed into that pot? It's very difficult to give an estimate, but you can say, I think the advisory is provided by the United States around how much these IT workers are earning annually. And individually, it is provided around 300,000 annually or something in that ballpark. But to what percentage is the IT worker contribution to these illegal cyber operation? I think it's a very murky figure, it's very difficult to estimate. And I know it becomes a little difficult from addressing this issue. The larger the estimate, then most probably law enforcement would have a better understanding or a prioritization or some kind of motivation to do something about this. But nonetheless, I think there are other ways to look at this issue. It's more got to do with, given IT workers are actually infiltrating into systems, the problem lies not in how much percentage of the illegal cyber operations is conducted by them, but more on how much information they get access to. So this is private company information, IP information, there could be legal repercussions, there could be reputational damages that could be done with North Korean IT workers getting access to company information. And on top of this is how much illicit revenue they can generate simply through salaries. So addressing this issue more from a broader perspective rather than a metric also helps in understanding this issue in a very linear way that is required. Right. Given the difficulty of talking about numbers, where do we see the center of gravity today in terms of this illegal fundraising, is it likely to be in the simple revenue extraction through invoicing and payroll or is it more in post access monetization like code and data exfiltration? Yeah, I think it's important to again go back to dividing whether these IT workers are illicit actors with malicious intent or are they there just to do the job and gaining standard revenue. So if you look at it, if you were to understand this issue more from the criminal mindset, you'd realize that having a stable revenue is good because there is a cushion to fall on for them compared to the other cyber activities that they're doing, whether it's buy bit hack or other crypto hacks that they're quite risky, very sophisticated. So for them to fall back on this stable revenue that they're generating through incomes, I think that's a strategy to work at. But I think it's more on understanding this issue broadly and how they work with each other. They're both actors as well as just the stable revenue that they're earning. Okay, let's talk about identity management. In simple terms, where do today's identity verification and authentication processes fail companies, especially in the area of remote hiring? We've already mentioned the problem of turning on cameras, but what are some of the other issues where these systems fall down? Yeah, I think that's one way as to how I wanted to approach this research because I think that could be one way of bringing up or coming up with practical mitigation strategies because there is no one way or one standard, golden standard way of hiring anybody. Every company has their own. If there ever was one, there certainly isn't one anymore. No. So there are no standardization CVs or even with remote workers. Every single recruitment company has their own policies. Every company's have their own policies to work with third party recruiters, it can keep going that way. There are many, many methodologies, but I'm not saying that there should be one single methodology. But I think it's more got to do with how robust this methodology is and how is it possible for these methodologies to be audited or looked at it from a due diligence or compliance perspective? I think that is more important. So there are very obvious loopholes here because out of personal experience, not that I know any North Korean IT workers, but through my friends or colleagues or others who've been hired doing remote role, they are working in different companies in different geographic locations, but their own, they haven't been asked to show their passports or their national ID, for example, to verify whether they are real or not, or do they have the right to work or not. This is the most basic thing that anybody should be doing, and I'm not blaming HR here. HR already has a whole load of issues that they need to worry about anyway. Curious to hear the rest? Become an NK News subscriber today for access to the full episode. Head to nknws.org/join for more information. If you're already a subscriber to NK News, you can listen to full episodes from your preferred podcast player by accessing the private podcast feed. For more detailed instructions, please see the step-by-step guide on the NK News website at nknws.org/private-feed.

Podcast Summary

Key Points:

  1. Chandana Sashadri discusses North Korean IT workers exploiting identity management vulnerabilities for financial gain.
  2. Strategies to mitigate risks in remote hiring include verifying identities and auditing recruitment processes.
  3. The connection between North Korean IT workers and cyber operations is complex and overlaps with wider cyber networks.

Summary:

In an exclusive episode of the NK News podcast, Chandana Sashadri highlights the exploitation of identity management vulnerabilities by North Korean IT workers to earn hard currency and support cyber operations. Strategies discussed include verifying identities through methods like turning on cameras during remote hiring and auditing recruitment processes. The discussion delves into the intricate connection between North Korean IT workers and cyber operations, emphasizing the need for a broader perspective to understand their role within the larger cyber network.

The interview touches upon the challenges faced by companies in authenticating remote workers and the importance of robust recruitment methodologies that can be audited for compliance. The conversation provides insights into the evolving landscape of North Korean IT workers, their revenue-generating activities, and the potential risks they pose to organizations.

FAQs

Christina Chapman's case highlights how she ran laptop farms for North Korean IT workers, facilitating jobs for 300 companies and revealing the extent of their operations.

A red flag is when remote workers refuse to turn on their cameras during interviews, indicating a potential risk of North Korean IT workers exploiting identity management vulnerabilities.

Boards should monitor turnover rates of remote workers, auditing systems, and payment methods like cryptocurrency to gauge identity risk exposure.

DPRK IT workers are part of the larger cyber network in North Korea, with overlaps between revenue-generating and malicious activities, contributing to the regime's revenue needs.

While there may be overlaps in activities or networks, it is challenging to confirm direct connections between North Korean IT workers and cyber heist groups like the Lazarus group.

Estimating the exact contribution of IT workers to illegal cyber operations is difficult, given the complex nature of their activities and revenue generation methods.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.