EPISODE · Mar 17, 2026 · 59 MIN
How to Detect Malicious Remote Workers w/ James McQuiggan
from Antisyphon Training Anticasts · host Antisyphon Training
SummaryCould a nation-state threat actor get hired and stay invisible to your SOC?🛝Webcast Slides-https://www.blackhillsinfosec.com/wp-content/uploads/2026/03/SLIDES_2026-03-11-AntiSyphon-DPRK-Hiring.pdfJoin us for a free one-hour training session with James McQuiggan, CISSP and Advisory CISO, as he teaches you the full lifecycle of North Korea’s AI-enabled IT worker operation, from AI-generated identities and U.S.-based laptop farms to the data theft and extortion that follow once they’re inside.You’ll learn a practical detection and hunting playbook covering behavioral anomalies, identity red flags, and post-hire SOC indicators that catch what background checks miss.If your SOC isn’t hunting for threats that were hired legitimately, this Antisyphon Anti-cast will change that.Chapters(00:00) - Intro – How to Detect Malicious Remote Workers - James McQuiggan (01:06) - DPRK Solution – Did you Hire a North Korean? (02:24) - But Really, Did We Just Hire a North Korean? (04:20) - How comfortable are you to spot deepfakes? (05:35) - Who is James R. McQuiggan (07:31) - Webcast Agenda (09:25) - Overview - North Korea Situation (11:45) - DRPK Education (14:20) - The Ultimate Inside Threat – DPRK Job Opps (16:06) - Attacker's Playbook — Contagious Interview / WageMole Campaigns (17:36) - Investigations – Crowdstrike / Okta / Unit 42 (19:03) - How Identities Are Built – AI Images (20:54) - GenAI Resumes (23:28) - Stateside Assistance (25:12) - Face Swap / Voice Cloning & Webcams ➜ LIVE Deepfakes (25:38) - AI Face Swap Demo (29:44) - Video Camera Real time Video Deepfake Face Swap Interview (30:32) - KnowBe4 Use Case – July 2024 (34:07) - Legal Impact (35:31) - Companies Infiltrated — The Numbers (36:00) - North Korean Farmers Arrested (40:12) - SOC Playbook – Deepfake Dashboard (40:42) - 12 Best AI Deepfake Detector Tools (41:43) - Detecting VOIP Numbers & Identity (42:50) - SOC Telemetry (45:06) - Hiring Flags (45:57) - HR – Hiring Tips (48:13) - Human Risk – AI First Ready Security Team (50:15) - Wrap Up and Q&A (54:28) - James' Survey QR Code CreditsCreators & Guests Deb Wigley - Host Jason Blanchard - Host James McQuiggan - Guest Chat with your fellow attendees in the BHIS Discord server:https://discord.gg/bhisin the #🔴live-chat channel🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.comClick here to watch a video of this episode. Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.comClick here to view the episode transcript.
Embed this episode
NOW PLAYING
How to Detect Malicious Remote Workers w/ James McQuiggan
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.