
Loading summary
Nicole Prolorath
I was a little concerned, but I
Charles Carmichael
really wanted the money.
Nicole Prolorath
I don't know if they are telling
Ilya Krugman
themselves a story that they are running a legitimate business or they just don't care.
Nicole Prolorath
It was shocked that this is North
Michael Barnhart
Korea, and I mean, they are everywhere.
Nicole Prolorath
The pressure to meet quotas was much stronger than any ethical concern.
Charles Carmichael
Honestly, I've yet to find a company that has told me they haven't unintentionally hired a North Korean IT worker.
Nicholas Carlini
This is IT.
Nicole Prolorath
I organizational scale. This is not an individual threat actor or a isolated group. I'm Nicole Prolorath, and this is To Catch a Thief. Over the course of this season, we've watched North Korea infiltrate companies, steal cryptocurrency, and build one of the most sophisticated sanctions evasion operations on earth. But money was never the end goal. It was just a means to an end. And to understand that end, I turned to someone who's been studying North Korea's end game closer than almost anyone.
David Sanger
I'm David Sanger. I'm the White House and national security correspondent for the New York Times.
Nicole Prolorath
David's a good friend, and for a decade, he was my reporting partner at the New York Times. Together, we covered some of the biggest national security stories of our generation, from cyber operations by China, Russia, Iran, and the United States to North Korea's attacks on Sony and beyond. And while I was focused on the cyber of it all, David was tracking the other half of the story. North Korea's accelerating nuclear program and Kim Jong Un himself.
David Sanger
Well, Nicole, it's been pretty remarkable when you think about the fact that when Kim Jong Un came in, the CIA assessments were asking questions like, could this guy last six months? Could he last a year? Will the old generals and elders kill him, or will they just exile him? And the first thing he did was consolidate power. With a speed that shocked everybody, it appears Kim Jong Un has purged some
Nicole Prolorath
of his father's generals. Vice Marshal Ri Yong Ho was often
Hani Farid
seen alongside the new leader and then mysteriously fired from all his duties in July of 2012.
David Sanger
Second, he began to embrace the new technologies that he thought could make money for them. Remember, how did North Korea make money before cyber came along as an option to them, they counterfeited $100 bills. But the fact of the matter is the world's moved to a more cashless society, and he was actually ahead of the curve here. So we saw Kim move from plain old cyber attacks that were meant to send a message. The Sony hack was the classic example and the one that woke all of us up. To learning how to steal from central banks, to learning how to get inside cryptocurrency wallets and drain those out. And they've done it time and time again. They've turned sanctions of Asia into an art form, but they got so good at it that it's clear that they are becoming a model for other countries. Ultimately, the money's going to all of his favorite projects, but his most favorite project are his nuclear weapons projects.
Nicole Prolorath
If North Korea was going to survive as a global pariah, the regime knew it needed nukes, the ultimate deterrent against the world's superpowers, especially the United States. If the past decade proved out anything, it's what happens to countries when they give up their nuclear leverage. See Libya.
David Sanger
Today in Tripoli, the leader of Libya,
Nicole Prolorath
Colonel Muammar Al Qaddafi publicly confirmed his
David Sanger
commitment to disclose and dismantle all weapons of mass destruction programs in his country.
Rob Joyce
Today we can definitively say that the Qaddafi regime has come to an end and one of the world's longest serving dictators is no more.
Nicole Prolorath
We came, we saw, he died. After more than 40 years in power, Libya's new leaders say Muammar Gadafi is dead.
David Sanger
Skeptics once claimed that the nuclear threat would actually grow after the Soviet Union dissolved. But because of the wisdom and statesmanship
Nicole Prolorath
of the leaders who joined me here,
David Sanger
the skeptics have been proven wrong.
John Holtquist
The document signed by the leaders of Ukraine, Russia, the UK and the US Required Ukraine to give up its nuclear weapons stockpile. In exchange, world powers promised to respect Ukraine's existing borders and sovereignty.
Nicole Prolorath
Now we head overseas to the fast moving changes in Ukraine, signaling the Russians appear to have won this round.
David Sanger
Taking control of their prize Crimea, Russia
Nicole Prolorath
overnight launched its long anticipated attack on Ukraine, striking military posts across the country. And then there's Iran, which signed a nuclear deal with the United States, only to watch America walk away, then join Israel in taking out its leader and bombing the country a decade later. Overnight, the US Launching strikes on military targets on Kharg Island, Iran's main oil export terminal. And with hours to go until his deadline for Iran to make a deal. President Trump with an alarming new threat, writing a whole civilization will die tonight, never to be brought back again. The President addressing the nation after a coordinated attack on Iran. The military operation now underway with Israeli forces. The strikes by Israel and the US Hitting targets in Tehran during the morning. After the US And Iran traded strikes this week, the Trump administration asked Iranian officials to publicly state the Strait of Hormuz is open and its attacks on ships have ended. The US Is blaming the strikes on divisions within Iran's government initiated by, quote, radicals in their system who are trying to derail the negotiation. J. Ron says it's not responsible. Iran is the crisis David's been reporting on most closely. But Iran also tells us something chilling about North Korea, about why Kim was never going to stop short of a nuke. Because once you cross the nuclear threshold, the world may sanction you, isolate you, threaten you, but it's far less likely to attack you.
David Sanger
You know, we spend a lot of time discussing Iran these days. But think for a moment about what would have happened if Iran had followed Kim Jong Un's strategy and not dilly dallied around and walked up to the edge of building a nuclear weapon, but just went for it and had obtained one. Would we have attacked in February? United States? I doubt it.
