Oktane, Identity, Security Staff Acquisition & Development

Okta: Fake IT workers are getting stealthier than ever

(Adobe Stock)

The issue of North Koreans being hired under false pretenses as remote IT workers for Western companies seems to have faded from the headlines. But according to experts at the Oktane conference last month, the problem isn't going away. In fact, it's getting worse.

"This is a huge, huge threat," said Okta Director of Threat Intelligence Katie Nickels during a panel discussion at Oktane. "Adversaries are using the perfect mix of AI and human techniques."

She explained that IT workers from countries other than North Korea, including Pakistan, India and Russia, had gotten into the game.

"We now use the term 'workforce infiltration,'" she added. "The threat actors have really industrialized this at scale."

Click here for more coverage from this year's Oktane conference.

The main goal of workforce infiltrators is not espionage but money, whether for the North Korean government or the worker's own bank account, Nickels and other Okta experts told us.

Skilled IT workers and software engineers are hard to find, the jobs pay well, and, since the perpetrators are mostly outside the U.S., there's little chance of punishment if they're caught.

"It's not like they won't take advantage to commit espionage if they target the right company and they happen to come across the right thing, but it's just not the primary motivator anymore," said Matt Immler, Okta Regional CSO.

AI makes it possible to fake video interviews and helps scammers do their jobs, letting some of them hold multiple remote IT positions at a time. A support system has even arisen in the U.S. for overseas scammers, Okta experts told us, giving remote workers U.S. IP addresses and hiring Western-looking stand-ins to sit for video interviews.

"There's no downside to doing it," Immler said. "The rise of AI has made this easier. A lot of their work output is just simply throwing it into AI and seeing how long they can get away with it before they're eventually caught."

Why this problem won't go away

A number of factors have coalesced to make pulling off such scams easy — and made it difficult for companies to tell the difference between legitimate job candidates and fakers.

"It definitely is a phenomenon that really has occurred just through the way that work has changed," said Jeremy Kirk, Okta Director of Threat Intelligence. "And the fact that people don't show up to offices every day like they used to."

Nickels said one simple but effective scam is to clone someone else's LinkedIn profile, including their name, and change only the contact email information so that the "candidate" passes a cursory background check.

Scammers also use AI to scrape LinkedIn for the skills and experience that employers are looking for, then cobble together convincing profiles for fictional people.

"It just speaks to how easy it is to create synthetic fake IDs," said Kirk. "This is a problem generally in financially motivated cybercrime and fraud, is that it's really easy to build a LinkedIn profile for a completely made-up person with expertise in certain areas."

Many firms with overworked hiring teams farm out recruitment to outside agencies, which may need to deliver a minimum threshold of qualified candidates to recommend.

"Third-party recruiters often have quotas to meet and won't practice due diligence," Nickels said.

Meanwhile, the degrees of deception may differ. North Koreans using AI to deepfake Western-looking candidates are clearly in the wrong, but what about an Indian with coding experience who copies someone else's resume to improve his chances of being hired? He's still going to do the work — and the company that hires him may be fine with that.

"It can be hard to hire really experienced software engineers," said Kirk "There's a lot of competition."

As Nickels pointed out, the process has become industrialized, and some of that industry exists on American soil in the form of "laptop farms" that overseas workers can remote-desktop into to make it look like they're in the U.S.

"If I think I'm hiring Jen from Minnesota but I also have to ship a laptop to Pakistan, that's a red flag right there," Immler explained. "But if there's a facilitation company that has an office in Minnesota somewhere, that's where it goes. ... They get a little cut of what the person in Pakistan or whatever country is making."

While the North Koreans are famed for using AI to disguise their faces and voices to look and sound like Americans, Nickels said the people sitting for interviews often really are Americans paid to take job interviews.

To answer interview questions properly, she said, the stand-ins may be consulting LLMs on laptops or listening to audio feeds on hidden earpieces, and some may have received pre-interview coaching.

"It's super interesting to look at it because you see all the different ways that they're trying to achieve their end goal of getting employment," said Immler.

How to spot a workforce infiltrator

There are a number of steps that companies can take to minimize the chances of hiring a fake IT worker.

If the job candidate is sitting for a remote video interview, ask them to move their hand in front of their face. That will disrupt (for now) AI's ability to deep-fake their appearance. If the candidate refuses, end the interview.

Ask the candidate to present strongly authenticated government documents, such as a passport or driver's license, during the interview. This won't weed out very good counterfeit documents, but it may trip up paid stand-ins who pass the hand-in-front-of-face test.

Take a screen shot of each candidate's face for future reference and compare new recruits to the headshots you already have.

"These guys are doing this at scale and will reuse faces," said Nickels.

Train your hiring teams to be aware of the problem, to communicate with the legal and security teams, to take notes during each interview, and to look for small signs that may add up to big red flags.

"Threat actors take advantage of any time there's a lack of communication between teams in an organization," said Nickels.

Once a candidate is hired, track where a company laptop or other equipment is sent and make sure it's delivered to the address the new employee claims to be their home.

"If something changes, we can remotely basically brick that machine and say it's never going to work because we know it's not going to the place that we intended it to go," said Immler.

The best way to verify new hires is to have them come into a company office to present themselves along with strong forms of identification. Okta does this as a matter of policy.

"Once somebody's onboarded, within the first month of employment, and I don't care if you're a remote employee like this, you show up in an Okta office somewhere. We will get you a plane ticket and you will show up," said Immler. "We can actually do an in-person liveness check as well as go through in-person security training and onboarding."

Granted, smaller companies may not be able to afford to pay a new hire's travel costs and may not have offices all over the world. For them, verifying job prospects and new employees is going to be harder.

"All of this is going to get increasingly difficult as AI gets more polished," said Kirk. "It's going to just pose a continual challenge for identity verification."

Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds