Amazon Identified North Korean IT Worker by Tracking Keystroke Activity
Amazon has identified a North Korean operative masquerading as a U.S.-based systems administrator. This discovery was made through analysis of typing latency rather than traditional background checks.
Amazon has identified a North Korean operative masquerading as a U.S.-based systems administrator. This discovery was made through analysis of typing latency rather than traditional background checks.
Amazon security specialists noticed the worker's keystroke input lag. Typically, data from typing by a remote worker in the U.S. reaches the company's network within tens of milliseconds. However, this particular individual showed a delay exceeding 110 milliseconds.
This anomaly prompted a deeper investigation, revealing that the "U.S. remote worker's" computer was remotely controlled from a different location. The device was physically situated in Arizona to appear legitimate, while the operator was located overseas.
Amazon's Chief Security Officer, Stephen Schmidt, disclosed that this incident is not isolated. Since April 2024, Amazon has intercepted over 1,800 attempts by North Korean IT workers to infiltrate its systems, with a 27% quarter-over-quarter increase in such attempts.
Amazon has identified a North Korean operative masquerading as a U.S.-based systems administrator.
Proactive monitoring was crucial in identifying these operatives. The schemes often involve "laptop farms" in the United States. In this case, an Arizona resident facilitated the fraud by hosting hardware that allowed North Korean actors to route traffic through a U.S. IP address. She has been sentenced to prison.
The objectives of these infiltrations are generally to generate revenue for the North Korean regime and to engage in espionage or sabotage. Although advanced telemetry, such as keystroke tracking, played a key role in detection, other indicators such as improper use of American idioms or English articles were noted as potential red flags.
Robust security software and active monitoring are emphasized as the most effective measures against state-sponsored corporate infiltration.
Based on reporting by GBHackers.