Nicole Prolorath
These days, I imagine Kim Jong Un squirreled away in one of his private residences, villas or fortified compounds, watching the strikes on Iran, thinking I've done it right. In some ways. The west just spent the last 20 years validating North Korea's nuclear give em up and you might pay a price.
David Sanger
President Trump called me to talk about the Iran deal that he had just signed. And I said to him, you know, if I was the Iranians, and I drew a lesson from this, the lesson I think I would have drawn was the North Koreans got this right. And if I was an Iranian who had just survived this war, I'd probably think it's time to follow Kim Jong Un's strategy. But the fact of the matter is they now have 60 or more nuclear weapons. Some analysts think it's probably closer to 100, which would put them at comparable to the arsenals of Pakistan and Israel. And that's where the money's going. It's not going to social welfare programs to feed its people.
Nicole Prolorath
And yes, the weapons program gets the lion's share. But not every stolen dollar ends up in a missile silo. Munitions get priority funding. But Kim Jong Un has another line item. His toys.
Rob Joyce
Bulletproof stretch limos made by Mercedes and Rolls Royce worth about $500,000 each. There's nothing for Kim Jong Un quite like a ride on a white stallion on a revered mountaintop. As a means of inspiring his people. Pyongyang's state run news agency released several photographs of Kim riding the galloping horse atop North Korea's highest peak, the volcanic Mount Paektu. Experts say Kim also spends the money on luxury goods for himself, for his glamour conscious wife and his cronies, a private jet, an exclusive ski resort, and a polished white yacht.
Nicole Prolorath
But Kim's top priority has always been his nuclear arsenal. And year after year, while the world was focused elsewhere, North Korea kept advancing right under our noses.
David Sanger
You know, one of the things that astounds me in this job is that Donald Trump did not raise the alarm about North Korea. He's barely talked about North Korea, and every time he does is to tell everybody what a warm relationship he's got with Kim Jong Un. We got along great.
Nicole Prolorath
I know him better than you do.
David Sanger
I know him better than anybody almost.
Nicole Prolorath
You know, I'm not supposed to say I really like him a lot, because if I do that, I get killed
David Sanger
in the fake news media. But I got along with it very
Nicole Prolorath
well, and we had no problem. But relationships aren't disarmament, and neither is our inattention. And while Washington moved on to Iran, to Ukraine, to China, to whatever crisis was breaking that day, North Korea kept building. Not suddenly, not secretly exactly, but in the space created by our assumption that this is still a backward, isolated country we can afford to underestimate.
David Sanger
It tells you how much the North Koreans rely on us thinking about them as a backward society whose people are eating grass because they've got nothing else and where the smokestacks are all silent, as they were when I was in North Korea more than 30 years ago, if it wasn't for nuclear weapons, how much thought would we all give every day to North Korea? Not much. Second, if we had a state like North Korea that was helping the Russians, cleaning out cryptocurrency wallets, engaging in high scale cyber fraud, conducting operations like Sony, but that it didn't have nuclear weapons, do you think that we would be treating them with such kid gloves? I don't think so.
Nicole Prolorath
When I first started digging into North Korea's IT workers scheme, there was an odd comfort in believing these workers were mostly there for the paycheck. Yes, the salaries still funded North Korean nukes, but at least the workers themselves didn't appear to have a more destructive mission. At least that's how investigators understood it. Then here's Mandiant's Chief Technology Officer, Charles Carmichael.
Charles Carmichael
My initial assumption was that these actors had to have been doing something malicious. We knew that they had access to production code, production systems. We knew that they had the ability to insert backdoors into a variety of things. And we very deliberately looked for evidence of that malicious activity. And we found none of it over hundreds of investigations. And what we assessed was that these Actors are just collecting a paycheck.
Nicole Prolorath
But as more companies grew wise to this scheme, they've started hunting for North Koreans in their workforce. And the good news is they're finding them. Companies are starting to look for signals we've surfaced throughout this series. Inconsistent identities, coached interviews, strange login patterns, laptop farms, a last minute change of address, keystroke latency, and workers who don't quite match the person they claim to be on camera. And that is where Rob Joyce, the former head of NSA's Cybersecurity Directorate, told me, defenders may actually be reclaiming the advantage.
Rob Joyce
I actually think the North Korean problem is much more solvable than, than the generic intelligence asset deployed into a company. Why do I say that? Because these are all remote workers. So I was at a conference just this week where people were talking about the tools they've enacted to stop remote workers from getting into their employment chain. They're doing things like taking a picture on the video interview and then using that when the person shows up and is online at work to see if they've changed in any appearance or haven't kept a consistent, consistent story. Others are insisting on a one week onboarding where you come in and you've seen things like technical capabilities, looking at the latency of keystrokes. So the fact that they're remote workers is a reliability. And I think the industry will adapt and get much stronger at detecting and preventing this.
Nicole Prolorath
At companies across America, cybersecurity teams are on the hunt for red flags and behavioral tells. But as companies screen for these red flags, North Koreans are landing fewer jobs. Companies who hired them are firing them faster, but the quotas remain. And so do the regime's financial expectations. The punishment for workers who fail for their families, it's still there. And that's where the danger lies, because if the paycheck disappears, something else will have to get monetized. And incident responders, they're seeing that shift. Here's Charles.
