Transcript
By 2025, the investigators at Nisos had spent three years smoking North Korean IT workers out of American companies. It becomes something of their calling card. They've triaged cases for clients across the Fortune 500 and beyond, but all of that work was done from the outside, at a distance. And for Nisos CEO Ryan LaSalle, that wasn't enough. It was probably not even six months before, I was at a bar with a CISO. I was like, what if we could get in and infiltrate one of these groups? What if we could be one of them? What if we could interact with one of them to learn more about how they're evolving their techniques? And his point to me was, it's impossible because you're not in the room. They're all in a command center somewhere. They're in China. They're in North Korea. Never once had it crossed their minds that a North Korean mole might apply to them. I'm Nicole Perleroth, and this is To Catch a Thief. So, after almost three years of doing research and helping clients and tipping law enforcement to the threat of North Korean actors trying to find jobs in U.S. companies, we had some new open roles that we posted for an AI developer. And we got a flood of great resumes coming in. Perfect resumes, actually. These candidates flooding in, it was if their entire career had been built for this one AI security role at Nisos. But one person stood out above the rest, a Joseph based in Palm Beach County, Florida. So, Nisos arranged an interview, but the minute he came on screen, something was off. And the hiring manager came to me and said, Megan, I don't want to make assumptions, but I don't think this person is who they say they are. Based on some of the issues that happened during the interview, this could potentially be a DPRK candidate. What do you want to do about it? While most HR leaders might have flinched, Megan Jacinto, Nisos' chief people officer, leaned in. Like many at Nisos, she'd come from the CIA. The chance to engage in North Korea directly was just too good to pass up. So, she tells him to run it up the chain. That Monday, our CTO brought his interview to us and said, look, I think we've got something here. It feels pretty clear that this person's probably a DPRK, North Korean IT worker, just like we've been talking about, just like we've been writing about, just like we've been investigating for a couple of years now, and he wants a job with us. I think we could run this as an operation. And we sat around the table and we're like, this is crazy. This is crazy. Like, how are we going to do this? If they really wanted to get inside the brains of a North Korean IT worker, they weren't just going to have to bring him back for another interview. They would have to hire him. How do we assemble the right team? If we wanted to run an operation, do we have the technical wherewithal to do it? How are we going to get them a laptop, get them instrumented? How are we going to actually technically pull this off? Even if they could solve the technical side, engaging a North Korean risked violating sanctions. Our GC was in the room as well, and the question was, how do we do this legally? Can we actually do this in a way that doesn't blow up in our face? And how do we take the steps to really, truly understand this threat group, this very particular fraud and scam, and do it in a way that doesn't come back to bite us in the ass? They decided to bring the candidate back for a second interview, but this couldn't feel like a CIA interrogation. They needed to confirm Joe was North Korean without scaring him off. We didn't know going into that interview whether we would validate it as North Korean or not. We thought high confidence it probably was, and if it was, then we would go to the next step. I think generally, everyone's nerves were high every step of the way. We were anxious about not tipping our hand, not making it feel like we were leading this guy on. We were anxious that we didn't want North Korea to start thinking, like, if there are other people watching his interviews, we didn't want them observing our behaviors and trying to figure out who we were and making us a target. There would be a normal interview, but all along the way, we would be trying to figure out the tips and cues, the body language, the signals, and some of the gotcha questions we thought we would use to help understand how this person was trying to misrepresent themselves, and whether we thought that it was a general workplace fraud or something very specific with the IT workers in North Korea. Nisus made a point to study North Korea's Zoom interviews, like this one. I really like AI. So these days, actually, AI, you know, make a real impact in our real life. Do you think there are big security risks with AI? So, uh, of course, yeah. They knew all the screening questions that can quickly weed out a North Korean worker, like this one that you might have seen because it went viral. We get like a lot of imposter candidates, particularly North Koreans, so one of the Something like, Kim Jong-un is a fat, ugly pig. Could you say that for me? Uh, hmm. Can you say it? The interviewer asks him again, but all of a sudden, the candidate's screen conspicuously freezes. There's silence, and then it's clear. He's gone. Damn. He really don't want to say it. But for Nisos, the goal here wasn't to scare him off. It was to confirm he was who they suspected and pull him in. So the Nisos team studied these interviews, then choreographed their own. It was decided Megan and Ben Reisenberg would work together. Like Megan, Ben had come from the CIA, too. He was trained to spot foreign operatives, but they would have to give Ben the alias Ethan, since anyone could have traced Ben's CIA background on LinkedIn. Together, they figured out who would say what, when to press, and even laid a few traps. So we got into the interview, the person was right on time. My name is Megan, and I have my colleague Ethan here. Hey, how's it going? And he looked very, very young, especially given the amount of experience that he had listed on his resume. So think