Secureworks released a report detailing how North Korean attackers are targeting western countries with a new tactic. Attackers are fraudulently obtaining positions so they can victimize the employer!
I predict we will see more of these types of attacks where stolen or fabricated data is used to obtain a trusted position at the targeted organization. Once permissions are granted to the new employee, they use that access to steal information, upload malware, facilitate ransomware attacks, and eventually plant logic bombs & backdoors in products and infrastructure. Depending upon the role the fraudster is able to obtain, they may be able to use their position to infect partners, vendors, and even customers!
Be wary and act now to implement basic insider risk programs to prevent/minimize, detect, and respond to these attacks
The best mitigation is to thoroughly vet applicants, apply the principles of least access to new hires, and train existing employees to watch for signs of unusual activity.
Comments