{"slug": "researchers-hired-suspected-north-korean-it-workers-to-expose-their-post-hire", "title": "Researchers hired suspected North Korean IT workers to expose their post-hire playbook", "summary": "Researchers Mauro Eldritch and Heiner Garcia Perez hired three suspected North Korean IT workers into a fake cryptocurrency startup and recorded their post-hire activities, revealing the use of forged identities, AI tools, and remote access infrastructure. The investigation, published by ANY.RUN on August 10th, attributed the workers to Famous Chollima, a North Korea-linked operation tracked by CrowdStrike since at least 2018. The workers, hired for smart-contract, front-end, and back-end roles, used documents with warning signs such as mismatched addresses and AI-generated images, and after receiving legitimate access, they inspected systems, installed remote-access software, and synced personal accounts.", "body_md": "[Mauro Eldritch (@MauroEldritch)](https://x.com/MauroEldritch) and Heiner Garcia Perez say they hired three suspected North Korean IT workers into a fake cryptocurrency startup, then recorded how the developers used forged identities, AI tools and remote access infrastructure after receiving legitimate access to the workplace.\n\nThe researchers detailed the operation in an [investigation published by ANY.RUN on August 10th](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/). They attributed the workers to Famous Chollima, a North Korea-linked operation known for placing developers at Western businesses under false identities. CrowdStrike has tracked Famous Chollima activity since at least 2018, while Microsoft uses the name Jasper Sleet for a North Korea-aligned remote-worker operation. ([any.run](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/))\n\nEldritch, the founder of threat intelligence business BCA LTD and leader of Bitso's Quetzal threat research team, ran the project with Garcia Perez, a financial-crime and cyber threat intelligence analyst associated with [NorthScan](https://northscan.co/). The pair had previously posed as facilitators offering laptops and interview assistance to suspected operatives. Their second experiment followed the scheme through onboarding and into day-to-day engineering work. ([any.run](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/))\n\n### The fake startup offered access worth stealing\n\nEldritch and Garcia Perez created Ballena Azul LTD, or Blue Whale LTD, as a fictional decentralized finance protocol serving large cryptocurrency holders. They built a website, branding, documentation and an online presence, then presented themselves as executives recruiting remote developers.\n\nA suspected Famous Chollima recruiter introduced three candidates for smart-contract, front-end and back-end engineering roles. The researchers interviewed and hired all three. Ballena Azul then requested the identity, address, banking and cryptocurrency-wallet information that an employer might collect during onboarding. ([any.run](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/))\n\nThe documents contained multiple warning signs. One candidate claimed to live in Pasadena, Texas, while presenting a California driver's license and New York banking details. ANY.RUN's report says metadata showed that the license image had been processed with Google Gemini and contained a SynthID watermark. Another candidate supplied a photograph of a New York license bearing a different person's name. A third submitted a Texas license, a Social Security number and banking details.\n\nThose findings line up with established North Korean remote-worker tradecraft. The FBI says the schemes use stolen identities, pseudonymous accounts, proxy computers and facilitators who receive employer-issued devices. Microsoft has separately documented AI-enhanced photographs, fabricated profiles, tailored resumes, VPN accounts and payment records associated with suspected North Korean workers. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-worker-threats-to-u-s-businesses?utm_source=openai))\n\n### Legitimate credentials opened the door\n\nInstead of shipping physical laptops, the researchers gave each hire a virtual desktop built by [ANY.RUN](https://any.run/). Three isolated environments recorded files, network connections and user activity while appearing to operate like ordinary corporate machines.\n\nThe workers first inspected the systems with Windows utilities including `dxdiag`\n\n, `systeminfo`\n\nand `wmic`\n\n, checked their visible IP addresses and installed remote-access software. One worker synchronized a Google account with the virtual desktop, exposing account data to the instrumented environment before opening GitHub and beginning work. ([any.run](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/))\n\nThe observed toolset included AnyDesk, Google Remote Desktop and AstrillVPN, along with ChatGPT, Gemini, Cursor, Visual Studio Code and Remix. Browser extensions included Saved Prompts for GPT, Simplify Copilot, AIApply and Final Round AI. The researchers also observed a service used to share two-factor authentication codes, cryptocurrency wallets and virtual private servers that acted as intermediary access points. ([any.run](https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/))\n\nAI appeared throughout the workflow. The workers used ChatGPT for coding and troubleshooting, while the Gemini-linked license showed how generative tools can support identity fabrication before an interview begins. Google has previously observed North Korean actors using Gemini to draft cover letters, research salaries and jobs, generate code and support fake-worker applications. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai?utm_source=openai))\n\nThe developers' technical performance was uneven, according to the report. They searched for basic smart-contract instructions, moved ChatGPT responses between development tools and struggled to obtain test cryptocurrency. Skill level, however, was secondary to the access they had obtained. Ballena Azul treated them as employees, giving them credentials and permission to interact with code and business systems.\n\nThat distinction makes the remote-worker scheme an insider threat rather than a conventional account compromise. Mandiant has observed suspected North Korean workers performing assigned duties while holding permissions to modify code or administer systems. The Justice Department says related operations have affected hundreds of U.S. businesses, using laptop farms and stolen identities to generate millions of dollars for overseas workers. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/mitigating-dprk-it-worker-threat?utm_source=openai))\n\nThe FBI recommends repeated identity verification, careful review of shipping and work locations, restrictions on remote desktop software and monitoring for unauthorized access tools. The ANY.RUN experiment shows why those checks must continue after the employment contract is signed: a fraudulent hire can use valid credentials, approved devices and normal engineering workflows without exploiting a software vulnerability. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-worker-threats-to-u-s-businesses?utm_source=openai))", "url": "https://wpnews.pro/news/researchers-hired-suspected-north-korean-it-workers-to-expose-their-post-hire", "canonical_source": "https://runtimewire.com/article/researchers-hired-suspected-north-korean-it-workers-fake-defi-startup", "published_at": "2026-08-11 06:23:55+00:00", "updated_at": "2026-08-11 06:37:00.524850+00:00", "lang": "en", "topics": ["ai-tools", "ai-ethics"], "entities": ["Mauro Eldritch", "Heiner Garcia Perez", "ANY.RUN", "Famous Chollima", "CrowdStrike", "Microsoft", "BCA LTD", "Bitso"], "alternates": {"html": "https://wpnews.pro/news/researchers-hired-suspected-north-korean-it-workers-to-expose-their-post-hire", "markdown": "https://wpnews.pro/news/researchers-hired-suspected-north-korean-it-workers-to-expose-their-post-hire.md", "text": "https://wpnews.pro/news/researchers-hired-suspected-north-korean-it-workers-to-expose-their-post-hire.txt", "jsonld": "https://wpnews.pro/news/researchers-hired-suspected-north-korean-it-workers-to-expose-their-post-hire.jsonld"}}