Detection Dispatch (Alex's Version)
Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.
Detection Dispatch (Alex's Version)
Your Dream Job Offer Might Depend on You Cloning/Running Malicious GitHub Repos feat. Tim Peck
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The job market is shitty right now, and threat actors are exploiting exactly that. Developers are a hot target, and it cuts both ways: they'll come at you as a fake recruiter sending a "coding test" straight off GitHub, or as a fake candidate using a stolen identity to get hired and work the inside. Cloning and running a malicious repo is now just part of the interview process. Doing a human CAPTCHA to prove the person on the other end isn't AI is no longer optional.
Tim Peck (Director of Research, Detections.ai) joins Dispatch to break down DEV#POPPER and the broader Contagious Interview campaign, still active, still evolving.
In this episode we get into:
- Why this attack starts with the human and why you can't train that instinct away
- Word Wrap Obfuscation: hiding payloads past the edge of the screen so scrolling through the code looked clean
- Why devs specifically get targeted: the power-full/shell languages baked into the job function itself, affiliation with crypto wallets
- Fake candidate red flags: brand new LinkedIn profiles, awkward response lag, 4am emails, resume inconsistencies
- What detection helps assuming breach
Follow Tim's work on:
- Detections.ai
- https://www.securonix.com/blog/analysis-of-devpopper-new-attack-campaign-targeting-software-developers-likely-associated-with-north-korean-threat-actors/
Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.
Welcome back to Detection Dispatch, the show where we go beyond the alert and into the craft of the engineers building the detections that actually hold up under fire. Today we're talking about one of the most unsettling social engineering campaigns that came out of the DPRK engineers. One that doesn't necessarily target your sock per se, it targets just how shitty the job market is right now. And well, it's always been, I mean, obviously pretty competitive, but with AI impacting jobs and layoffs left and right, it's a pretty prime hot spot to aim at the and exploit the anxiety and the vulnerability that a lot of folks are living through right now. And at the moment where I feel like they're the most vulnerable mid-interview, where you're just like scrambling trying to impress hiring managers, that's when it happens. Joining me today, Tim Peck, director of research at Detections AI, he authored one of the original uh Dev Popper campaigns that was happening in the wild. And can you imagine that it's literally still happening in the wild as of like two days ago?
SPEAKER_01Still happening.
SPEAKER_02Literally still happening. So, Tim, welcome to the show. I can't wait to talk about fake recruiters, fake, fake home assessments. How are you? Are are you watching the World Cup?
SPEAKER_00Awesome. Oh, yeah, of course. I mean, that was a tragedy yesterday. I'm sure we were all watching with England, but at least for me, right? I guess it depends on the side you're on. But uh yeah, I'm doing great. Thank you for having me. This is something I love talking about. This is an interesting tactic because, you know, it's you know, it's like detection engineering wrapped around psychology, wrapped around threat actors, DPRK. So it's kind of like it's a little outside of the normal malware or traditional phishing that we typically see. It's a it's a attack chain that involves the human. So, you know, it starts with social engineering, you know, attacking the human versus the computer directly.
SPEAKER_02Yeah, and it's not really that all that technical. I mean, there's some technical components, but nothing all that super sophisticated on the technical side.
SPEAKER_00Right. It's kind of it starts with convincing somebody to execute malicious code on their computer. It's we see that a lot with ClickFix too, where it's you're convincing somebody to run something malicious. So it starts with the human. It's not a CVE exploit where the attackers are breaking in. It's convincing you to do something that's causing you harm.
SPEAKER_02Yeah. So definitely non-Tradesh. Before we get into that, I always love to start with how did you get into the space and what are you working on right now? Are you expanding the research of Def Popper? Because I know you started that at another company.
SPEAKER_00My previous role, yeah. So before I started with Detections AI, I was doing full-time threat research mixed with detection engineering. So I got my hands on a lot of malware. We were kind of on the forefront of the discovery side where we were the ones putting out the threat intel, looking for new malware, naming malware. So that part I really liked getting into. So we eventually stumbled upon this campaign and put out a report along with some other vendors too, kind of in that space. There were a lot of different vendors tracking it kind of all at once because at the time it was new and novel. But yeah, before Securonyx, I did some consulting work uh on the SIM side, worked with customers. Uh that's kind of where I got my feet wet with detection engineering. It was a mix of consulting mixed with improving SIM capabilities for threat detection. And so, you know, detection engineering, that's where I got the bug being able to actually catch threats. I I think at that point too, I stood up my own hack lab where you know I could kind of run my full validation cycle as well. Like, cool, I have a rule, but let's run the malware, let's run the script that I'm trying to catch. And then I was able to show my customers at the time that, cool, yeah, here's a nice rule that can catch whatever version of malware or ransomware. Here's some cool data and some logs to go along with it. So that's the type of stuff I think they appreciate because you know or rightfully so. I think everybody in the detection engineering space is a little bit suspicious, right? Like, cool, here's a rule, but you know, show me, right? Like I need the data to go along with it.