teenager, young. In fact, I thought, gosh, I want his skincare routine if he is supposedly, you know, in his 30s. And so one of the first questions we asked him was where he was from, and he said Florida. And I said, oh, you know, my dad lives in Florida. And I said, you know, they just had a hurricane, you know, Hurricane George. How did you do? How was your house? How is your family? And he really stumbled around that question. Yeah. How can I say, the winds were strong and we got a lot of rain. But luckily, my place was fine. Some branches down, a bit of cleanup, but no real damage. Just one thing. There was no Hurricane George. They'd made it up. And you could see him kind of looking off on a screen to try to get information about a hurricane and certainly Hurricane George, which there wouldn't have been any information because there was no Hurricane George in 2025. And so that was a really good indicator that he was using one, a chat bot to answer questions and two, likely didn't live in Florida. It wasn't just the hurricane. Every question, no matter how trivial, was followed by a pause and filler words. It was a little uncomfortable. And you know, at first you kind of think, okay, English is the second language for him. So he's formulating, you know, the translation in his head and then responding. But some of our questions were like, what do you like to do for fun? So outside work, I like to keep things pretty simple. So I enjoy exploring new tech on the site. But when I'm not in front of a screen, I like going for works, reading and just spending time outside. And it became apparent that he was listening to an answer. Someone or maybe something was feeding him each answer. Megan and Ben moved the conversation to his work experience and asked Joseph to walk them through his portfolio. Then Ben said, you know, while we have you here. We can make it even easier if you want to share something now, if you can just pull up your screen, we can try. Yep. Sure. Do you want to share your screen and show me a little bit of the work? Right now? Yeah, why not? And he paused and he got visibly started shaking a little bit and started looking around and then I saw him closing windows on a screen and he said, yeah, I can share. Just give me a second. Can I rejoin? You want to rejoin? Yeah, yeah, yeah, good sequence. And he just ended the interview. And we thought, OK, we'll just hang a bit, hang around a bit to see if he comes back on. Pretty sure he was not coming back on. And sure enough, he did not. We waited a good 15 minutes and he did not return. We were all waiting on Slack to see what they said when they were done. But as soon as they got off, the channel was like, and and they're like, no, this is it's exactly what we thought. And now we need to figure out what to do next. This was the Intel gathering chance of a lifetime. But it also carried real risk. We weren't quite sure how active that cell might be in terms of retribution or in terms of getting upset about what we were doing. The last thing we need is a small business is to break a law and suddenly have to pay fines for OFAC sanctions or something crazy like that. So we need to keep a very clean nose on this stuff. But ultimately, everyone agreed they had to try. We did call a contact of the FBI that had helped us in some of our other investigations and talk them through what we were planning and helping make sure that the things we were doing on our machines, with our equipment, with our software, weren't running afoul of the law. And then they hired him. So what we decided was to offer him a contracting assignment. So, hey, we have this AI project. We really enjoyed the interview. Sorry you couldn't rejoin. Hope there weren't too many technical difficulties, but we'd like to offer you an upfront retainer if you will work on this project for us. Immediately responded to me. Just to be clear, Nisos could never actually pay this retainer. But they knew if they could string him along even just a little longer, they might just get a glimpse into how this guy worked, where else he worked. And if they were lucky, pry open a window into the world's most sealed off regime. So Nisos sends this guy a contract of sorts. We sent a fake document that contained a canary token. That canary token could cut through his VPN to reveal his true whereabouts. Joseph asked that they send his laptop to Florida just to be sure it didn't get shipped off from there. Nisos planted a tracker inside the package, which confirmed the machine was, in fact, in Florida. And last but not least, they leased the laptop with spyware. We were able to track logins on the network, and also the most important piece was we were able to turn on the camera, so we're able to see what's going on around the computer. This is where things get wild. We saw a bunch of other laptops all in the closet with us. We're sitting in a walk-in closet. I mean, you could see it was container store type of wire shelves in the closet. You can see our laptop sitting facing the opposite wall with other laptops on another shelf. From an IT perspective, I was very offended because the cables were super messy. Any nerd worth their salt has better cable management than these guys, so that was the first offense. So you're seeing a bunch of other laptops, and are they literally putting the laptop in with the camera open as it would be on my MacBook right now? Yeah, it's just sitting open on a shelf. But try as they might, Neosys never sees a person come on screen. But on the back end, Neosys could see its laptop and every other laptop connecting back to a hidden mesh of remote tools that allowed operators overseas to control them. Keyboard, mouse, everything. From their employer's perspective, any activity off these Florida laptops look completely legitimate, when in fact, they were all being remote controlled from abroad. As to where exactly, that's where the Canary token came in. And so we were able to see that the IP address pinged somewhere in China. In intelligence, you're always thinking about probabilities. and every