Skip to content

To Catch North Korean Hackers, They Set Up a Fake Project

Aug 15, 10:00
To Catch North Korean Hackers, They Set Up a Fake Project
Original Title: Smile, You're on Camera. Part 2: Hiring Lazarus APT's IT Workers in a Fake DeFi Startup
Original Source: ANY.RUN
Original Translation: Qin Xiaofeng, Odaily Planet Daily


Editor's Note: Crypto enthusiasts who are often targeted by phishing scams have probably heard of the North Korean hacker group Lazarus Group, whose well-known "campaigns" include but are not limited to: the Bybit ($1.5 billion) theft case, the Ronin Network / Axie Infinity bridge attack ($620 million), the DMM Bitcoin / Ginco-related attacks ($308 million), the Harmony Horizon Bridge attack ($100 million), and the Atomic Wallet attack ($100 million).


The key to the success of these attacks often lies in social engineering—hackers usually disguise themselves as legitimate job applicants, infiltrate crypto companies for months or even years, and wait for the right moment.


Recently, the security firm ANY.RUN, in collaboration with BCA LTD (a company dedicated to threat intelligence and hunting) and NorthScan (a threat intelligence program exposing North Korean IT workers' infiltrations), joined forces to effectively combat North Korean hacker operatives.


Researchers created a fake DeFi startup and successfully recruited the "Famous Chollima" operatives specialized in human penetration under the North Korean Lazarus Group, providing an inside look into the actions of North Korean IT workers. The ANY.RUN sandbox environment provided real-time insights into the operatives' behavior, exposing their evolving toolsets, remote access workflows, AI tool usage, and supporting infrastructure.


This investigation went beyond mere recruitment processes and delved into how these operatives collaborate after joining, how they acquire and exploit company resources. The research findings indicate that North Korean IT workers' plans pose not only recruitment risks; once operatives infiltrate the organization, they can legitimately obtain access to code, systems, intellectual property, and critical business processes.


Below is the report jointly authored by the three parties, translated by Odaily Planet Daily, Enjoy~


Introduction


In December last year, we fully documented the infiltration cycle of "Famous Chollima" for the first time. From recruiting accomplices to help them join Western companies, to forging documents, shipping laptops to intermediaries' residences, and even using AI tools for real-time assistance and translation during interviews, the entire process is meticulously orchestrated.


In that operation, we posed as intermediaries willing to participate in interviews on their behalf and lend out laptops in exchange for a percentage of their salary. The crucial part was that those laptops were actually in an ANY.RUN sandbox environment, recording every click and every step of the operation. This provided us with a massive amount of data, hours-long screencasts, and video footage of in-person interactions, leading to an unprecedented investigation that made headlines in numerous media outlets.


(The "Famous Chollima" Recruiter, codenamed "Flame" Aaron)


This was no easy task and required months of effort. We had to thoroughly understand their background while posing as their criminal accomplice. And today, we have decided to take it a step further.


This time, we are no longer posing as intermediaries but have transformed ourselves into the founders of Ballena Azul LTD. This is a new DeFi protocol firm that is directly collaborating with cross-chain crypto whales and is looking for developers to build its platform. These developers are individuals we can trust with a vast sum of money—an amount so significant that it dwarfs what you and all your friends have in your pockets, with so many zeros that you can't even count them.


Ballena Azul LTD Website


This new chapter has it all: an overly confident CEO who doesn't conduct background checks on employees; a fake developer holding forged documents; a money mule account for laundering; a journalist disguised as a venture capitalist; and an Italian lawyer who will ultimately blow the whole scheme wide open.


Let the show begin!


Chapter One: The Chollimas


First, let's briefly introduce our main adversaries. Famous Chollima is one of several branches under the North Korean Lazarus group. Their objective is straightforward: to be employed by Western companies.


They target remote positions in industries with high intelligence value and abundant funds. Cryptocurrency, finance, and healthcare have always been their prime targets, and their recent actions have extended to pharmaceuticals, civil engineering, construction, and other sectors. To secure these positions, they rely on forged identities, fake resumes, proxy interviews, remote helpers, and ghost developers—all working together to make the company believe that the person they have hired is who they claim to be.


(North Korean Operative Captured by Bitso Quetzal Team During Company Interview)


Unlike traditional breaches, their goal is not to compromise an organization within hours or days, but to become a part of it. A successful hire grants them months or even years of ongoing access, including to internal systems, source code, intellectual property, and corporate decision-making processes, all while earning a legitimate salary and ultimately funneling funds back to the North Korean regime.


