How a North Korean Fake IT Worker Tried to Infiltrate Us
ID: badda16c-826b-5dbe-92f8-7d7789a366b4
STIX ID: report--badda16c-826b-5dbe-92f8-7d7789a366b4
Feed Name: KnowBe4 Blog
Threat Score
KnowBe4 detected and contained an attempted insider compromise in July 2024 where a newly hired engineer — later attributed to a North Korean fake identity — received a company Mac that immediately began loading malware; the SOC intervened, engaged Mandiant and the FBI, confirmed the hire used a stolen identity and AI-enhanced imagery, and reported no data loss but recommended strengthened vetting, monitoring, and access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