Charles Carmichael
Again, things changed in 2024 as more and more companies disclosed that there were North Korean IT worker problems. And as companies became more aware of the problem, they started doing a much better job of blocking and finding these North Korean IT workers. And so the problem for the IT workers is that years ago, they would hold a job for a year or two years and they would have multiple jobs. Now or in the second half of 2024, they struggled to hold jobs. They might have gotten a job for a few days and then somebody noticed that something was going on and then they were terminated. And so they needed to find a way to supplement their income. And for a very small number of our cases, under a dozen, we saw that there was some element of extortion by the North Korean IT worker. The individuals who were terminated would tell their supervisors that if you don't pay me my sign on bonus, I'm going to take all this data that I got access to through my job and I'm going to publish it on the Internet. We didn't actually see the publication of the data, but we saw the threats fast forward. We saw more and more aggressiveness by these IT workers demanding money. And in the most egregious case that we saw, we saw a brand new Persona send emails to a number of victim organizations saying, I've hacked into your network. I've stolen your data. Here's a sample of the data that I stole. And in those investigations, what we found was that that sample of data exactly matched the information that a suspected North Korean IT worker had taken six months prior to now. From our perspective, it felt like these individuals were learning how to extort companies.
Nicole Prolorath
That last line is one that should make every company sit up. Because this is no longer just about North Korean workers collecting salaries under false pretenses. It's about the data and access they gain along the way and what happens to it when the lie collapses.
Charles Carmichael
By the end of 2024, we knew about hundreds of Fortune 500 companies that had unintentionally hired a North Korean IT worker where they lost a fair amount of data. Because these employees, once they were caught, they didn't return their laptops. In most situations, they kept their laptop, had whatever data that they needed. So that data was out the door. It was gone. And our fear was throughout 2025, possibly some of this data that was taken could show up in the future. Could this data be used to facilitate future attacks? It absolutely could be used.
Nicole Prolorath
For years, there seemed to be a clear division of labor. The IT workers earned money. The hackers stole it. But by 2024, that line had blurred. Researchers started catching handoffs between the IT workers and the elite hacking units. The walls were breaking down.
Michael Barnhart
Not all IT workers can be hackers. Every hacker at any point can be an IT worker. And that's a very important thing because we've seen them interchange at Times.
Nicole Prolorath
That's Barney, aka Michael Barnhart, DTEX's lead insider intelligence analyst. He admits that this overlap makes it harder to track their ever evolving strategy.
Michael Barnhart
I want them to be in tiny little beautiful buckets, and I can just be like this one does this and this. But that's by design, too. Now, the thing that's very interesting is, like, for the IT working force, there are several levels. You've got your IT workers that are just completely revenue generation, and they're like, very low level. Like, it's like slave labor. The human rights elements for them is really, really. It's terrible. And then you have your more elevated ones. The elevated ones always seem to be on those crypto units. And it's interesting because they get certain privileges. But the IT workers that are embedded with the actual hacking groups, or at least assigned or associated with them, are very interesting.
Nicole Prolorath
What Barney started seeing in 2024 set off alarm bells. For the first time, he was catching communications between North Korea's remote IT workers and the elite hacking units he'd spent more than a decade tracking. Groups like Undarial, the hacking unit behind Sony, and Ransomware assaults on US Hospital hospitals, and Trader Trader, the North Korean crew behind Bybit and the crypto heist. They were talking.
Michael Barnhart
It's something that blew my mind because we started seeing IT workers in their operations, and Dariel should not be talking to these IT workers. And I remember just sitting there, like, what is going on here? Like, is this wrong? What is this? And you start peeling the onion back and you say, oh, all these other accounts are all IT workers. Oh, these are all the hacking group. And I'm like, okay, so they're just with them, right? Like, no, they're actually helping them with operations. Some of these hacking groups are actually managers, and they're overseeing some of these IT working teams and helping each other. And that's when I'm like, okay, we need to sound the alarms bad. The problem was, at that time, it was sensitive and sometimes classified. So we had to wait like a year and a half until we'd actually see this stuff happening out in the open. And then we're like, now this is actually coming to light, we can start talking about this more. But once we did, it was just banging on the trash can lids. Hey, everyone. Because that's when people started to take note. Like, hey, they're not just revenue generation. And then suddenly, it's almost like this Andariel group was like, hey, we want to get into all these organizations. We have IT workers at these organizations. Why are we not abusing them? Let's use them as the human backdoor. They were the first to do it. And now you see all the other groups doing similar things to leverage the IT workers in a malicious way. So they're watching what they're doing.
Nicole Prolorath
Barney isn't being hyperbolic here. Just remember what the North Korean defector told us. Computers had monitoring software installed, and a supervisor lived on site with us while continuously observing activity.
Michael Barnhart
All that information is going back to the Ministry of State Security program managers, his overlords. There's also cameras all around the rooms, too. Now, remember these hacking groups, they're now managers for these teams. So they're watching in the background. He's gonna be like, hey, I want you to come over here and look at what this one's saying. Look at what he's doing right here. We can use this. The hacking group is taking the information from the IT worker to. To weaponize it against XYZ. Org thereafter.
Nicole Prolorath
This is the nightmare collaboration. The workers get inside, but the hackers inherit their access. And the threat doesn't stop. When companies fire these workers long after they're fired, the possibility for damage remains. Here's Charles again.
Charles Carmichael
They don't forget about the data that they've stolen in the past. They don't throw it away. They keep it. They leverage it. They come up with really creative ways to use it down the road. So information that we've seen stolen years ago, I anticipate seeing being used by the adversary years from now. They will continue to build upon the information, the infrastructure, the access that they've gained over the years.
Nicole Prolorath
One of the challenges investigators face is something John Holtquist, who leads Google Threat Intelligence, calls the soda straw problem. It's something I faced as a journalist in this space, too. When you look down the hole of a soda straw, you only see a tiny slice of the world around you. In any given moment, we're lucky to catch one attack. But by the time the full picture of a campaign comes into focus, years have passed. The data's gone, the intellectual property's gone, the access has already been established, and only then does the full motive become clearer.
