LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

45 Minute Watch Tue Luu,
Threat Detection Engineer

What happens when a newly hired remote worker isn't who they claim to be?

In August 2025, a suspected North Korea-linked IT worker passed standard hiring checks, completed onboarding, and began operating inside a customer's organization.

LevelBlue SpiderLabs identified anomalous behavior and initiated an investigation. Within one business day of the first suspicious activity, the account was terminated; with no evidence of data exfiltration, persistence, or residual access.

In this session, Tue Luu, Threat Detection Engineer with LevelBlue SpiderLabs, walks through the case: what triggered suspicion, how the investigation unfolded, and what it means for organizations relying on standard controls to catch threats that don't look like threats; until it's too late.

In this session, you’ll learn:

  • A step-by-step breakdown of the activity; from onboarding through detection and response
  • How LevelBlue OTX threat intelligence and XDR behavioral analytics worked together to surface the threat
  • The infrastructure and tradecraft used to present as a legitimate remote employee
  • What to look for during hiring and onboarding before access is established
  • Practical approaches to building integrated detection for this type of activity

Watch the Webinar

Related Resources

Current: resourceswebinarshow-we-detected-a-suspected-north-korean-it-worker
Resource: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Webinar

Multi-Hop Phishing: Kits, Clouds, and Chained Attacks

Current: resourceswebinarshow-we-detected-a-suspected-north-korean-it-worker
Resource: resourceswebinarslevelblue-ttp-briefing-q1-2026-trust-abuse-exposes-weaknesses
Webinar

LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses

Current: resourceswebinarshow-we-detected-a-suspected-north-korean-it-worker
Resource: resourceswebinarstracing-a-multi-vector-malware-campaign-from-vbs-to-open-infrastructure
Webinar

Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure