
A Fake Job Offer Put a Children's Hospital on North Korea's List | 2 Minute Drill with Drex DeFord
Questions Answered in This Episode
- Do you know every contractor and every vendor with a login to your network?
- Would you catch it if one of your developers ran a coding test that wasn't really a coding test?
- If a foreign government added your hospital to a list on the dark web, would anyone on your team even know?
About This Episode
A recruiter offers a developer a remote job. Good money. Just run a coding test first. The test is malware, and the people sending it work for the North Korean government. The trick has a name: Contagious Interview. You think you're getting hired. You're getting infected. Vangelis Stykas, a security researcher in Greece, got inside the attackers' own servers after they infected their own machines. He sat there nearly two years and counted 1,640 companies across 57 countries. Seven or eight hundred of them hit hard: root access to servers and cloud. At crypto firms, they walked off with the keys to the money. He took it to Black Hat in Las Vegas and read the list: Coinbase, a chunk of the Belgian government, Italy's top judicial council, a Saudi bank, and a children's hospital sitting on a target list built by a foreign government, all off a fake job offer. Nobody kicked down the digital front door. They walked in as contractors and freelancers with real logins.
In this Two Minute Drill, Drex DeFord asks the question hospitals should be asking now: do you know every contractor and every vendor with a login to your network?
Remember, Stay a Little Paranoid.





