Biz hired, and fired, a fake North Korean IT worker – then the ransom demands began
ID: 8a6d4e4f-f2a2-5b08-9168-080294cb843d
STIX ID: report--8a6d4e4f-f2a2-5b08-9168-080294cb843d
Feed Name: The Register (Security)
Secureworks documents an active North Korean campaign (attributed to Nickel Tapestry) that places fake remote IT contractors to establish persistent access, exfiltrate proprietary data (often to personal Google Drive locations), and then extort victims with six-figure cryptocurrency ransom demands; observed indicators and TTPs include use of Chrome Remote Desktop, AnyDesk (linked to Astrill VPN IPs), SplitCam virtual webcam software, laptop rerouting, and the use of payment services like Payoneer—organizations are advised to verify candidates, restrict unsanctioned remote access, and monitor onboarding financial changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