John Holtquist
We have to recognize that we have limits here. There is this lurking risk that we have to be very clear about. And so I fully suspect that if they are in the right system, that they're going to do a handoff or at least capture that data and pass that along. And even if we haven't seen it, right, and we have to recognize that we have limits here. I have to believe that this group is not so insulated that they can't bother to pass things backwards. Right? And if they find something of value, they can't believe in a state like North Korea, you're not under some kind of very serious Order to not pass something that you think is a value to the regime.
Nicole Prolorath
At the end of the day, these workers aren't just workers. They're foreign operatives working at the behest of an adversary. In a hacking context, the IT worker's day to day is reconnaissance. The data they glean, the source code they access, even build. In some cases, it's exactly what hackers seek. In the first half of the kill chain, the exfiltration or detonation might not come until later, but we have to assume it will come. Here's Rob Joyce again.
Rob Joyce
They are going to turn that insider access from a revenue paid salaried position into an insider threat position, so an employee can become a foothold to follow on operations.
Nicole Prolorath
And as we've learned, these IT workers, they're everywhere. Here's Barney again.
Michael Barnhart
They have placement access globally. I mean, they are everywhere. Have they ever done. Has an IT worker ever done it? Yeah, they've done destructive attacks, they've done stuff on the inside. So really what we have now is a worldwide chess game. And they've put all their pieces in place. Now, they're not really in an armed conflict right now. I know they're always kind of fighting in the grave space, but if push comes to shove, you have thousands and thousands of organizations at your disposal that you can start blowing up from the inside.
Nicole Prolorath
Listening to Barney, I couldn't help thinking back to our first season. Then we were talking about Chinese hackers quietly pre positioning inside America's infrastructure. Now we're talking about people, people with legitimate jobs, credentials, real access to source code. The crown jewels, our most critical infrastructure in some cases. I mean, for heaven's sake, don't forget we found one of these North Koreans working at a US nuclear utility. And this may actually be the more insidious form of pre positioning. Here's David Singer again.
David Sanger
For the IT workers, there's no greater sort of way to break into a system than to have somebody in there who's got legal access already. Right. It's the same reason that the Soviets used to try to put spies inside the CIA and the counterintelligence operations started to IT because computer systems are dynamic and the employees are likely to have access to the most up to date passwords. They'll understand the systems better. So this was a really smart strategy. And one of the things that actually most strikes me is that the Chinese, as far as we know, have not replicated it yet. But somebody will.
Nicole Prolorath
That's the part that should give us all pause. North Korea built the playbook but they're no longer the only ones using it. Here's John Holtquist again.
John Holtquist
There's ample evidence that this insider risk thing is definitely not just a North Korea problem. Right. I think they, let's say they scaled it up, they industrialize the insider risk problem. But I think it'd be wacky to assume that they're the only ones doing this stuff. Right. There are so many countries who have a strong interest in placing insiders in organizations all over the world. That's been going on since, I don't know, since there were city states in the middle of the desert, the height of civilization. North Korea has proven to intelligence organizations around the world that it's very possible to gain access this way. So for high value targets, the insider risk is stronger than ever. I think that we went through this period where we just kind of forgot how to vet people. We increased remote work, at the same time decreasing vetting people. It's not the recipe for disaster. The good news from all this is I think we've had to revisit a lot of those processes.
Nicole Prolorath
But if that's the good news, here's the bad. North Korea's playbook. It's spreading with a troubling twist.
Ryan LaSalle
I thought stories about North Korean IT workers were pretty extreme. And it's gotten weirder because it's actually happening in person, in country.
Nicole Prolorath
That was Ryan LaSalle, CEO of Misos, who by now should sound familiar. It's been four years since NISOS answered that first call from a Fortune 500. But today, after a steady stream of these infiltrations, the calls have been changed. NISOS is increasingly being asked by companies and their investors to vet new hires at the front door, not just investigate them after the damage is done. And what they're finding sounds a lot like deja vu.
Ryan LaSalle
So we help one of our clients vet all their employees. And in this case they had another one of these recent hire. Something seemed off about it. Their spidey sense was tingling. They didn't know what was going on. And we were doing the diligence anyway. When we looked into the person, they had a long history in the US but they'd actually come from Iran. There's a lot of people in the US working who have come from Iran and are bringing great talents to the country. This person, however, had a weird gap in their life. There were some gaps in their education, there were some gaps in their work history. Essentially they disappeared from the world for about nine years and all the digital trail went cold. And it was not even Clear that their name was the same early in their life as it was later in their life. We came back to them and said, okay, their work history in the US Checks out. Before they get to the us There's a nine year gap that we can't attest. They said, thank you very much. They went and took that to some of their partners in law enforcement and the US government helped them figure out who that person was. The US government looked at him and said, oh, this guy is actually an IRGC plant, an Iranian plant in the us we need to get him out of the country. And they expelled him from the country.
Nicole Prolorath
This Iranian spy wasn't just working for any old company. They infiltrated a startup that while based in the US was actually run by people from Israel. Iran's key adversary.
Ryan LaSalle
Part of the Israeli diaspora of startups that are doing like really cutting edge work and expanding into the US and globally. And they're having to think really hard, who are they hiring and the people that they're bringing in who may actually want to do them harm because of who they are, not because of what they do.
Nicole Prolorath
And this one Iranian spy, he wasn't the only one they found.
Ryan LaSalle
Two times now for one company, we found IRGC plants, the Iranian Guard Corps, the hardliners who are running the country, putting plants inside those companies.