SPEAKER_02Has it actually been tested under real conditions and not just fake data or just gut feeling? And then this this is the behavior. Here's the role, but but not actually simulated.
SPEAKER_00Right. Yeah. I mean, that offers like a whole level of confidence at that point when you have that. And you know, sometimes you know you don't have that data, especially when you're on the CVE side of the house and you kind of go, well, okay, based on what I'm capable of researching, because I don't have the enterprise tool that it's attacking.
SPEAKER_01Yeah.
SPEAKER_00Here's a detection that should work. And it's a lot of times it's the effort behind it and just getting that confidence as high as you possibly can. But yeah, I mean, we're we're going back in time, you know, uh before that, you know, that's where I started my cybersecurity career was at IBM. And I believe you're an IBM or past IBM or two.
SPEAKER_01Former IBMers.
SPEAKER_00Former IBMers. That's where it all starts.
SPEAKER_01Wait, so so I gotta know. You did you work inside of Q Radar?
SPEAKER_00I did.
SPEAKER_01Okay.
SPEAKER_00So yeah. So I I started as a threat analyst on the IDS IPS side. So back when IBM had their Prevenia lineup, um, we would support that and support customers for you know processing alerts and uh a false positive tuning.
SPEAKER_02Yeah.
SPEAKER_00And then I kind of morphed my way into the Q radar side, and that was my intro to sim.
SPEAKER_01Yeah.
SPEAKER_00Which was a lot more obviously, you know, a sim is a lot more robust than an IDS IPS, so that was kind of a like gateway drug into the sim space.
SPEAKER_02I mean, what's a detection engineer without a sim?
SPEAKER_00Right. Yeah. I mean, I guess it does exist in IDS IPS. You know, you have like, you know, Siracata Snore, you know, like they were kind of all over the place. Uh you could even argue like Zeke and stuff like that.
SPEAKER_02Yeah, the Zeke. But NDR world.
SPEAKER_00But sim, I think I I'd probably argue is probably 90-95% of detection engineering space, uh with whatever type of sim that looks like.
SPEAKER_02But I feel like you would appreciate my take on Q radar, because at the time, and I'm not saying now, nowadays, because Eli Woodward is spreading rumors that I still like Q radar nowadays. I'm like, no, no, no, no, no. At the time, Q Radar was truly the only sim that in a really simplified way concatenated event traffic and net flow and even layer seven. Like it really, and for a young professional that's trying to make sense out of these properties that it ultimately affect your rule chaining logic, like building blocks, thinking things in building blocks is a fantastic way to do that, right?
SPEAKER_00Absolutely. Yeah, the content, I think it was the first sim too that had really rich context too into your environment, like with like your assets, and you can have your vault, your I I think it I think you could have your magnitude, the magnitude, criticality, severity. Yeah. So like your I think it would link into your for it's so long since I've touched Q radar, but like you could have your Vuln scanner basically report to Q radar what your technologies were. I've pulled a lot of Qualists. Yeah.
SPEAKER_02Uh-huh. Yep. It even had a Qualis dashboard inside of it.
SPEAKER_00The Qualest dashboard, yep. And yeah, no, that kind of got me into like creating rules too as well, as well as tuning and modifying them. And then yeah, my next full-time sim rule, it was pretty much just that. So yeah, I've been in the rule detection space for a while. Um I love the research side as well. You know, just getting paid to just blow up malware all day is, you know, pretty awesome.
SPEAKER_01That's a pretty sick job.
SPEAKER_00It's pretty sick. You know, I'm like, all right, let's run this ransomware. I remember this has nothing to do with what we're talking about, but like running, just seeing what would happen if you execute like 20 ransomwares all at once.
SPEAKER_02Just as Oh my God.
SPEAKER_00You're gonna have to have fun with it. Oh, yeah.
SPEAKER_02You can like Well, they would be competing to encrypt everything for each other. Like, how would that even encrypt the malware file?
SPEAKER_00They they would, and they'd encrypt each other's encryption files too. So you'd have like encrypted, encrypted, encrypted, encrypted. And what's weird is like the fast ones, the ones that are really good, like Lockbit, they were in they ended up losing because they were the fastest. So then you'd have, yeah, I was kind of counterintuitive, but I don't know. This is like the weird science we end up doing when we have access to labs and and maybe there's something to be gleaned from all this, but you know.