This makes the 'Famous Chollima' a distinctly different kind of threat. Malware campaigns can have dramatic effects overnight, but they are also incredibly noisy and come with significant exposure risks. In contrast, the risk of employee exposure is lower. The longer they are trusted, the greater the opportunity to gather intelligence, influence decisions, and gradually integrate into the organization. If a sufficient number of operatives secure positions within the same company, they could eventually impact engineering decisions, code reviews, pull requests, approvals, or other trust-based processes without exploiting any software vulnerabilities.


Knowing they actively seek such opportunities, we decided to proactively create one for them.


Chapter Two: The Company


The answer is Ballena Azul LTD.


On the surface, this is the company the 'Famous Chollima' has been dreaming of: a DeFi protocol collaborating with a crypto whale spanning multiple blockchains, seeking experienced developers to help build the platform.


The protocol itself is simple. By combining NFTs and other on-chain mechanisms, the whale wallet can voluntarily disclose its identity and openly declare ownership. The idea is to reduce unnecessary market speculation during large fund movements, avoiding rumors of hacked trading platforms, wallet thefts, exit scams, and ecosystem panics.


Ballena Azul LTD on the OpenSea NFT Marketplace


Everything must appear authentic. A professional website, corporate branding, documentation, online presence, and most importantly, a plausible product. We are doing this not in the hope that investors will believe, but because we anticipate they will take the bait.


(The existing registration information of Ballena Azul LTD at the UK Companies House helps enhance the company's legitimacy. This entity is unrelated to our operation)


I have taken on the persona of Leonardo Nelson, co-founder of Ballena Azul LTD. My business partner Benito will be joining our meeting from Italy. Meanwhile, Heiner is once again playing the role of Andy Jones, the developer and collaborator from the first episode. This time, he is the Chief Technology Officer of Ballena Azul and was personally recommended to me by Benito.


On the infrastructure front, we have opted for the most trusted provider: ANY.RUN. Now, all is set, waiting only for the developer.


Fortunately, Andy happens to know the perfect fit for this role: Angelo Cruz, an aspiring "Famous Chollima" external recruiter.


Chapter Three: Horse Trader


Angelo Cruz first met Andy on GitHub. They started chatting, and soon after, Cruz persuaded Andy to collaborate, with Andy serving as his trusted collaborator to help his developers find jobs.


Angelo looking for collaborators on GitHub


Andy agreed and swiftly introduced Angelo to Ballena Azul LTD (our company), framing it as a fantastic opportunity. As per the plan, Ballena Azul LTD would be another sacrificial lamb. After all, we trust Andy's judgment, and whoever he chooses, we welcome.


Interview with Famous Chollima (YouTube video)


To establish a false sense of trust, Andy suggested that he could lend them his brother's ID card, although this was ultimately not used. Shortly after, Angelo introduced to us our first engineer: Angelo Espree (the show begins).


Chapter 4: Team


Angelo Espree was the first person to accept a position at Ballena Azul LTD, becoming the first North Korean IT worker to join our company and the first individual in our investigative files.


Prior to the interview, Andy and Angelo agreed on a simple cover story: they would inform the CEO (me) that Benito had already known Angelo, personally vouched for him, and agreed to his entry into the company.


And so, our first interview began. Angelo, a Real Madrid fan with a background in mathematics, will be in charge of developing the company's smart contracts.


Angelo's Interview (YouTube Watch Video)


During the interview, we asked Angelo to scan a QR code to confirm his attendance. He did so, falling into the oldest trick in the book. The QR code discreetly redirected him to one of our Canary Tokens, recording the triggerer's IP address, user agent, and other information. At the time, it seemed like a minor mistake. However, it later became crucial evidence in uncovering a larger conspiracy. We will discuss this later. For now, we are just happy to have made a new friend.


As friends, we explained that Ballena Azul is a completely trust-based environment, and we only intend to recruit individuals we can truly trust. Angelo already had someone in mind: his friend Jack Anderson (one and done, moving on to recommend other members of the hacking group).


Jack was notably more reserved, and his English proficiency was not as strong. Throughout the entire interview process, we noticed him glancing off-screen several times, as if looking at a real-time translation tool running on another monitor—the standard tool of the "Famous Chollima." Like Angelo, Jack also studied mathematics, supports Real Madrid, and is not one to mince words. Nevertheless, he convinced us, and we welcome him to Ballena Azul LTD as a front-end developer.


Jack's Interview (YouTube Watch Video)


One thing led to another, and in this line of work, everyone needs a trusted contact. Jack recommended Lucas Theo, a senior backend developer. We interviewed him. He understood the job requirements, showed a strong interest in the position, and even talked to us about his dog Lulú, his honeymoon trip to the Philippines, and his love for hiking. We had no reason to doubt him.


So, we also warmly welcomed him to the Ballena Azul family.


