Fortune | FORTUNE 07月04日 19:44
Microsoft suspends 3,000 Outlook and Hotmail accounts created by North Korean IT workers
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

微软揭露了一起由朝鲜IT工人策划的、涉及全球范围的诈骗活动,该活动每年非法获利高达6亿美元,并资助了朝鲜的核武器计划。这些IT工人通过伪造或盗用身份在全球范围内获取技术工作,并利用人工智能技术提升诈骗手段,例如消除语法错误、美化照片等。微软采取行动关闭了数千个虚假账户,并开发了检测工具,以识别和阻止此类活动。该事件凸显了网络安全威胁的复杂性和朝鲜利用技术进行非法活动的严重性。

💻朝鲜IT工人通过伪造或盗用身份在全球范围内获取技术工作,涉及美国等多个国家,并利用“笔记本农场”等方式远程工作,非法获利高达6亿美元,用于资助朝鲜核武器计划。

🕵️‍♂️微软的“Jasper Sleet”项目致力于追踪和打击该诈骗活动,关闭了3000多个虚假账户,并采取措施保护客户,包括开发机器学习解决方案来检测可疑账户和活动。

🤖朝鲜IT工人正在利用AI技术改进诈骗手段,例如消除语法错误、美化照片,甚至使用换脸软件。微软警告称,未来可能出现结合AI语音和视频的诈骗,以欺骗面试官。

💰该诈骗活动涉及“笔记本农场”、身份租赁等多种方式,一些美国人也参与其中,为朝鲜IT工人提供便利,例如出租身份申请工作,或协助安装软件以便远程登录。

The $3.7 trillion tech giant’s Threat Intelligence arm, which refers to the IT worker scheme as “Jasper Sleet,” detailed its efforts to hunt down scammers in a lengthy post this week. The Department of Justice also announced a coordinated takedown in the IT worker scheme, seizing hundreds of laptops, 29 financial accounts, and shutting down nearly two dozen websites. Law enforcement also searched 29 “laptop farms” across the U.S. The laptop farms are sites where accomplices—including Americans—agree to take care of laptops shipped by companies that have unwittingly hired North Koreans for remote jobs. They install software so that the IT workers can log in from overseas or they ship the laptops to other locations, including Russia and China. 

Some Americans have also rented their identities for the IT workers to use in applying for jobs. A nail salon employee in Maryland will be sentenced in August after he was found to be holding 13 jobs remotely that were handled by North Korean IT workers located in China. His 13 jobs paid nearly $1 million. 

The North Korean IT worker scheme is a global conspiracy in which trained workers from the Democratic People’s Republic of Korea (DPRK) are sent around the world to get jobs in tech using fabricated or stolen identities. The workers are legitimate; Microsoft noted some companies that have been victims of the scheme reported that the remote IT workers “were some of their most talented employees.” 

The scheme generates up to $600 million a year, according to UN estimates, and the IT workers share information with more malicious cyber attackers that have stolen billions in crypto. The revenue generated by the scheme and the illicitly heisted crypto are used to fund DPRK authoritarian ruler Kim Jong Un’s nuclear weapons program, according to the FBI and the DOJ

According to Microsoft, the workers are increasingly improving their tactics through the use of AI—eliminating grammatical errors, polishing up photos, and experimenting with voice-changing software.

Jasper Sleet is constantly changing and evolving their profiles across a wide variety of consumer email accounts, senior director of Microsoft Threat Intelligence Center Jeremy Dallman told Fortune in a statement.

Beyond the 3,000 consumer email accounts that were recently taken down, in our efforts to disrupt the actor activity and protect our customers from this threat, Microsoft has continued to takedown persona accounts as they are identified and track the actor’s use of AI,” said Dallman.

At this point, Microsoft hasn’t seen the IT workers using combined AI voice and video just yet, the company said in its warning.

“We do recognize that combining these technologies could allow future threat actor campaigns to trick interviewers into thinking they aren’t communicating with a North Korean IT worker,” Microsoft warned. “If successful, this tactic could allow the North Korean IT workers to do interviews directly and no longer rely on facilitators standing in for them on interviews or selling them account access.”

The IT workers often use the same names and email addresses over and over in crafting their fake personas, using fraudulent profiles on job-networking sites and open-source coding platforms. Microsoft reported the IT workers have also started using AI tools like Faceswap to “move their pictures over to the stolen employment and identity documents” and to generally spruce up their profile pics. 

Beyond the account suspensions, Microsoft said it has launched an array of methods to detect IT worker activity through ID protection and other tools. The company has also developed a custom machine-learning solution that uses “impossible time travel risk detections, most commonly between a Western nation and China or Russia” to identify suspect accounts. 

Introducing the 2025 Fortune 500

, the definitive ranking of the biggest companies in America. 

Explore this year's list.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

朝鲜IT工人 网络诈骗 微软 人工智能 网络安全
相关文章