SPEAKER_02I think it's the pattern involvement of it all. It's uh constantly the evolution of rules. Someone who maintains a rule content library has a unique view. I do believe that, as to like what actually gets used by customers, because so many of these detection content libraries just grow stale. And you having a view of what actually gets deployed out in the wild, it really shows how good of quality that rule is. And or if there's a a new attack vector or a new uh a new thing, looking back and be like, oh, I have a rule kind of like this, and then adding on to that rule instead of building an a new one and it added a unique perspective.
SPEAKER_00Yeah, for sure. You know, it's it's the life cycle, right? It's like when to produce a new rule versus when to update an existing rule. Um and then you know, you you have so many other variables too, like the technologies involved with catching this and endpoint logs, their data sources, you know, which is more or less capable of and then when you're on the sim side, you're on the vendor side. So it's like, well, okay, what's the average customer gonna appreciate at least first before we start getting you know deep requests for coverage? But at the end, taking all of that knowledge, that research knowledge, that detection engineering knowledge is kind of what led me into my current role at detections AI, um, where I'm able to help build this product that detection engineers like myself would end up using, making it better. And I've I I haven't even been with a company for a year yet, getting up pretty close, but it's been amazing to see the amount of changes we've had, especially around the community side, where you know, we're trying to make this product as good as we possibly can for detection engineers. And like the ultimate goal is to save them time, especially when that crisis hits, right? That CDE, that attack tool, that nightmare eclipse tool, of course, that's going to be released, just having those ready based on a community model is something that's been really fun to build and watch it evolve over time.
SPEAKER_02It's been amazing to see how fast that that repo grew in in even in just in months. Like it went, I I remember being a part of the early Harrison connected me with this community at the very, very early days. And then all of a sudden I look back and now like we was like 8,000, then 10,000. I don't even know where you guys are at now.
SPEAKER_00Yeah. I don't either. I think it's up over 20.
SPEAKER_02Oh shit. Oh wow.
SPEAKER_00It's like it's like at the point where like you've crossed a threshold and it's like, well, we're not really tracking this anymore. It's just a crazy amount. But you know, we have tons of community contributions, and it's cool to see too, like when a threat does hit, you know, like that CVE. Pick your favorite, you know, like and then everyone kind of rallies together. And you know, we've been putting a lot of time and effort into Threat Intel too, because you know, like detection engineering is a reactionary field, right? We're not just building detections based on theory or something that we think might be cool. We're building detections based on something that happened, you know, a new piece of malware or a new technique that gets dropped, new TTP of some kind, right? So it's cool to see that whenever something happens in the industry that's semi or really groundbreaking, like the community kind of rallying together and rallies together.
SPEAKER_02There's no other way. If we can't all learn together like that, it it's I hate when people gatekeep to themselves. It it sucks. Like For sure.
SPEAKER_00Yeah. Yeah.
SPEAKER_02I mean that person will not get along if they do that.
SPEAKER_00Same.
SPEAKER_02Good.
SPEAKER_00Well we're all on the blue team side, right? Like let's help each other.
SPEAKER_02Exactly. Exactly. Well, let's talk about some of the ways that um we're seeing the job market get exploited because I it really is both on the faking the recruiting side of things as well as faking as a fake candidate. And I think you've covered more the research on the fake recruiter side, uh, where they post as a hiring manager, right? Real developers will apply and they'll get sent this test. How have you seen that unfold? Uh, how elaborate does that recruiter need to get? And I mean, and also, is it right to only blame DPRK? Because I feel like maybe it it's not all them. And then now they've picked up on the novelty, and other people are probably really leaning in and trying to copy that.
SPEAKER_00Yeah, it's interesting because Dev Popper is about a year and a half old at this point, which is when, you know, uh, we released Dev Popper, um, Palo Alto released Contagious Interview, ESet released another one called uh Deceptive Development. Deceptive Development. Um, it was kind of all around the same time. So those clusters were all kind of getting formed right around the beginning of 2014. It does seem like all roads seem to lead back to North Korea. I I I haven't, you know, right before this call, I kind of re-dove back into it just to kind of just kind of casually. Oh, here it is again. You know, uh it really does seem like this is just a really I don't know, strong tactic of North Korea. Whether it's 100%, I mean we can never be 100% sure.
SPEAKER_02Can never be, yeah, 100%.
SPEAKER_00But yeah, it just does seem like all paths lead back to DBRK anytime this does get resurfaced. So and yeah, you're absolutely right. This is the research I've done in the past has been on the fake recruiter side. But it can absolutely go both ways, right? With the and you you end up with totally two different threat profiles, right?
SPEAKER_02You're like oh yeah.
SPEAKER_00Uh your fake recruiter would be trying to steal your stuff, infect you with malware, whereas like the uh the other way interviewee would try to infiltrate your company. Yeah, I mean it does go both ways. So uh yeah.