Lucas's Interview (Watch on YouTube)


Thus, they formed the perfect team to carry out the heist of the century. Meanwhile, on our end, we had a room full of "thoroughbreds," waiting to be tamed.


But you know, any sophisticated lie requires documentary evidence—a lot of documentation.


Chapter Five: The Impersonator


It's time to sign contracts and solidify our alliance. But as an experienced CEO, I need to do a simple background check on the new hires. Asking for identification should be enough, right? I also requested their address, cryptocurrency wallet, and bank account information—standard onboarding paperwork.


Jack sent a Texas driver's license (claiming he lived there), along with a valid social security number and a bank account from Lead Bank in Kansas City.


Lazarus Jack's Fake Driver's License


Angelo, on the other hand, was more audacious. He claimed to live in Pasadena, Texas, but sent a California driver's license and an account from Citibank in New York.


Angelo's Driver's License


The most interesting part lies in the metadata. Multiple EXIF entries show that the image was processed with Google Gemini and embedded with a SynthID watermark. Combined with obvious visual inconsistencies, the forgery is almost glaring, yet he remains oblivious.


Angelo's Driver's License Metadata


If Angelo's actions were bold, Lucas took it a step further.


He didn't send his own documents but shared an image of Pui Chin Teoh's New York driver's license and a Wise bank account. Unlike Angelo's documents, the metadata indicated that this was a genuine photo taken with an iPhone 15.


Unfortunately for us, the GPS coordinates had been stripped. We speculate that Pui Chin is a real person who may have taken a photo of their driver's license for KYC purposes or a similar reason, and this photo was later leaked, ending up in Lucas's possession.


Lucas's Driver's License Metadata


At this point, we have uncovered identity fraud, a stolen Social Security number, a mule account used for money laundering, a possible accomplice safe house, and a cryptocurrency wallet with transaction history.


So, it's finally time for my all-star team to get to work. We weren't ready with the laptops to ship, but that's no issue. We informed them that our vendor had set up a virtual desktop environment for us, and they could start immediately. That vendor is ANY.RUN.


Chapter 6: North Korea Task


Capturing face-to-face footage is as crucial as recording everything that goes on inside the machine; both provide different pieces of the same puzzle. ANY.RUN allows us to record every file opened on the system, every network connection, and nearly every click, with not a single byte escaping our real-time monitoring. These instances were custom-tailored for this operation, running for hours just like a real VDI.


We launched three separate instances, assigning each developer their environment—it's time to observe them in action.


On the first day, Angelo and the team used almost identical tactics to other North Korean hackers to recon their machine. They started by running dxdiag (DirectX Diagnostic Tool), systeminfo, and wmic to gather system details and then checked their displayed location by accessing a legitimate IP lookup site (this time IP8).


Everything looked normal, so Angelo felt safe enough to log into his Google account, install Google Remote Desktop (as seen in our first episode), and sync his account with the machine.


Yes, sync his account.


A Multi-Million Dollar Touching Misstep


For those unfamiliar with how Google account syncing works, this means all the user's stored information is made available on this device, including browsing history, search history, saved passwords, and installed extensions. Just with one accidental click, all his information was now in our hands. In a previous investigation, this allowed us to identify the toolset of "Famous Chollima," including the AI tools they used during the hiring process.


However, he seemed unaware and just proceeded to log into his GitHub account as usual.


The team was pushing forward on multiple fronts, but that didn't mean they were doing things right.


Jack was struggling to create a frontend that didn't look so cookie-cutter Vibe-like, like half the sites on the internet, while Angelo and Lucas were wrestling with the backend and smart contracts.


They googled basic knowledge, like how to build upgradable smart contracts, imported an existing MetaMask wallet, and then painfully scraped together some cryptocurrency from the testnet faucet. Once, they even pasted the testnet URL into the wallet address bar and ended up complaining to ChatGPT, saying, "Now they all require real money."


Angelo Uses ChatGPT


Then, they continued working in their code repository, now forced to develop with entirely fictional assets due to the failure to claim tokens from any faucets. At this moment, we seriously doubt if this is the right business decision. Ballena Azul's next quarter financial report is not looking optimistic.


Perhaps it was just an off day at work; everyone has those days. So, we decided to make things a bit worse.


Previously, we had introduced artificial failures and network interruptions to slow down the agent's progress, and then immediately blamed them for "breaking" the laptop we lent them. This time, we maintained selective network interruptions while also making the mouse cursor randomly disappear.


(Angelo debugging selective network interruption)


Whenever they complained, we would tell them that an IT support person from our vendor would connect to help resolve the issue.


What happened next unexpectedly echoed what Aaron did to Andy in the first episode, except this time it was between Angelo and our "IT support" person: communicating via handwritten notes.