Nicole Prolorath
Two suspected Iranian operatives trying to land jobs at the same company in the span of a single year. A company that knew to ask the right questions, call in the right investigators, had connections to law enforcement. Now zoom out. Think about all the companies that don't share that same level of paranoia or their connections. The real question now is how many of these plants are still inside. And unlike North Korea, Iran isn't primarily motivated by revenue. If its previous attacks are any indication, its primary motive isn't just espionage. It's retaliation and destruction. Also blamed on Iran. Recent hits on Saudi Arabia's state oil company Aramco and Qatar's natural gas producer rasgas that disabled 30,000 computers entirely.
Rob Joyce
CNN has learned thousands of employees at Sans casinos in Las Vegas and Bethlehem, Pennsylvania had their computers hit. Iran is suspected to be behind the attack.
Nicole Prolorath
Iran has a long history of destructive cyber attacks. Saudi Aramco in 2012. Sands Casino in 2013. Two attacks that paralyze these companies. And this year, Iran's hackers resurfaced with the same destructive playbook, this time aimed at a major US medical equipment company. Stryker. A massive cyber attack knocking out the
Michael Barnhart
network for medical device maker Stryker.
Nicole Prolorath
Disrupting services across company devices.
Charles Carmichael
A pro Iranian Hacker group took to
Nicole Prolorath
social media to claim credit for that attack. This was a devastating attack. I spoke to a Stryker employee who tells me they watched some of their computers and iPhones get wiped out by hackers in real time. All that data gone. The IT worker playbook looks very different in Iran's hands. And what's troubling is that investigators are starting to see North Koreans actually recruit Iranians to their IT worker scheme. Here's Barney again.
Michael Barnhart
Even in some of the recruitment pitches that you see North Korea doing, they actually have verbiage where they talk about, hey, we're both sanctioned. We're both in this struggle bus together. I need money, you need money. Why don't we work together? And in the direct collection efforts that we see across, our partners, they're seeing it too. Iranian facilitator this, Iranian facilitator that. It could be a laptop farm. It could be an identity brokerage. But you are seeing groups, North Korea, uniting the criminal underworld.
Nicole Prolorath
At times, even the Nigerian prince scammers are at it. They're all borrowing the model. Now, cybercrime groups not in North Korea are like, oh, wow, that's smart. Let's start doing that.
Michael Barnhart
Absolutely. We've got North Koreans using Nigerians as their subcontractors. We've also got Nigerians just being like, we're gonna do this ourselves. So again, that prince. The Nigerian prince scam that came back, it's almost like he's back. He's back, and he's got all his friends here to work with us now. The problem is, is that they're adapting. Anything that we do, the criminals are adapting so quickly. So by the time you get information out, by the time this comes out, they're going to be doing something even different. North Korea will definitely listen to this podcast or get the reporting that comes off of it and adapt their tactics.
Nicole Prolorath
North Korea industrialized the IT worker model, but pulling this off still requires people and manual labor. Elaborate fake identities are hard to craft. Passing a screening interview takes time, technique, and tact. Charming laptop farmers recruiting Americans to show up for your drug test. It's a tough gig, to say the least. And for some, writing convincing English is challenging. Until now, Artificial intelligence has helped cyber grift reach new heights. AI didn't invent this playbook, but it removes almost every obstacle to running it. And if it isn't abundantly clear by now, North Koreans aren't just early adopters. They're pioneers with crypto. And now AI. Here's John Holquist again.
John Holtquist
Interestingly, they were like the early adopters of AI, because the first applications of AI were really in the social engineering space, right? What it was very good at at the beginning was fabricating content, right? That's like you started off with fake pictures, right? And then it was sort of fake text translating things, right. There's a whole family of third party apps that are based on this technology that offer very specific use cases. So we could see them using it to brush up their resume or their cover letter. One of the big ones we could see them use it for was faking identities, right. As AI has gotten better, we could see them progress from these static uses to these dynamic uses. So not an image, but a video, right. Not just like a single translated document, but a conversation where they can essentially do multi turns. And that's really powerful if your play is social engineering, right? Because you imagine these guys are from Pyongyang and they're computer nerds from Pyongyang. So they've got like two strikes against them and their job is to go out, pretend to be an HR person from like California, right? That's a huge lift. Imagine if you're like, you know, you live in Pyongyang, your accent would probably be a dead giveaway on some of these scenarios. So you would use deepfake voice to cover that. You know, one of the incidents we saw is we could see them essentially use deepfake video to convince a person that they were a cryptocurrency executive. Right? And so the game is, I think they reached out to a compromised Telegram account, set up a fake zoom call. They get into the fake zoom call, they've got this deep fake video, and then the ploy is there's something wrong with the audio here. I'm going to walk you through some technical instructions on how to fix your audio. Those technical instructions are essentially like malicious instructions. Next thing you know, you've infected your machine. And so the deepfake stuff is showing up more and more and we could see them sort of screwing around with it in places like Gemini. It's been a huge uplift for their social engineering capabilities.
Nicole Prolorath
Deepfakes deserve a moment here. And for that I'll bring in my friend Hani.
Hani Farid
I am Hani Farid. I am both a professor at the University of California, Berkeley, soon to be at Dartmouth College, and I'm the co founder and chief science officer over at Get Real Security. I focus on authenticating digital media from images to audio to video.
Nicole Prolorath
Okay. And not to make you blush, but you're sort of the world's foremost expert in deepfakes. But you were studying this long before North Koreans started using this in interviews. Give us the state of place. Where have the deep fakes come into play?
Hani Farid
So let me tell you some of the things that we have absolutely been seeing. We have seen recordings where it is absolutely a deep fake where somebody is driving either a new face, eyebrow to chin, cheek to cheek of somebody else to conceal their identity, or they're driving an avatar so they're talking in front of a camera and speaking in front of a microphone. But what you're seeing is somebody completely different. And we have seen that as well. We at Get Real have seen all of these in various forms because. But it's also shifting. We're seeing the tools get more sophisticated. We're seeing as they get detected, they are adapting.
