
A Fake Job Offer Put a Children's Hospital on North Korea's List | 2 Minute Drill with Drex DeFord
Questions Answered in This Episode
- Do you know every contractor and every vendor with a login to your network?
- Would you catch it if one of your developers ran a coding test that wasn't really a coding test?
- If a foreign government added your hospital to a list on the dark web, would anyone on your team even know?
About This Episode
A recruiter offers a developer a remote job. Good money. Just run a coding test first. The test is malware, and the people sending it work for the North Korean government. The trick has a name: Contagious Interview. You think you're getting hired. You're getting infected. Vangelis Stykas, a security researcher in Greece, got inside the attackers' own servers after they infected their own machines. He sat there nearly two years and counted 1,640 companies across 57 countries. Seven or eight hundred of them hit hard: root access to servers and cloud. At crypto firms, they walked off with the keys to the money. He took it to Black Hat in Las Vegas and read the list: Coinbase, a chunk of the Belgian government, Italy's top judicial council, a Saudi bank, and a children's hospital sitting on a target list built by a foreign government, all off a fake job offer. Nobody kicked down the digital front door. They walked in as contractors and freelancers with real logins.
In this Two Minute Drill, Drex DeFord asks the question hospitals should be asking now: do you know every contractor and every vendor with a login to your network?
Remember, Stay a Little Paranoid.
Transcript
This transcription is provided by artificial intelligence. We believe in technology but understand that even the smartest robots can sometimes get speech recognition wrong.
A Fake Job Offer Put a Children's Hospital on North Korea's List | 2 Minute Drill with Drex DeFord
[00:00:01] Drex: Hey everyone, I'm Drex, and this is the Two Minute Drill. Thanks to Fortified Health Security for sponsoring this podcast. It's great to see you today. Here's some stuff you might want to know about. There's a guy named Vangelis Stikas. He's a security researcher in Greece. He's the kind of guy who pokes around in systems for a living. He's hunting for one loose thread that no one else has noticed.
[00:00:24] Drex: About two years ago, he found one and he pulled on it. And I'm going to get to that, but the best way is probably to tell this story from the other end of the thread. Somewhere out there, there's a software developer who's just received a friendly message from a recruiter. And the recruiter is offering this great job. Good money, work from home, kind of rare now.
[00:00:48] Drex: Just take a quick coding test first. It's kind of the initial gate to the interview process. And he asked the candidate to download a file and run it and show us what you can do. But it turns out the coding test is malware. And the people sending it weren't really recruiters.
[00:01:07] Drex: They were working for the North Korean government. And this fake interview trick is common enough now that it has its own name. It's called a contagious interview. And it's exactly what it sounds like. You think you're getting hired, but in fact, you're getting infected. And now back to the other end of the thread and the security researcher I started this story with, Vangelis. He got inside the attacker's own servers.
[00:01:32] Drex: And part of how he got into it is almost funny that hackers had sort of sloppily infected their own machines with their own tools, which allowed him to get inside and see everything in their infrastructure. Cloud, their Slack, their Discord, about five terabytes of their code and all their keys. In his words, I have access to a lot of stuff.
[00:01:55] Drex: So I sat there quietly for nearly two years watching the people who spend their days watching everyone else. And he started counting. Sixteen hundred and forty companies, fifty seven countries, seven or eight hundred of them hit really hard, route access to their servers, route access to their cloud.
[00:02:17] Drex: And the crypto firms at the crypto firms, the attackers walked off with the keys to the money. Vangelis called it ridiculous access. And he took all this to Black Hat, the big security conference in Vegas a couple of weeks ago, and basically held it up in front of the room. And he said, this is real and this is a big deal.
[00:02:37] Drex: And oddly enough, many of the companies in the room had no idea it was happening. Then he read down the victim list, Coinbase, a chunk of the Belgian government, Italy's top judicial council, a Saudi bank. And then one name that kind of caused me to stop. It's a pediatric hospital, a children's hospital sitting on a target list built by a foreign government,
[00:03:01] Drex: all off the back of a fake job offer. In this case, the children's hospital involved says that the incident involved a former independent contractor's personal device and not the hospital systems. And once they'd been informed, the cybersecurity and I.T. team disabled remaining any remaining active access within hours. And they found no evidence of unauthorized access to the hospital systems.
[00:03:25] Drex: But in that one case, and actually in all of these cases, nobody kicked down the digital front door with some brilliant zero day. They walked in as people who were supposed to be their contractors, mostly outside consultants and developers with real legitimate logins.
[00:03:44] Drex: Vangelis found some contractors had access to as many as 30 companies at the same time because these contractors were independent freelancers. You compromise one freelancer and you're standing inside of 30 company networks. North Korea does this for a reason.
[00:04:04] Drex: The money they steal, the access they hold ransom, all that funds the regime and their weapons programs. Straight past every sanction, every country in the world has put on them. So here's today's question. Think about your own shop for a second. The offshore dev team or the imaging vendors, engineers or the consultant who built your integration and still has a login months after the job has ended.
[00:04:30] Drex: Do you know every contractor and every vendor with a login to your network? Would you catch it if one of your developers ran a coding test that wasn't really a coding test? And if a foreign government added your hospital to a list on the dark web, would anyone on your team even know? That's it for today's Two Minute Drill. Drop me a note and let me know what you're working on.
[00:04:54] Drex: I'm always happy to hear from you. I'm Drex at 229project.com. Thanks again to Fortified Health Security for sponsoring the show and thank you for being here. Stay a little paranoid and I'll see you around campus.





