Imposter for hire: How fake people can gain very real access
ID: 58bc3e98-42f2-5ace-8395-7041f6d8f5db
STIX ID: report--58bc3e98-42f2-5ace-8395-7041f6d8f5db
Feed Name: Microsoft Security
Microsoft DART investigates a campaign attributed to the North Korean remote IT workforce known as Jasper Sleet, in which attackers posed as legitimate remote hires and used PiKVM devices to gain persistent, out-of-band control of employer-issued workstations, bypass endpoint controls, and exfiltrate sensitive data. The report details detection and response actions (account disables, forensic collection, telemetry analysis), tools used for investigation, and recommendations including stronger pre-employment vetting, least privilege, monitoring for unauthorized IT tools, and Microsoft security controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