Nicole Prolorath
Deepfakes are showing up more and more and people are getting savvy to them. Like Ilya Krugman, the founder of the Vancouver branding agency, who posted on LinkedIn that he was looking for a developer earlier this year. He hears back from several candidates, one of whom looked perfect. So he gets on a zoom with this guy, Nikodem Blonda, who's young, blue eyed and at first glance looks Polish.
Charles Carmichael
Hi, Ilya.
David Sanger
Hi.
Ilya Krugman
Yeah, so we jumped on. Didn't get too much of a smile or anything like that was very morose. Face didn't really move too much. I was like, okay, Eastern European, you know, I'm kind of used to that. I have family in Poland. So one of the first things I started with was, oh, you're in Poland. I was just there. My stepfather's from Warsawa, so.
Hani Farid
Oh, really?
Ilya Krugman
Oh, we were in Krakow.
Nicole Prolorath
Warsaw.
Ilya Krugman
We went to Moldova and then we went to Berlin after.
Nicole Prolorath
Oh, nice.
Hani Farid
Yeah, I live in Lublin, by the way.
Ilya Krugman
Dublin. Lublin, yeah. Yeah, Very nice place. So tell me about yourself. When talking to him and looking at him, I didn't really clue in at first. I didn't think anything of was about a minute and a half or so into the conversation, I asked him, please explain your history and tell me where you've been in your career.
Nicole Prolorath
So I studied at Atoz, mostly focusing
Hani Farid
on the web, web development and also some learning, good practices.
Nicole Prolorath
And then I, after that I joined,
Ilya Krugman
you know, Vix and as he started
Hani Farid
to speak, so I, I was helping the clients establish some coding standards.
Ilya Krugman
I couldn't put my finger on it at first. And then all of a sudden it dawned on me. I'm 90 seconds in. As he was telling his whole story and Then I was like, the way he's saying this is kind of weird. Like, why isn't he speaking like an Eastern European? And then I like, kind of closed my eyes and it dawned on me that this is a pure Korean accent. You can see me laughing in the video. I'm like, this is, this is too comedic not to ask.
Nicole Prolorath
Mid interview, Ilya calls it out. Can I just stop for a second?
Ilya Krugman
Why do you have a Korean accent?
Nicole Prolorath
In the blink of an eye, the call drops. Ilya is left smiling. With a little shake of his head. He actually figured out what was going on pretty quickly. He said he'd read articles about North Korean IT workers. And after his post went viral, he's been hearing more and more from friends who've had experiences with DPRK deep fakes.
Ilya Krugman
My friend Emily is a professional recruiter and she told me that they get four or five of these types of people every week and they identify them with a tag called FAF fake as.
Nicole Prolorath
The problem is the dead giveaway here, that Korean accent, it's disappearing. Thanks to AI, freely available tools can now modulate accents in real time. And yes, there are legitimate use cases for this, helping people who've lost their voice, making speech clearer across languages, protecting people from harassment or identification online. But North Korea has found a darker use case, using AI to sand down the one clue interviewers were trained to listen for and make a state sponsored operative sound like any other remote worker on Zoom. Here's Hani again.
Hani Farid
We've also seen voice modulation, so deep fakes have many flavors. It can be visual, but it can also be auditory. So one of the things that we've been seeing is real time voice modulation where the accent can be concealed. So it doesn't have that very strong accent. So the visual is real, but the audio is manipulated. You know this, Nicole. I mean, you've been doing this for longer than I have. So they're very clever and they are adapting to the threats and they're adopting the new technology as it's rolling out very, very quickly.
Nicole Prolorath
Do you know what tooling they're using?
Hani Farid
Yeah, I'm not going to give you the names of the tools because, you know, that's still not the best idea in the world. But I would tell you they're called voice modulators and they work in real time with a few millisecond delays. So essentially what happens is I'm talking right now into a microphone. Deepfake technology grabs that audio, modifies the voice to change the accent or the intonation and then shoves that into the video streaming and you can do that in more or less real time with less than 50 millisecond delay. And there are many, many commercial open source technologies for doing this. It's called voice modulation. It's very effective.
Nicole Prolorath
By the way, I have seen some of these interviews and some of them have even gone viral where it's clear they're using a deep fake. Someone says, put your hand in front of your face and they refused to do it. At what point did you discover, oh, they've managed their way around this.
Hani Farid
Here's something very dangerous I should point out, because I've saw that same viral video and you saw somebody saying, oh, put your hand in front of your face and it didn't work. And now everybody thinks, oh, just have them wave their hand in front of their face. And now I'm safe. No, no. Even if that was true today, it sure is not going to be true three months from now. So I can tell you that the newest technologies for creating avatar and face swap deepfakes don't work. And the reason they don't work in the old school deepfake, what the technology would do is simply identify where the fake was and track it over time and either map a new face on or drive another face. And when you obscured the face, the face tracking would get confused. But the new versions are what's called occlusion awareness. They are aware when something is in front of the face and they simply factor it out and they can track the face even when something is occluding. Now, if you really occlude the face, really block like 80% of the face, it will start to break down. But the hand waving in front of the face just doesn't work anymore.
Nicole Prolorath
Okay. We were able to get inside one of these discord channels that this one North Korean cell of 22 people were using to manage their operations. And we would see them say, hey, I can't show up for this inter. Can someone else swap in? Or I can't show up for this zoom meeting I need to do. Can someone swap in? So I imagine this is where deepfake technology would be incredibly useful.
Hani Farid
Yes.
Nicole Prolorath
Is that how you're seeing it, not just for interviews, but sort of used in these jobs?