SPEAKER_02It can get pretty elaborate on both sides. It's like for the fake recruiter, right? Sending you a coding test from GitHub, running the malware themselves, and then damn, you're popped, right? But and maybe it just stops there. But for the candidate, I mean, are they gonna fake their way and then actually end up working at the company and then like how long? Like how long does it have to be a good thing? How long does it go on?
SPEAKER_00And it does happen. Yeah.
SPEAKER_02Yeah. That that will that's a very elaborate, long, long game.
SPEAKER_00That's the long con. Yeah. But think about the stakes though. Like if you do gain trust inside of a company, especially for a position that would have access to internal resources, confidential information. It's kind of a gold mine without deploying any malware. I mean, it's not a thing your EDR is gonna catch, it's not a thing your sim is gonna catch.
SPEAKER_02It's no. Where do you draw the line with HR and then security? Because this is more, it still happens in the external side. There's a bunch of external documents being sent around from recruiters on the fake recruiter side, but just a couple of days ago, uh it seems like even as developers looking for collaborations opportunities, it was like a literal, like, hey, I want feedback on this cool project I'm working on. Uh, here's like a super exclusive, you know, program you can run it. Uh, and for someone who's a developer, you're very much used to running code that you didn't write.
SPEAKER_00Yes. Right.
SPEAKER_02And and exploiting that aspect of it. And then this guy's literally desperate. I mean, quite literally, he said it.
SPEAKER_00Right. Yeah. Still very fresh attack. Um it's you know, purely social engineering. And you know, you could see it both ways. With DevPaupper, we saw it was more outreach, um, right? Like LinkedIn recruiters looking for devs, temporals usually one-offs, um, like project-based type.
SPEAKER_02I I agree with this guy. If there's malicious um GitHub rebos out there, again, where is the line? GitHub should be getting involved. Vercell was like the one who helped get the the HTML kind of like the vibe-coded website of it up. There's a couple of different people involved here. Um do we do we not have brand monitoring here to see clearly this is a malicious repo? I don't know.
SPEAKER_00Oh, this GitHub in general this year has been under fire. I mean, it's shy halud. I mean, you could just go on and on. But yeah, I mean, like GitHub staging isn't, you know, especially if you're targeting devs, isn't like an unusual thing, right? Throw your code up in GitHub and have them clone and run something. I mean, that's such a normal workflow for a dev to do. It just that by itself wouldn't set off any alarm bells.
SPEAKER_02Have you done any research on maybe the structure of the repo? Because there's certain there's certain best practices that typically a good, well-architected, well-structured GitHubs are are sort of organized as. Is there any real like obfuscation or tests behind it that because it's almost it's it's really difficult to see what is a malicious GitHub repo versus not.
SPEAKER_00It is. In the case of DevPauper, it was really interesting. You would end up cloning a repo, and it was, I can't remember the type of application it was. It was some basic app. It was a Node.js app and the it would pull down multiple, multiple files, probably 50 and elaborate folder structure. And then somewhere inside one of the folders, there was a file. And if you look closely too at the folders, one of those files is a lot bigger than the rest. So that could be your first red flag.
SPEAKER_02Maybe.
SPEAKER_00Like 20 kilobytes, 25, 1.1 megabytes. You know, it's like, okay, that's a that's a big, that's a big little JS file. Uh so when you open it and you scroll through it, it didn't look like there was anything out of the ordinary, but if you paid really close attention, the scroll bar at the bottom was really long. So if you scroll way over to the right, they hit all of their malicious code way out of standard view, like 2,000 characters out of frame. I guess if you had word wrap turned on, you'd probably be like, ooh, what is that? You know?
SPEAKER_02What's going on here? Yeah.
SPEAKER_00I don't I don't know what the percentage of people who use WordWrap versus not Word wrap, but yeah, so they hid that normally out of sight, I guess, just in case you decided to take a peek at it, and it would just increase their odds of you missing it.
SPEAKER_02A very cle a clever word wrap obfuscation. I see.
SPEAKER_00Right. Yeah. So it was all purely just obfuscated JavaScript.
SPEAKER_02Yeah.
SPEAKER_00That would kick off the next attack chain. I think it called uh just the command interpreter process to download the next stage payload, and then you end up with, I think in this case it was a Python-based rat, which we didn't have a name for, but I think it's evolved into I don't know, what was that? I think beaver tail. I could be wrong. No, invisible ferret. So you you these names. These names, I you know, you gotta have some kind of fun animal in there, but we do. I think Unit 42, I think, named it that. So it's uh kind of appropriate invisible ferret, you know, you don't see it that it's a ferret. It's mulling around, yeah.