step of the way, our probability and our certainty about this being a North Korean threat actor kept going up and up and up. That Canary token from that first onboarding document that beaconed back from China was probably the thing that was the most movement to certainty that we had. We're like, nope, this is it. This is not a kid from California. This is definitely a North Korean actor operating out of China, trying to get a job at our company. We're sure of it now. The moment it all clicked came courtesy of the spyware Nisos had installed on his laptop. It let them see everything he typed. He Googled, is Florida in North America? So again, if you live in Florida, you probably know that you live in North America. It was questions about what sports are played in the United States. So a pretty good indicator that this person did not live anywhere in the United States. And then came the real break. Joseph logs into his Personas Google account from their laptop. Without that, we wouldn't have had passwords for all of his accounts. We wouldn't be able to see all the companies he's constantly applying to. How many hundreds of emails he sends out or applications he fills out every single day to get jobs and schedule interviews with companies. I think it was hundreds of interviews, several job offers. I think at some point in time, he was working four jobs. But incredibly, this IT worker had made a rookie mistake. He stored the passwords to all his accounts in Gmail. We got lucky in that we got email addresses and passwords for Discord, which we in the beginning didn't think that why would they be using Discord for anything? But we decided let's go see what's on Discord he might be using it for. Discord, a chat platform used by a lot of gamers, hardly seemed relevant. Mesos wasn't super interested in whatever video games Joe was playing on the side, but they double clicked anyway. What they found next wasn't downtime. It was a clear view into the complete inner workings of an entire cell. What we learned is that this network is using Discord to figure out what jobs they're applying to and really coordinate all of their activities across 22 individuals on Discord. The leaderboard is on there. Their rewards and measurements are all on there. They get tracked by activity and outcomes. How many jobs do they apply to? How many jobs do they get? And they actually get measured on a leaderboard. Almost all of his screen was interview confirmations or progress on interviews or feedback on a job offer. Or that's what the whole thing was all job boards from multiple companies, multiple recruiters, multiple freelance sites. And all day long, that's what he spent his life doing. This cell tracked their entire operation like a sales dashboard. Every application, every interview, every rejection, every offer letter was posted to this one Discord channel. It also functioned like a group chat. They traded tactics, shared scripts, compared notes. We were like, this is crazy. This is next level. This is much bigger than we thought we had. And I think that that was where it started getting really exciting. The amount of slacks going across our business every day, all night long, like the new things we were finding, the crazy stories we were seeing. And I still think the funniest thing were the failed channels. Every time a North Korean operative got caught, they posted it to a Discord channel labeled horror so other cell members could learn from their mistakes. A playbook built in real time. So if they get fired, it says on there, this is the reason that I lost the job so that way they can keep that for metrics as well. Or if something worked out really well, here are tips that how you can be better at getting jobs. A North Korean IT worker best practices channel. In essence, yes. One of the things I thought was hysterical was every time they got a job and every time they lost a job, the chat would fill up with PJU just got his dream job. And there'd be the offer letter from whatever company it was. And then like three days later, there'd be a frowny face. PJU just lost his dream job. And I'm like, oh, so sorry. It was almost like an automated alert. Like you'd have them like a Slack bot. And it was just like the way they were sharing the wins and losses that they had every day of what to them was a game. And to us is massive fraud. As North Korean IT workers became more of a known entity, interviewers started screening for them. The MISO's team could see the confusion that unfurled on Discord with some of these questions. Yeah, one of the big things that they kept getting caught up early on was when the interviewer asked about what the mascot of the university was. So we had a lot of screenshots of what exactly is a mascot? Why would a university have a mascot? What's the mascot of X university? So that way they can able to answer questions and they warned each other of those things. These are a lot of virtual backgrounds. And then every once in a while, somebody else in their same room as them would come through the virtual background and show up on camera. And you could see the interviewer's face being like, what's that? And then the person who came through being like, and then a shocked face and then run off camera. The screenshots of those things being like, ah, we got outed again. One of my favorite ones is there was an application where there was a question, are you from a designated country like North Korea, Russia, Iran and Sudan? And the person put yes in the application. And then the HR person followed up and said, I noticed in question eight, you answered yes to this. Was that a mistake? And he screenshotted back that he wrote yes, mistake. And that was it. Then the person said, okay, we're good. Like, oops. Yeah, not even the full sentence. Yes, mistake. Nisa starts getting a pretty clear idea of where all these workers are getting jobs in the US, both from the discord chatter, but also from their laptop camera back in the closet in Florida. They could actually zoom in on the screens of every other laptop in this closet. And