logo

Imposter for hire: How fake people can gain very real access

ID: 58bc3e98-42f2-5ace-8395-7041f6d8f5db

STIX ID: report--58bc3e98-42f2-5ace-8395-7041f6d8f5db

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2025-12-11

Date Updated: 2026-04-28

Author: Microsoft Incident Response

...
...

Microsoft DART investigates a campaign attributed to the North Korean remote IT workforce known as Jasper Sleet, in which attackers posed as legitimate remote hires and used PiKVM devices to gain persistent, out-of-band control of employer-issued workstations, bypass endpoint controls, and exfiltrate sensitive data. The report details detection and response actions (account disables, forensic collection, telemetry analysis), tools used for investigation, and recommendations including stronger pre-employment vetting, least privilege, monitoring for unauthorized IT tools, and Microsoft security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.