Protect.Computer
NEWS

Researchers Built a Fake Crypto Startup to Catch North Korean IT Workers

· 1 min read · Identity theft Got hacked
Researchers Built a Fake Crypto Startup to Catch North Korean IT Workers

Researchers from BCA LTD, NorthScan, and threat intelligence firm ANY.RUN built a fake decentralized finance (DeFi) startup called Ballena Azul, advertised developer positions, and hired three people they now believe were North Korean operatives. Every virtual machine issued to new employees was recording from day one.

The scheme worked because the workers went through the standard hiring process — interviews, signed contracts, and proper onboarding — giving them legitimate access to source code and internal systems the moment they started. All three workers began day one with reconnaissance: they ran system profiling tools (dxdiag, systeminfo, wmic) and checked what country their connection appeared to originate from. One installed Chrome Remote Desktop and synced his personal Google account to the work machine, handing over his browsing history, saved passwords, and browser extensions. The fake identity documents the workers submitted had visible AI fingerprints: one showed metadata indicating the file had been processed with Google Gemini, and a SynthID watermark — Google’s invisible AI-content marker — was embedded in the image. The workers’ browsers also carried AI-powered job application and interview assistance extensions, including AIApply and Final Round AI. Infrastructure was hosted on Vultr and Gorilla Servers, with AstrillVPN exit nodes used throughout — a tool that security researchers at Silent Push have separately linked to North Korean operations. The research was presented at DEF CON 34 in Las Vegas and coincides with a July 31 joint advisory from eleven governments warning employers to watch for North Korean IT workers seeking remote positions.

The researchers attribute the three workers to the Famous Chollima cluster, which CrowdStrike links to North Korea’s IT worker operation, part of the broader Lazarus umbrella. They recommend periodic identity verification rather than one-time checks at hire, in-person verification for remote-first companies, recruiter training, and blocking AstrillVPN at the network perimeter. Red flags that showed up in this operation: a worker claiming to live in one city but providing identity documents from different states, and AI-edited photos with GPS coordinates stripped.

Sources

Related reading