KnowBe4 mistakenly hires North Korean hacker, faces infostealer attack
ID: 1627e9fd-ed8c-5c84-9700-1331bf97b4c9
STIX ID: report--1627e9fd-ed8c-5c84-9700-1331bf97b4c9
Feed Name: Bleeping Computer
KnowBe4 hired an individual who was later determined to be a North Korean state actor using a stolen U.S. identity and AI-generated profile to pass background checks; the actor attempted to install an information-stealing malware on a newly issued Mac (using a Raspberry Pi and remote access via a mule laptop farm) but the company's EDR detected and blocked the activity, preventing data loss. The case underscores DPRK tradecraft including identity fraud, AI-assisted masking for interviews, and remote mule infrastructure, and KnowBe4 recommends isolating new-hire systems and treating address inconsistencies as red flags.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