SPEAKER_02Yeah. But um well creating on the fake candidate side, I I definitely have seen this a lot where they apply to real companies, right? They use these sort of stolen and fabricated identities where that in and of itself takes kind of a bit of time, right? To build a LinkedIn profile. LinkedIn doesn't really let you obviously go back and say that you this profile was created in 2011 when we were all creating them. So that it's it's honestly a little bit more of a telltale sign. If you come in and you see a candidate and they're not verified with LinkedIn and it's a profile that was just created in 2025, that's a red flag. Why are you not using LinkedIn? Most people are doing job searching through LinkedIn nowadays, right? And so, and but these AI companies, I mean, with that, have you seen all this funding? Uh, these new startups, especially in security, they're hiring fast and they're hiring almost like two, three quick like the rounds are quick. Like they're they're they're moving super, super fast. And I think that's the point where you can exploit. Um, and they're and I feel like they're getting far enough where they're extracting some information and and these guys are pretty, pretty sophisticated people. Like I think they in order to find a good candidate to interview, they they they're probably also like looking for actual software engineers that can that can talk the talk, right? So it in in a way, it's like they're getting pretty far. Um, but it's like how far do they actually go? The Tall Tale Science is a dream resume, like eight, 10 years of experience, but then LinkedIn profile 2025.
SPEAKER_00Right. Yeah. I just decided to hop on LinkedIn, you know. Yeah. Now. Yeah. Like, I mean, you know, since we're talking about social engineering and, you know, attacking the human versus attacking the computer, right? Like it's that that would be like your first line of defense, right? Like looking at the source, doing exactly what you said, taking a look at your recruiter to make sure that this wasn't a profile that was set up like three weeks ago, who's now all of a sudden just contacting you who has two connections. You know, that's that's not a recruiter, right? And you know, especially you mentioned AI, you know, with the advent of AI, you know, it makes it a lot easier. You can just generate a billion profile pictures and just say, hey, build me out a recruiter description. Uh you know, it make it sound really nice, you know, and it it's something you could do, but AI is really good at speeding things along. Right.
SPEAKER_02It is.
SPEAKER_00At that point, you could create 12 dozen profiles and see how you do with you know using the most effective one at that point. And then when it gets banned, inevitably, because people are reporting you for spamming malware, you know, like you've got a whole bunch more thanks to the speed of AI.
SPEAKER_02I my head of ops who I he swears that he has been interviewing people from North Korea, or people that were definitely sketchy, so that there was like a lot of lag in between the questions, almost like an awkward amount.
SPEAKER_00So it's like they were typing in and waiting for the response, or probably.
SPEAKER_02It was an it was an chat bot. I know. And at that point, it's like, okay, do you ask them kind of like comp TIA style, like to share your screen? Cause you're supposed to. When you take now virtual exams, you're supposed to share your screen, you're supposed to share your space. Uh you you were talking about how you have to do all of these like verifications. Yeah, it's like what now do we have to add to the checklist to verify?
SPEAKER_00All these other human, like human human captures, right? Uh yeah, human human captures. Like proving that you are human by, you know, like we were talking about before we started, like having to like run your hand in front of your face, you know, proving that you're human by yeah, turning around, opening your mouth, you know, there's a whole bunch of things you could do. But which leads into, you know, something we had talked about earlier. Uh when you're in the thralls of being interviewed, right? And you're nervous, you're not really thinking 100% like, would you be willing to ask the person interviewing you to prove that they're human? Or would that be considered out of line, right? Because I mean, you want the job, you know, there's some absolute psychological pressure there. So not everyone is at their best or thinking cybersecurity is like the first thing on their mind, right? So it's true. It's tough.
SPEAKER_02It's true. According to LinkedIn, the easiest way to sniff out if you have a fake North Korean candidate is ask them or say something really mean about Kim Jong-un.
SPEAKER_00Nice. I like that.
SPEAKER_02And and when they when they start getting offended, maybe that's a talltale sign.
SPEAKER_00Right. Yeah. But that's fantastic.
SPEAKER_02According according to LinkedIn, not me. So don't come after me. But okay. The psychology of the lure. So what is it about the job interview, would you say specifically that makes people just override that security instinct? Like obviously, you and me were we're living in breathing security. We can sniff something out more and probably pass a phishing campaign more than just somebody in accounting, right? Or somebody in finance who their, they live and breathe talking numbers.
SPEAKER_00For sure. Yeah. I mean, I, you know, under the right conditions, I feel like even a lot of cybersecurity people, like myself included, could probably fall for something, especially if it's newer novel.
SPEAKER_02Uh, if it's really, yeah.