Hani Farid
Yeah, this is really important because there's getting the job right. And in some ways that's probably easier. When I call somebody up to do an interview, I don't know what they look like, I don't know what they sound like, I don't know what time zone they're in. But once somebody's been on board and I've been talking to them for six months, they, they have to show up for the call. And so now you can have an army of people who are swapping each other out. Right, and impersonating each other and absolutely, that's where deepfakes can be incredibly helpful. Cause I can just change my identity. And by the way, there are cross racial facial identification biases where within your racial group you're actually pretty good at identifying people. But across racial groups who are less good at it. This is a well established. So you can even see where it doesn't have to be quite perfect. Particularly if the quality of the video is not very good and there's eight people on the call and your attention is being dragged across eight different panels, the chance of somebody noticing that and you step away from the camera a little bit to make yourself a little bit smaller, you can get away with anything. And so these syndicates, if you will, these aren't lone wolves. These are extremely organized and when they work together, they're much, much more powerful and dangerous.
Nicole Prolorath
And AI isn't just making North Koreans better liars, it makes them better hackers. One of the few areas where North Korea's lagged behind the world's top cyberpowersthe us, Israel, Russia, China was in discovering brand new software vulnerabilities and weaponizing them into exploits. The so called zero days that can slip past modern defenses before anyone even knows they exist. North Korea's strength has never been cutting edge vulnerability research. Its strength was extraordinary persistence, relentless social engineering, taking known techniques and operationalizing them at scale. But AI threatens to erase that distinction. Here's Broadcom's Eric Chen, whose primary concern now is how AI is erasing the barrier to entry. For hackers and nation states like North Carolina, Korea.
Eric Chen
But that is our worry. When AI shifts from being passive to active and they're at the verge of it already, and we have demonstrated already with the existing AI, no, no new technology needed, that we can conduct an attack end to end and I have to type hack Acme Corp, maybe three words, right? And that could happen, that is our worry with AI is when it becomes very active and the agents become very sophisticated and then the barrier to entry becomes very low. I don't even have to research and learn about how this thing works. I just tell it to do it on my behalf.
Nicole Prolorath
These days, the same frontier models that can generate flawless English, convincing resumes, real time translation chatbots, they can also Analyze source code, uncover vulnerabilities, write exploit code, and increasingly chain those exploits together with little or in some cases no human guidance at all. That's a capability North Korea has never really had. But soon it will. Which brings me to Mythos.
David Sanger
Anthropic is calling its new Claude Mythos a potential cybersecurity reckoning, saying that the
Nicole Prolorath
tool can identify so called zero day vulnerabilities. Unless you're one of these people who's just buried their head in the sand on AI, you've probably heard about Anthropic's newest frontier model, Mythos, and the controversy surrounding its exploitation capabilities.
Hani Farid
Use this is the latest and greatest Anthropic model and it is capable of executing not just finding a bug, but exploiting that bug, going through all the links of the cyber kill chains to successfully execute attack and doing so autonomously.
Nicole Prolorath
AI company Anthropic is withholding the release of its new Mythos model. The company says some of its AI
Michael Barnhart
capabilities are too powerful.
Nicole Prolorath
Anthropic says it's Mythos preview presented unprecedented cybersecurity risks.
Eric Chen
They found thousands of vulnerabilities in every
Nicole Prolorath
major operating system and web browser. Anthropic made the unusual decision to restrict access because of what the model could do. The US government followed suit by restricting its export. Anthropic then pulled Mythos and another model, Fable altogether.
John Holtquist
The US government, the Trump administration has now removed these curves suburbs on Anthropic's most cutting edge model. So Fable 5, along with Mythos 5, they will now be from today be able to be accessed beyond US shores. So what that means again in terms of how a Trump administration has gone from being very less a fair in terms of how they control these models to hang on a second, this is potentially dangerous. The potential for these models to escape their guardrails. They appear to now have the Commerce department in the U.S. some assurances from Anthropic to the point where they can remove these export controls that came as such a shock when they came into force in June.
Nicole Prolorath
And while I have lots of thoughts on how this went down, the relevant point here is that AI has reached a new level of capability and no export control or ban is going to stop this train. Mythos won't be the last. Soon every frontier model, if they don't already, will have Mythos level of exploitation capability. And eventually the open weight models will too. Certainly within a year, months even. By some projections, this is the beginning of a new era of automated exploitation. And the capabilities they're very real earlier this year, I sat down with Anthropic's lead red teamer, Nicholas Carlini, to understand what Mythos can do. Here's a clip from that conversation.
Nicholas Carlini
The basic setup is we tell the model we want you to find a bug. This is the code base you're looking at. You have complete access to the machine. Go forth and find something for me.
Nicole Prolorath
As for what Mythos went forth and found, well, most of it still isn't public because in many cases they're still waiting for a fix. But I asked Nicholas to describe the capabilities in plain English.
Nicholas Carlini
So, on most web browsers, on most operating systems, we have full exploits. The kinds of things where you visit a webpage and then the model goes and accesses your bank records. The kinds of things where, on most operating systems, an unprivileged user can become administrator. The kinds of things where if you give me your locked phone, I can download the pictures off of it without unlocking it. These are the kinds of things that we have, which are sophisticated exploits that people used to think of as only the kinds of things that tier one adversaries could build, that the model is producing for us. And it's like me and a handful of other people at Anthropic who are doing this. None of us who are doing this are experts in this and would have absolutely no hope of doing this unassisted. And over the course of a couple of weeks with the model, we found dozens of these kinds of things.