on them was their corporate logos. We saw four other companies in the same space as us. There was a healthcare company. There was an insurance brokerage company. There was a mortgage company. Some of them were household brands. Some of them were not. I started getting on the phone and calling the other companies that were in the same room with us and letting them know that they had been subjected to the same kind of scam that we were in the middle of. So you call them up and you say, Hey, Ryan here from Nisos. Got something for you. Tell me what that conversation sounded like. Does this podcast have an explicit rating or do I have to keep my language clean? It doesn't have an explicit rating. We enjoy curse words here on To Catch a Thief. One of the heads of security called me and said, this is the worst fucking sales call I've ever received. You better not be extorting me. I was like, well, I'm really here to help. Here's what we did. Here's what we saw. Here's who the person is. You guys need to do your investigation. And he got real calm. Fast forward four weeks later, he took a bed and a night out for a beer, but he didn't appreciate the approach to start. The other companies were a little bit more cautious, but they came back pretty quickly and said, tell me what you're seeing. How are you seeing this? I don't, like, are you inside our network right now? And so we had to say, no, these are the things we're seeing in this house in Florida. And we can tell from this house who this person is and that they purporting to work for you. All of them fired their person. Half of them also contacted the FBI to make sure that the FBI knew that their equipment was in the possession of someone that they did not grant possession to. On Discord, North Koreans post their job offer letters. As these offer letters pile up, Misos makes a point to call each company, letting them know a North Korean is on their payroll. It becomes almost routine, but then one conversation stops them cold. One of the companies was a placement agency. And when we let them know that one of the folks they placed was, in fact, one of these folks from this operations network, they blanched because the person they had placed, they had placed at a nuclear utility. They had placed a North Korean in a U.S. nuclear utility. Now, he worked on low-level IT systems, but given the sector, this was still extremely concerning. They were nervous about what that person could have access to and could do. Misos digs deeper into this one worker's activity in the Discord, and what they find significantly raises the stakes. Some of these folks would post screenshots from their companies proving that they had jobs. And this particular guy posted a picture of what looked like an industrial control system control panel. This is as serious as it gets. An industrial control system panel is the interface to the physical world. At a nuclear utility, it can mean the controls that regulate the nuclear reactor. It's cooling, safety locks, fail-safes, not anything you would ever want in North Korea's hands, or anyone's for that matter. That elevated the intensity of this quite a bit. We all sat down together to brief the end company on what we learned and how we learned it so they could understand that it was a valid and real true threat. And they also validated the screen was something that did not have access to any true control systems. It was a training screen. And they'd already fired the guy before we had even notified them. So they felt like the risk was pretty well managed, but from a near miss perspective, that was a pretty scary one. It was crazy. I mean, it was like, people were like, oh crap, let's look at the screen. Oh crap. And they looked at it like, okay, it's okay. It's not a live system. It's all fine. It's not a real thing. And I think to me, like the bigger concern is going to be motivated attackers who want to have access and means and who have a real intention and a target employing the same tactics. I want to come back to this leaderboard. So there's 22 people. They're on this leaderboard. I assume it's constantly shifting. At the top of this leaderboard, how many jobs was number one holding at any one time? The leaderboard is much more business focused. It gives you a sense of how professional this thing really is. So the top person who's applied to the most jobs in this cell is 26,688 jobs. That person has also managed to land 5,781 interviews. However, they are not the most effective at getting jobs. A person who has almost 26,000 and 4,600 interviews has 19 jobs, 19 offers. So I don't think they were working them all at the same time, but over the course of the period, this person was probably the most effective at landing jobs through the process. But that's still a really crazy funnel. 27,000 applications for 19 jobs. If my kid who's graduated from college is trying to get a job and that's what it takes for him to get a job, I'm terrified. And Joe was part of just one cell. Once Nisos tipped off Discord, Discord was able to use the cell's characteristics to unearth much larger cells of North Korean workers on its platform. What they learned from our intel was that the way these guys are showing up on their platform is less like a scam network and more like a startup. And so now as they look for the behavioral signals they're looking at things that look more like small companies than they are criminal rings. No one has published a definitive tally of just how many of these discrete cells exist, but the most recent UN report found North Korea is dispatching thousands of workers through coordinated cells across multiple countries, enough to flood job markets. The most anybody's held was five or six jobs concurrently. Most people only had two to three jobs and then there's a couple of people that only had one job. What's interesting about it is though, is that it didn't seem to matter how many jobs they had. Really what the metric was driven by is how many applications did you fill out today? How many interviews did you go on today? That was what