SPEAKER_00It's tricky too when you think about like North Korea, you know, the resources that they have available, right? This isn't like uh an operation where you have like a couple people with a computer, right? This is state sponsored. They understand like the psychological pressure and how to get people to convince people to do things they wouldn't normally do. Yeah, like when you're interviewing job, I mean, we've all been there, right? It's you really want the job, you need money, yeah. You're gonna do, you know, there's that trusted authority figure, right? Where you you'll you'll basically do what's asked out of fear of you know not getting the job or something that's expected that all the other candidates who have you interviewed for this have done. So I need to do this too to prove that I'm capable, right? So it's that social engineer psychological pressure that's goes on behind the scenes when you're doing a live interview. When somebody tells you, you know, you're a dev, here's a GitHub repo, go ahead and clone it and you know, run it and then tell me what you see. Oh, for sure. Yeah, let's go. I know how to run. I know how to do this. You know, you're proving your capabilities at this point, you're not really trying to defend yourself. So it's that whole psychological pressure, you're stressed, you're not thinking like you normally would when you're running random GitHub repos from home. You you're not vetting the code. And even if they're really good at hiding the code, you know, it's possible that you might be looking through the code, making sure it's safe to run, but then miss it just due to how well they're able to obfuscate it and hide it from you.
SPEAKER_02No, it's it's true. This authority versus anxiety dynamic uh you've hit pretty spot on. And GitHub repos, they definitely coat all of the legitimacy possible. We're almost like trusting how legitimate GitHub is.
SPEAKER_00Yeah. Oh yeah, for sure. Yeah, like I said, I mean this hasn't been the greatest year for GitHub trust.
SPEAKER_02Fair, fair. That's true.
SPEAKER_00Yeah, no, it's well, awareness, right? So maybe we'll start seeing uh other tooling be used. You know, if it's not GitHub, it's gonna be something else, right?
SPEAKER_02It's genuinely like a clever campaign. I I'm just it's not just lucky. I'll give him that. Like because you can't train that instinct away without breaking their actual job function.
SPEAKER_00Right. It plays perfectly into that job function. Because it's it's not like these threat actors, when they're posing as an interviewer, they're do they're asking you to do something that's outside of the norm, right? You know, in the past we used to get phishing emails where it was like, please enable macros. And maybe some people would, but I think most people would look at that and go like, oh wait, my cybersecurity training's kicking in at this point. Like, I shouldn't do that. And with this one, you're on an interview, already stressed, and then they're asking you to clone a repo and run some code. You know, this is exactly something that you would probably have done on a past interview if you're a dev. So it's very in line with exactly what you might do. Um just with a little malware on the side.
SPEAKER_02But you know what, you made you made a good point. It's not not going to affect you and me. I'm like saying, oh, it won't we won't be victims, but there's been some phishing emails that have been very, very, very good like as of late. And I, since I'm so chronically online, like I don't think it would be hard for someone to really quickly figure out that I love me Dye Coke, oysters, Taco Bell. I if I see any carefully crafted, oh, the best oysters in Chicago are happy hour oysters, one one dollar for oysters in Chicago. I'm going to be clicking on that.
SPEAKER_00It's gonna happen. Right. Like it just requires like those perfect set of circumstances, maybe a little bit of stress mixed in. And if somebody knows you well enough to spearfish you in a way. It's true. Right, yeah.
SPEAKER_02Like, so what are we supposed to be doing? So spinning up a new email every single time, like a fake email, going on AWS and taking advantage of the $200 credits for each new account and then running a VM and then running the GitHub inside there.
SPEAKER_00View everything from VMs. Have your email VM, have your interview VM, you know, like compartmentalize everything we do. This is my browser VM.
SPEAKER_02Literally. I mean, that's what it's gonna have to come down to. I feel like there should be more of a community-based also approach to job search. Uh, job description should be transparent about their salary. People should, you should know what you're getting into. It's the team you're gonna be working with. And there should be more of like, oh, what is available versus just these rando one-offs opportunities that if people don't already know that this team is well known and they're looking for their next person, maybe try to go with a more reputable brand, right?
SPEAKER_00Yeah. I think it's it, I think it's hard in the case of DevPaupper too, because you know, it's not so much a recruiter, but more like, hey, we're working on a side project and we need a dev, right? You know, like hey, we just need somebody for the next three months to come in and code up this Node.js app, right? So I don't have really any professional development experience, but I I'd imagine that's probably a lot more common. When I'm not so much in the cybersecurity space, which I think we're used to, but I feel like in cyber you don't really have these temporary jobs. No, you're kind of in it for the long run.
SPEAKER_02Yeah, you're in it for the long run. Yeah, at least a year. At least a year. Yeah. But that's true. That the these these guys probably just want to just jump from gig to gig.
SPEAKER_00Right. Yeah, sweet. You know, three-month gig for you know, X price, you know, I know Jayos pretty well.
SPEAKER_02Is that why then? Why developers are a prime target? Because it's higher churn. Is it because those stacks, is it stack related? Because Python, you could do so much with it, both maliciously or Rust specifically. Like what this group is the target, really.
