We're screening for North Korean IT workers in the wrong place. Most of the advice on North Korean IT workers is about catching them in the interview. I think that's the wrong place to put most of our effort.
The joint advisory four governments just put out is a good example. The hiring advice is almost entirely human: check the applicant's IP against where they say they live, call their phone number, drill the resume live, and ask about their hometown and hobbies.
(Apparently "tell me about your hometown" is a security control now.)
I'm not knocking any of it. Talking to a real person is still one of the better fraud checks we have. But it only works on applicants, and a laptop farm exists to beat the IP check anyway. None of it helps with the one who already passed, got the laptop, and built a normal work record.
And I'd assume one already has. At
@OneRSAC last year,
@Mandiant's Charles Carmakal said nearly every Fortune 500 CISO he'd talked to about this problem admitted hiring at least one North Korean IT worker. I wouldn't bet on smaller shops doing better. (I'd love to be wrong on that.)
The advisory does mention least privilege, in one line, next to revoking accounts once you suspect someone. Revoking only helps once somebody notices. I'd put least privilege at the center for new remote hires. Access should grow with tenure instead of arriving on day one, and you should have a tested answer for how fast you can pull it back.
Pick your newest remote engineer. What could they reach, exfiltrate, administer, deploy, or monetize before anyone had a reason to wonder? I built the brand new FOR500: SANS Windows Forensic Analysis case with
@HeatherMahalik Barnhart and
@ovie Carroll around exactly that hire.
Operation Crimson Ledger puts you on the Windows 11 laptop of a remote engineer who cleared the interview and looked normal for months: two remote-access tools, a consumer VPN, an AI coding agent with more screen time than Office, company files staged to a personal Google Drive, a mailbox exported through a second copy of Office, and a wiper run seven times in the two minutes around the upload. (Least privilege wouldn't have stopped all of it, but it would have made the trail a lot shorter.)
Advisory:
ic3.gov/CSA/2026/260918.pdf
SecurityWeek:
securityweek.com/japan-disma…