every big question was about from leadership. And then the job stuff was just, okay, now you're getting some sort of salary. There was no concern about how much the job paid. So we had seen offer letters come in anywhere from having a very junior job that paid $25,000 a year until very senior jobs, which paid 170 and more. And it didn't matter. There was no negotiating for salary. It was just like, your job is to apply and get interviews. And if you have a job, that's great. Okay, but how are they actually getting any work done? So if somebody's double booked for something, they coordinate who will do the actual work meeting for them and who's going to do the interview. So it's a platform really designed to facilitate all the work that they could be doing at the same time. And then we did also see them, if somebody had five or six jobs, outsourcing some of the work because it was getting really busy for them. And how are they recruiting them? Through a variety of ways. Through a variety of job boards. Saw them posting, hey, I have a job. I need somebody who's really good at Azure, which is like a programming language. If you have free time, I would love to talk to you about a job you can do for me. So like they try to hire people to just do the job for them. Occasionally employers would learn the hard way that not only had they hired a North Korean, they'd unknowingly hired their subcontractor in India, the Philippines or Nigeria. One of the guys had a job at a company. So I called the CEO of the company and I said, hey, this guy is not who they said they are. So he goes, yeah, I know. How do you know? Well, cause last week he disappeared and I haven't been able to pay him. And then this week I got a note from a guy in India saying I owe him $10,000 because he'd been hired by this other guy to do all his work for him. And he'd built my entire app and I didn't even know about it. So there's a cascading supply chain for the person who gets the job to then figure out how he's gonna fulfill the work. And they go to India, they go to the Philippines, they go to Nigeria, they'll go to other places to backstop the jobs they've got. And were all these people above board as in they're just there for the paycheck or did you see him run ransomware or steal corporate data or just try to extort the companies as they go? So I will say that some of the smaller companies we were disclosing to were experiencing extortion already. Their North Korean workers had access to all of their code. And so when they would decide to fire them or not pay them, they would hold that code hostage and say, you know, if you don't pay me, I'm gonna release it or I'm gonna tamper with it. There was some of that going back and forth. It wasn't as sophisticated as a ransomware attack or IP theft. It was just pure cold extortion. Now, North Korea's IT worker cells are siloed from the regime's specialized hacking teams. But more and more, we're seeing handoffs between them. This is especially true for those who get jobs with crypto companies. Last year, the Justice Department alleged one DPRK worker's access was used to steal nearly a million dollars in crypto from an Atlanta-based blockchain firm. In a second case, North Korea allegedly used a worker's access to steal highly sensitive defense secrets from a Southern California defense contractor. And in several instances, when American companies tried to fire these workers, they moved to extortion, threatening to leak what they'd taken or tamper with the company's source code unless their employer upped their severance payout. Here's D-Texas Michael Barnhart, aka Barney. We had one extortion attempt that was pretty unique. They'll either ask for, hey, I want my back pay, you fired me on wrong reasons, I want all my back pay that's due to me. Or they'll say, hey, I have intellectual property years, you give me XYZ Bitcoin and I'll make this problem go away. Or you'll see something like- How much Bitcoin are they asking for? They used to ask for small amounts. They started getting bigger. At one point, I saw five Bitcoin. That's more than $300,000 at today's price. I mean, they want you to pay it out, so they will try to give a attainable amount. But yeah, and that was also on smaller companies. They were really starting to ask for more money and then hitting like the Fortune 500 companies with this type of activity too. But a third one is that they'll go, if you don't give me my money, my back pay or whatever, I'll either give it to a competitor or I will give it to a more qualified threat actor and let them see what they wanna do with it. Basically, the accesses. The problem was that you asked for one of those things and you might get one of those things. We had one extortion tip that had all three of those demands in the same email. So it was like, I don't know, brother, give me a chance. Like, damn. We saw one one time try to get access to the main servers and try to destroy those, but didn't have the right permissions. Sending malware-laden HR documents back to HR after they were terminated. Just, it seemed like it kind of spiked there for a little bit, but it's also visibility. Unless a company is telling you, you're not gonna know about it. And a lot of people don't want the embarrassment that they had an IT worker. So a lot of things we'll never know. It wasn't until May that I connected with a former North Korean IT worker, now a defector. We were introduced through an NGO, P-Score, People for Successful Korean Reunification. He said his cell was focused entirely on the paycheck, but the quotas were relentless and rising. He never mentioned extortion, but you can start to see the pressure building. For the safety of this source, we've omitted his name and are using a voice actor to read the messages he shared with us. The biggest pressure was meeting the required payment quota to superiors. We weren't assigned work. We had to find our own projects, bid on them, develop them, collect payment, and submit earnings. That meant handling everything ourselves from marketing to execution. If we