SPEAKER_00Yeah. And I that's honestly something I didn't think of. Um, like the whole victimology, why they were targeted. I think that's a really good point. Uh, because of the nature of the job is an easy target versus longer-term trusted roles at where you would be working, like you said, in a team where yeah, I think that probably could be a huge one. Uh-huh. I think so too, is I think it's the fact that they are generally involved with systems that would be lucrative for an attacker, right? Like if you do work as a dev for a company and you decided to have an interview on your company laptop, I mean, think about what you would have access to at that point. I mean, private keys, tokens, things that for a threat actor would be a gold mine, right? And if you're if you're not, if this is your own personal computer you were doing it from, you know, that info stealer runs, what's it going after? Your crypto wallets, your browser data, you know, banking information. I think uh there's probably a stronger overlap with people who are technically minded, like developers, and their involvement with crypto. Like in that case that you just showed, this person was. They stole all their crypto wallets, now it's in crisis mode. What do we do at that point? So I think it's the overlap. And the DPRK has been hugely involved with crypto scams and crypto too. So I mean, that's very much in line with the type of stuff that if they're gonna steal, they would target. So yeah. Nature of the job, what you're involved with, what you may have access to. I think those are huge reasons why threat actors would go after developers.
SPEAKER_02Aaron Powell They're not saved. We're not saved. Just like oh, you and me are not saved. This guy had eight years of experience, and he is very well aware of a lot of techniques hackers use, and they're they're still one step ahead.
SPEAKER_00Right. Yeah. If you're that involved with crypto, you've probably done at least some due diligence around how to secure your accounts, what not to do. It's crypto scams and you know, malware targeting crypto, pretty much the whole crypto C. There's there's a lot of theft. It's unrecoverable, you know. So there's a lot of precautions that I think are that are baked into your head at that point. So it's likely that this individual had some some basic cybersecurity knowledge and training, but yet it's just you fall for the right scam. You know, the right buttons were pressed and yeah. Disaster recovery at that point.
SPEAKER_02From a detections defense perspective, is there any realistic defensive posture for let's say this poor developer here, the angel?
SPEAKER_00Yeah. Well, I mean, the damage is done at this point.
SPEAKER_02Well, yeah.
SPEAKER_00It's you know, it's disaster recovery, securing your accounts. Difficult with crypto. It's not like traditional banking where you can put holds and things like that.
SPEAKER_02Yeah.
SPEAKER_00But but always starts with the human, circling back to classic social engineering. What is social engineering? You're going after the person, not the technology directly. So obviously the first step would be awareness. Before you put yourself in a position where you could be vulnerable, you know, make yourself aware of these scams or tell people about these scams.
SPEAKER_02Yeah.
SPEAKER_00If you suspect somebody you know is going in for an interview and it's like, hey, well, hey, just so like probably not, but yeah.
SPEAKER_02It can't hurt. It can't hurt to yeah, put it in his mind so they're more cognizant.
SPEAKER_00Yep. So yeah, it starts with the human, human defense. At what point you would know that you messed up. Uh if I guess it really depends on your technology. If you go to run that Node.js script and you hit NPM and all of a sudden you get that AV pop-up. Hopefully, it's like wow, you know, at that point you close your laptop and kill the interview and hopefully stop something before it starts. But threat actors like the DPRK who have access to an insane amount of resources, there's they're very much aware of A V at EDR bypass. You know, they're really good around sneaking around technologies, especially if they understand their victim, too.
SPEAKER_02So Yeah. Um, from the, I guess, the other angle, uh, what can we do in terms of like interviewing from work assets? I feel like the probably the straight answer is probably no. You you shouldn't be interviewing at other companies from your work your career. Yeah, but what if what if you don't have a laptop though? Like not everybody does.
SPEAKER_00Right. And and that's probably why it's so common, right? Uh it's an available piece of equipment that's got Zoom, it's got, you know, whatever meeting technology you have, easy to join from. It's available. I've got all of my workflow tools already ready to go. I'm prepped. This is the type of stuff I'm always doing, anyways. So it's it is an easy thing to turn to because it's a nice prepped system. It's probably a nicer piece of hardware than you currently have, or it's your only piece of hardware, like you said.
SPEAKER_02Yeah.
SPEAKER_00So I I think that's probably the why, but it's definitely a very unwise thing to do because of that.
SPEAKER_02Literally. And they probably would hate it as well. But when when awareness does fail, because I completely agree. I think the more you talk about it, the more it becomes the norm or influence, at least. But if someone, let's say, assume breach runs the payload, what does detection fallback then look like? And can we find it on detections AI?
SPEAKER_00We can. Um well, I mean, it depends, right? It's I can't give a definite answer of whether or not you or your company can, because I don't know your tech stack, I don't know your data sources, but and the malware that eventually executes, like, you know, what was it I said earlier? Beavertail, yeah.