Nicole Prolorath
The remarkable thing about Mythos is that Anthropic wasn't even trying to build an exploitation model. They trained Mythos to write code. The exploitation only emerged as a byproduct. But soon models will be deliberately trained, trained, fine tuned and finessed for exploitation. And when that happens, every human mistake becomes discoverable at machine scale. Every misconfiguration, every unpatched vulnerability, 24 hours a day across every time zone without human fatigue, and no export control is going to keep that capability out of North Korea's hands. Here's John Hulquist again.
John Holtquist
Everybody shifts with this stuff. Like, the high level guys are going to get even better. The low level guys are going to be doing stuff that they couldn't do before. I'm worried that they can shift away from social engineering and start moving into this play where they're focused more on exploits, that vulnerability capability, which we've seen North Korea try to get to, but it's been pretty limited. I feel like one of the repercussions of the ways that we're going to see them move is into that space, Right? And I think North Korean and Iran are potentially on the edge where they can make that shift to this higher level of play. At Google, we had this program called Big Sleep about. We started about two years ago, and we started using AI defined vulnerabilities. But to me, that was an alarm bell. We've got really smart people, but it won't be long before labs are getting set up in Pyongyang where they're like, trying to do the same thing. I believe that process has already begun. We found this year a criminal actor who was using a zero day built with AI. If the criminals are doing it, I'm fairly certain that they states are doing it. I think one of the weird things about this too, is that we're not necessarily going to see the stuff that's going on in Pyongyang, right? We get to see the end result. And we may not know that it was created with AI. And so my suspicion is we've already found things over zero days that were, were created this way. We just don't have the evidence.
Nicole Prolorath
And here's Rob Joyce with a lesson we've come back to again and again this season.
Rob Joyce
The North Koreans think about cyber operations from end to end. They look at the objective and they don't put any constraints on how they get to the objective.
Nicole Prolorath
Sanctions, export controls, a lack of Internet. If North Korea's proved anything, it's that there's no constraint that they aren't able to bypass. We can manufacture a few consequences, but they just keep getting better, more access. They're running a masterclass on crypto heists, and they're no longer just raiding the system from the outside. In some cases, they're helping build it from the inside. We've got several North Koreans working at crypto startups. It's clearly a priority. And again and again, crypto is where the lines blur fastest between the IT workers who get hired and the hacking teams that come in just behind them. And as crypto goes mainstream and moves deeper into the financial system, North Korea won't be chasing it. They'll already be there waiting inside.
Michael Barnhart
You're kind of nailing it right now. And this is really my biggest fear, because it's not that, you know, they're hacking crypto exchanges, really. They were there from the beginning. They're not hacking these things as much as They've developed these Web3 protocols. Whenever you and I first found out what a bitcoin was, I mean, I'd like to think that we were pretty cutting edge on some of that stuff. But even when you and I first found out what it was, was they had already absolutely masterclassed, they had already handled to begin with. When you see these guys inside these forums, they're not asking questions like, hey, what is Ethereum? What's this product? They're asking very in depth, detailed questions. They already know exactly what they're looking for. And they've been a part of that development cycle all the way from the beginning. And I think this really plays into who they are as a whole. Because when you think of emerging technologies, when you think of everything new coming out, criminals. And that's what North Korea is, it's a criminal nationwide syndicate. They will always latch on to these things before anyone else will.
Nicole Prolorath
They're early adopters, but they're also patient craftsmen. They spend years mastering whatever gives them an edge. And the next generation of tools is already falling into reach. AI systems that find vulnerabilities, impersonate people, scale fraud, and exploit human mistakes without fatigue. The people who study North Korea for a living have no doubt they'll master those tools too, and turn them back on us, either from the outside or through the access their IT workers have already gained. And that's why they worry less about the attacks we've already seen and more about the ones we're only beginning to imagine.
Eric Chen
The thing with North Korea is every time we see them, they're doing something new and something different and quite frankly, something kind of wild. And when we see those types of attacks, we might not initially know for sure yet it's North Korea. But our gut instinct always when we see that kind of thing is this is a weird nation to state attack. Who would do this? Oh, probably it's North Korea. So North Korea is a wild card. Anything could happen with North Korea.
Nicole Prolorath
That's a wrap on To Catch a Thief. Follow To Catch a Thief to make sure you don't miss the next episode. And if you like what you hear, rate and review the show. To Catch a Thief is co produced by me, Nicole Prolorath and Rubric in partnership with POD People with special thanks to Julia Lee.
Podcast Summary: To Catch a Thief: North Korea On Our Payroll
Episode 6: The North Korea Model (July 14, 2026)
Host: Nicole Perlroth | Rubrik | Pod People
In this riveting season finale, Nicole Perlroth unravels the global and technological evolution of North Korea’s “IT worker” operation. The episode dives deep into how not only North Korean operatives, but other nation-state actors and cybercriminals, have adopted and adapted the model of infiltrating companies through remote work—leading to data exfiltration, extortion, and the collapse of boundaries between insiders and adversarial hackers.
The episode tracks the flow of stolen money to North Korea’s nuclear program, explores chilling case studies of infiltration, exposes the synergy between sanctioned regimes, and spotlights the accelerating threat posed by AI-driven deception and exploitation in the hands of adversaries.
This episode spotlights how North Korea’s playbook for workforce exploitation is morphing into a global template, rapidly amplified by technological leaps in AI. With clear-eyed reporting and jaw-dropping case studies, listeners walk away understanding that the real threat is not just in the hacks that make headlines, but in the invisible, persistent reach of adversaries who may already “be inside”—with AI promising to dissolve the last barriers to large-scale digital infiltration.
Missed this? Catch up—you’ll see the next era of cyber conflict won’t just be nation vs. nation, but human vs. adversary, machine vs. machine, and trust itself on the line.