failed to meet quotas, even sleep and rest could be restricted. If we met them, we could earn higher pay and occasionally get perks like shopping, dining, or supervised outings. Because most clients were in the US and Western Europe, our schedule was flipped. We would usually go to sleep around 4 to 5 a.m. and wake up around 11 or noon, then have lunch. Depending on the project, we would either rest for another one to two hour or start work immediately. We worked continuously until dinner with short breaks afterward. From around 9 p.m., where the US workday begins, we would work straight through until 4 to 5 a.m. We could take short breaks of 30 minutes to an hour, but overall, we worked at least 12 hours a day. All computers had monitoring software installed and a supervisor lived on site with us while continuously observing activity. As for the paychecks, most went back to the regime. We typically earned about $5,000 per month. We personally kept about 15 to 25%, depending on how much we earned. Around $2,000 to $3,000 went to the government, and then the rest was split with local partners or used for expenses. Their IT work and their work for the regime could blur. There was a post where one of the guys was sharing news from the company that he had gotten a job at, and it was pretty big news. They had a major business event that was covered by all the papers. And he was like, hey, it's my company. And he got reminded by his boss, you work for us. That is not your company, you work for us. But the defector made clear that compared to what his countrymen are forced to do, this work is as good as it gets. Earning at that level could support a family in North Korea and even allow you to buy a home in Pyongyang after a few years. After defecting, I felt most guilt toward my family, who could face punishment because of me. Most workers are trying to build a better life, even while being exploited under harsh conditions. Yes, the work is illegal, but the persistence and effort of these workers should be recognized. And most are not simply hackers or spies. They're also victims of forced labor and systematic exploitation. The defector rarely questioned the ethics of his work. I didn't initially think the work was illegal. The pressure to meet quotas was much stronger than any ethical concern. Over time, especially after going abroad, I began to realize that much of what I had been told was false. Just like Joe, this defector had been sent to China. We had no choice in where we were sent. Living abroad as a North Korean felt like a privilege. Access to money, the internet, and communication with foreigners. But we were socially isolated offline. I can't disclose the exact location in China, but we rented a normal Chinese residence where we lived, ate, and worked. The conditions were relatively good, but compared to ordinary Chinese residence, it was cramped. Sleeping areas were especially tight, so we kept personal belongings to a minimum. We mostly ate local food, but sometimes cooked North Korean dishes ourselves using local ingredients. Grocery shopping was one of the few opportunities to go outside. As for how he managed to escape, that was the one thing he wouldn't discuss. I can't discuss the details, it's sensitive. But many people risk their lives to escape and success rates are below 50%. I was fortunate. Like many North Korean IT workers and hackers, this defector was identified young. Others have described the pipeline. Students singled out as early as grade school, funneled into elite technical universities, and those with the talent for hacking are sent to Pyongyang's Automation University, essentially a West Point for hackers, where they're trained to write malware, exploit vulnerabilities, and hack. The best graduates become part of North Korea's elite. In a country where the state assigns your housing, hackers get the best apartments, the best food, and some of the regime's most prized privileges. Then they're forward deployed. Here's Chris Wong, who spent years tracking North Korean hackers and IT workers at the FBI. You know, they're probably working 18 hours at least. So it's not like it's short, but at the same time, IT workers are in a privileged position. So compared to the rest of society in North Korea, they're earning more money. They're able to work outside of North Korea, and then their families get more benefits than your average North Korean. So from that perspective, they are in a privileged position. Where have you seen them? Laos has come up a number of times, Russia, sometimes Vietnam. Where else have you seen them operate? Laos rings a bell. Seen them operate in Africa. I've seen them operate in Dubai. But I would say China and Russia by far are the biggest ones. It's critical to understand China's role in aiding North Korea. It's not so much a friendship as it is an uneasy alliance. China backed the North in the Korean War, and it's been Pyongyang's lifeline ever since. Just this month, Xi Jinping visited Kim Jong-un on a two-day state visit to North Korea. Now, the two leaders kept a very busy schedule on Tuesday, paying respects to Chinese soldiers who were killed on the battlefields of the Korean War, and then visiting a school and planting a tree there together to mark the two countries' friendship before. For years, North Korea's entire internet access ran through China Unicom. Russia offered up a second line in 2017, but for more than a decade, China controlled the switch. There are 1,024 IP addresses in all of North Korea. I think I've got more than that in this room right now. Yes, I bet you do. The U.S., for example, has about 150,000 routes for internet. South Korea has 17,000. North Korea has four. As for China, North Korea forms a critical buffer between itself and South Korea and the tens of thousands of U.S. troops stationed there. As long as Pyongyang holds, the buffer holds. So China props it up because the alternative, a collapse, is far more dangerous. Jim Lewis describes China's relationship with North Korea like this. The Chinese are the ones who saved the North