SPEAKER_02Beavertail.
SPEAKER_00Yeah, those like Python-based malware. Like we do have detections for unusual process chains, like CMD being executed, or any of your command interpreters being executed from node-running processes, kind of stuff like that. Process chains are usually easy win. Rat activity. There's tons of detections like that on detections AI, uh searching for something. I bet if you search beaver tail, you'll find that without checking. But I mean, so it's kind of like finding what works for your sim, works for your environment. Yeah. I think especially in regards to a lot of the GitHub-based malware that's happened this year. There's a lot of you know, JavaScript, node, JavaScript, clickfix. There's a lot of overlap, I think, with a with these technologies and these type of command executions.
SPEAKER_02So Oh yeah.
SPEAKER_00Yeah. I think uh yeah, GitHub too. There's a lot of uh GitHub-based activity, depending on what you're logging, that you could go straight after. But yeah, this is assuming that the person is using a work asset, which they shouldn't be, but you know, they should not.
SPEAKER_02They should not be.
SPEAKER_00Having that detection is better than not. Uh malware may have done its thing, but you know, dwell time exists for a reason, right? Better to know immediately versus six months after the fact that it happened and that employee left because he got his gig at North Korea.
SPEAKER_02So Well, yeah, and on that well, for the interview, on the interview note side, the lag between the awkward lag between the question, CV, CV uh like inconsistencies with the resume. If they're if they're not really knowing exactly like what they're talking about that you're reading on the resume, I guess I just that can go for anyone, because anyone can just say anything these days without accountability. Um but definitely I I just but if but if they're not on top of it, if they're very they're you know not really fully confident, I think that that's for sure. And also the the the response times, the emails, like if they're responding at like four in the morning, that's a good call.
SPEAKER_00That's a good indicator.
SPEAKER_02Yeah, exactly. Exactly. Um because yeah, I don't think these guys are gonna change, I mean, maybe change their whole their whole sleeping schedules in biological right.
SPEAKER_00Yeah. I'd say yeah, definitely do your due diligence before the interview even starts. And that's a great indicator. Know who your recruiter is. And I would say don't be afraid to ask your the person interviewing you cybersecurity questions, you know, doing the doing the AI checks, you know. I if anything, I think they'd appreciate your cybersecurity focused mindset if the interview ended up being legit, right?
SPEAKER_02So that's true.
SPEAKER_00I would expect it to go both ways.
SPEAKER_02Create a bunch of uh temp emails because now there's there's a website that you can create temp emails and it'll delete it after 10 minutes.
SPEAKER_00Oh yeah, yeah.
SPEAKER_02Yeah. Temp emails and then spin up a VM on it with AWS free credits. You can you can spin up a VM like a Windows server for very, very little money.
SPEAKER_00Oh yeah, especially if you're gonna use it just for an area.
SPEAKER_02Yeah, exactly. And delete it right after. I'm sure like you won't you will not eat up your $200 free credits you get with every new account.
SPEAKER_00That's few bucks you ever spent.
SPEAKER_02Exactly. Well, the byline is that you really can't alert your way out of this one entirely, because there's some defense and depth proactive things you can do to layer it on, but you can't also fully train it away, like awareness train it away either. And I I still think that a combination of all these things uh with detections built around behavior, that's gonna have to be the how we treat the engineering work required.
SPEAKER_00Yep.
unknownYeah.
SPEAKER_00Especially too until we start building detections for actual people, which might be kind of just open.
SPEAKER_02Is layer eight the human element?
SPEAKER_01Layer eight, yeah.
SPEAKER_02Yeah. I mean, unexpected, what like what what what detections? Unexpected child processes, IDE, uh outbound connections from install scripts. That's top of mind. And well, I think takes us to the end of the episode, Tim. That's uh death popper, but also like now more of a modern spin on it. That this one again, the the developer, the blockchain developer that got popped, this one was coming from a oh, okay, not not Russian. It's a Ukrainian.
SPEAKER_00It's it's gonna be a matter of time. Like if somebody has success with anything in this world, people will copy, right? So if DBRK is having great luck with this campaign, you know, it's just a matter of time before we start seeing it all over the place.
SPEAKER_02Yeah, well, it's also a good reminder that some very dangerous exploits aren't always necessarily technically sophisticated. So uh definitely be cognizant of your hiring process and uh and the payloads, obviously, that come from that. Tim, thank you so much for walking us through both of those mechanics and the mindset behind that one. To our listeners, if you're a detection engineer, please take this one as a prompt. Go check whether your environment could actually catch some of these patterns. Keep building, keep testing, and keep engineering. Thank you for tuning into dispatch. We'll see you next time.