Koreans in the Korean War by coming and invading. The Chinese make movies about how wonderful they were in Korea, but it's a difficult relationship for them because it's like an unmanageable pet. It's frustrating to the Chinese. I had one experience where I had a Chinese friend who works for the Ministry of State Security. We were having dinner, and he actually sort of was really annoyed. He's like, those Koreans, they're uncontrollable. I never expected to begin a lecture on how North Korea is a pain in the neck from MSS, but it is one of China's only allies. So most of the North Korean hacking activity, the cryptocurrency laundering, the hacking schools, the technology they use for hacking all comes from China. China offers something North Korea can't, fast, reliable internet, a requirement for North Korea's hacking operations and its remote IT work. They had a restaurant chain for a while that was called Pyongyang that was in Europe, was in the Middle East, was in other Asian countries. Serving North Korean food and liquor and featuring live music, the chain offers visitors a rare glimpse into the reclusive nation's culture. You could go work at the restaurant and live like a Westerner, right? What a deal. And you could also hack. It wasn't just restaurant chains. North Korea ran hotels abroad too, aka the hacker hotels. He said Pyongyang Cyber Warfare Agency, which goes under the name Bureau 121, is based at a hotel in Northeast China, very close to the border with North Korea. And North Korea's nearly 2,000 member elite cyber hacking team are actually trained in China. Back in 2014, researchers at HP discovered one of North Korea's elite hacking units was operating out of a hotel in Shenyang, China, the Chilbosan Hotel. They're going to places like China, They're going to places like China, setting up shop in hotels where there's access to setting up shop in hotels where there's. broadband internet, and that is where law enforcement officials and top administration officials believe they're launching these attacks from. In online reviews, Chilbosan Hotel guests praised the warm hospitality, the food. Some even noted the surprisingly strong internet access. Recently, we've seen more North Korean outposts pop up just over the Chinese border, in places like Vietnam and Laos. And when I say just over the border, I'm talking an evening stroll from China. What these countries give Beijing is a bit more distance from its DPRK dependents, but they also offer easier visa access for North Korean operatives. Vietnam was a big one for a while, so it's not like a complete alarm. Like Vietnam, they were able to abuse the restaurant visas there. Basically, you come in on a restaurant visa, but no one will ever check it. So you can stay there for as long as you like. In March, both Vietnam and Laos were mentioned in a fresh round of U.S. sanctions. The Treasury sanctioned one North Korean front company for managing IT workers in Boten, in Laos, a border town that sits virtually on top of China. They also sanctioned a Vietnamese company and its CEO for allegedly laundering $2.5 million in workers' earnings into crypto, back to Pyongyang, and its weapons programs. If their photos are any indication, North Korean IT workers seem to especially enjoy their time in Laos. Not too long ago, security researchers uncovered a cache of their photos on an unsecured Dropbox folder. Inside were photos of these North Korean IT workers living the life, dining out at steakhouses, throwing pool parties at their rental in Laos. They also love minions. There's photos of them posing with large promotional displays of minions in Laos. For whatever reason, North Korean IT workers are obsessed with minions, as in the small yellow gibberish-speaking henchmen from Despicable Me. They use minions in their profile photos, in leaked chats they greet one another with a minion and refer to their boss as Gru. Some say it's just their innocent love of minions, because who doesn't love minions? But Ben from Nisos articulated an alternate theory. The reason it is believed that they use the minions is because the leader of the minions is Gru. And as we all know, and this goes back to the question you had earlier, is how are they related to Russia and China? GRU is the Russian service, so there's belief that they're using Gru as the accounts that the Russians are using to kind of show the North Koreans how to do this kind of work, and hence they're using all these minion characters. And we've seen that they make fun of each other, and when they send gifts to each other, everything usually has minions of either clapping or pointing at each other and laughing because a mistake was made. And so that's the minion angle. Whether it's a sly nod to the GRU or just their love of minions, Russia is becoming a growing hub for North Korean IT workers. Some of the photos from their stash show them sitting wrapped at taekwondo matches and figure skating events in Russia, taking in the culture, or at least the cover. It almost looks like they're on a chaperone field trip. A consistent presence in these photos is what appears to be their Russian handler. Here's a Poland-based researcher who's been actively tracking these North Korean workers. He's asked to go by his alias, Black Big Swan, or BBS, to protect his identity. Some of those pictures we have from Russia with DPRK workers, you can see there's definitely a person who is sort of a handler to them. Who are they? I don't know whether this is like a government agency or just somebody hired from Russia to take care of them. I have no proofs one way or another, but yeah, it's not a North Korean. So they wouldn't try to escape because obviously some of them could try to escape from North Korea for Russia or other places they are in. So there is definitely a person who is supposed to guard them. And that person is not North Korean. There's some evidence that the very best remote IT workers travel as a unit from outpost to outpost. BBS followed one DPRK operative who went by the alias Kasane Takeda, who held 10 jobs simultaneously. He was calling himself Kasane Takeda. That was like a Japanese name of his. And that's actually a guy who had 10 jobs in 2025. He was everywhere. I first spotted him in December 2024 and just spent another two or three months constantly discovering his new identity, new job. It was endless. You expect him to maybe have like one or two jobs, but then there's another and another and it never seems to end. He was constantly popping on our radar. We also have a lot of pictures of him outside of the context of his IT work. For some reason, regime was constantly taking selected few IT workers to different events. One of those events was in Russia, Vladivostok, and they were taken ice skating because there are certain sports activity, IT workers, DPRK, I guess it's extremely into ice skating. And one of those things is ice skating. And yeah, we have pictures of that guy from one of those ice skating events. And he was also in Laos. He's also in pool party pictures. Like we have a lot on this guy. Yeah, that was my favorite one. But now he's like completely gone. The Russia connection is strong and getting stronger. So as we all know, the North Koreans sent troops to Ukraine to help the Russians fight. It didn't do very well, but it was a good lesson for the North Koreans. So the Russian relationship is probably closer now than the relationship with China. North Korea will never escape China. They're right next door. China is the 800 pound gorilla. But the Russians are more likely to be considered friends. Russian President Putin travels to North Korea today. The dictatorship of Kim Jong-un is one of the key suppliers of weapons and munitions to Russia after the Ukraine war turned the country into a pariah. It's a budding friendship built on mutual isolation. And for IT workers, Russia is becoming a major outpost that can accommodate their ambitions and scale, which brings me back to Nisos. If you'll recall, Nisos had hired Joe, the alleged Florida-based AI developer, who was really a North Korean living in China, on a contract. But remember, this was all a ruse to infiltrate North Korea's IT network and spy on the spies. They couldn't actually pay Joe. That would be illegal, which meant their operation had a clock. At some point, he'd realize a paycheck was never coming. We just really kind of made up excuses. One excuse was, I was on vacation. And then the hiring manager was on vacation. And then, hey, sorry, the project is getting delayed, but we're still very interested in you. We just kind of kept stringing him along till he said, I'm done. You know, no, thank you. I've moved on, you know, to other employment. But in that narrow window, they saw something extraordinary. Over the course of the summer, just from June until our operations wrapped up at the end of September, we saw this cell apply to 160,000 jobs in the U.S. One cell, one summer, 160,000 job applications just in the U.S., which would make this one of the most ambitious workforce infiltration campaigns ever uncovered. And as this picks up, employers say their job portals are getting crushed with illegitimate candidates. And it's not just individual companies. It's platforms like LinkedIn and Upwork who are left to figure out who's North Korean, who's not, who's an American loaning out their identity to a North Korean. It's not just overwhelming. It's creating a job freeze. American job seekers are now competing with a fire hose of fake North Korean, perfectly AI-ridden resumes. And all of this is unfolding at precisely the moment AI replaces the first wave of IT workers. I met with a company and they were talking about how they had to turn off their external job postings because they couldn't get any legitimate candidates through. It made me think of that kind of cyber attack, a denial-of-service attack, where companies' websites are flooded with requests from an attacker who essentially brings down the website. No legitimate traffic can get through. No real customers can get through. And that's kind of what these folks are experiencing, but it's with resumes instead of cyber attacks. They're getting flooded by North Korean illegitimate resumes, so much so that legitimate candidates can't get through. It's committing a denial-of-service against their recruiting pipeline. The scale of this is overwhelming. As for North Korea, it's paying off. North Korea began the 9th Congress of the ruling Workers' Party of Korea on Thursday. In his opening address, North Korean leader Kim Jong-un said he is filled with optimism and confidence about the future. We have made significant accomplishments in overcoming economic stagnation, Kim continued, pointing to what he called progress across multiple sectors of state life. In March, the Treasury Department revised its estimates. They said North Korea made $800 million from its remote worker scheme in 2024 alone, far beyond earlier estimates in the mere millions. This exploits how we hire, how we trust, how modern companies actually function. But there's something else these North Korean IT workers have exposed, our part in this. An ugly version of America we don't want to see. I think if we go back to what's the big thing that people need to take away here, the first takeaway is there are thousands of people who are trying to rob U.S. companies of payroll. And the second thing is there are hundreds of Americans who are happy to help them. Because to pull this off at this scale, North Korea can't do it alone. They need our help. Americans, witting or not, willing to do their dirty work. So we haven't been able to find a ton about her on social media. She has a LinkedIn profile, there's no picture on it. It looks like she did have a Facebook profile. And she's young, she's 21. So here we go. Hello? That's next on To Catch a Thief. Follow To Catch a Thief to make sure you don't miss the next episode. And if you like what you hear, rate and review the show. To Catch a Thief is co-produced by me, Nicole Perleroth, and Rubrik, in partnership with Pod People. With special thanks to Julia Lee. To Catch a Thief