Are you there? (Watching YouTube videos)


Their vibecoding session was still ongoing as they struggled to troubleshoot the NPM installation issue, dealt with intermittent network interruptions, and switched between Remix and Visual Studio to see ChatGPT's outputs, hoping for a smooth process.


Debugging Node.js issues with ChatGPT


They were busy, short-staffed, under-skilled, and facing an imminent deadline in the first week, making it a perfect time to summon a classic villain of this series—"CAPTCHA Hell."


(Angelo stuck in an endless CAPTCHA loop)


After dealing with a few minutes of CAPTCHAs, a network failure "forced the VDI to be destroyed," erasing all unsaved progress in an instant.


As the days went by, the thoroughbreds ran amok in the stables, leaving behind not only erroneous code but also a plethora of traces: globally distributed AstrillVPN exit nodes, chat logs, conversations with AI agents, wallet addresses, and hours of facial recordings.


(Building the Dream)


But better than all of this, they exposed something even more interesting, caught red-handed: a special operations server used as a proxy and jump box to access VDI.


This finding was of great value as their servers tend to have a longer lifespan, are often repurposed, sometimes hosting multiple malware families, reflecting their evolution over time, accumulating many labels in the threat intelligence field by the end of their lifecycle.


One such server was in this state, but the other two servers were almost undiscovered, only labeled as a "scanner" ("this host conducts port scans") and—quite oddly—a "honeypot."


However, as the days went by, not only was our intelligence growing, but Ballena Azul LTD was also expanding. It expanded to the point of attracting someone's attention, someone eager to meet the next crypto unicorn team: a VC investor.


Chapter Seven: The Investor


Mr. Aelin Ashriver works at Definitive Communications (Def-Comm for short) and has shown interest in funding our dream. We went through several "drills" with the team, rehearsing our team salute: "Hello, Def Comm, we are Ballena Azul LTD!" When the big day finally arrived, everything went smoothly.


During the meeting, Mr. Ashriver asked if we were interested in getting some media attention, mentioning he could help and even claiming to have a close relationship with Cointelegraph.


In fact, Mr. Ashriver is Yohan Yun, Cointelegraph's correspondent in Korea, and has been our accomplice. And you, dear reader, thought our plot twists had ended.


Definitive Communications decided to invest in Ballena Azul LTD; you could almost see the dollar signs in their eyes. They seemed to have already tasted the flavor of rolling money. Landing one of the initial positions in a startup usually means securing a trusted role, and they could almost feel the cold wallet private key at their fingertips.


We are reaching the peak. But all that goes up... must come down. And so, our downfall begins.


Chapter 8: The Lawyer


I said we had more plot twists in store. Trust me, this is not the last one.


So far, Heiner (Andy) and I (Leonardo Nelson) have been working with Jack, Angelo, and Lucas every day. But if you've been paying attention, there's one more name in this equation: Mr. Benito, my co-founder (played by our friend Alejo). He was away in Milan juggling work and life, trusting us to hold the fort in his absence. However, upon his return and finding the house turned into a stable, he was not pleased.


Mr. Anderson's Various Lives (YouTube Watch Video)


The first to flee was Angelo, utterly spooked. Jack took a bit longer to grasp what was happening (relying heavily on real-time translation tools). Benito seized on this, and as we were nearly bursting with laughter, he kept dropping one after another 'Matrix' reference ("I'll be as frank as possible, Mr. Anderson," "Are you leading a double life, Mr. Anderson?"). Once Jack finally caught on, he, too, made a swift exit.


But it didn't end there. Our Telegram channel turned into a brawl between me—the betrayed CEO—and Andy—the employee with a rather loose view on labor laws.


I accused him of bringing in "illegal labor," still pretending not to fully understand what was really happening, and warned him that this could get me in trouble.


He fired back, saying he had to quickly assemble a team under immense pressure and that the money I paid him was insufficient to get the job done. He had done his best under the circumstances.


The argument continued for a while until I decided to not only end our working relationship but also our friendship, telling him that if he had anything else to say, he could go through my assistant or Benito.


In a genuinely humane gesture (I'm serious), Angelo reached out to Andy privately, inquiring about his well-being and expressing regret over what transpired between us.


We have not heard anything from the rest of the team, and they still do not know that they were the target of a reverse spy.


Extra Episode I: Once Again, Twice Again, and Thrice Again


If our second season cannot arrange for the return of a mysteriously disappeared character from the first season, what kind of show is this?


By the time we formed our team, we were already deeply involved and couldn't back out, so we did what others would do in this situation: moved forward and recruited our fifth Beatle. But this one is a familiar face to you and us. Listen for yourselves; you might be able to recognize that voice.


You're still alive! (Watch Video on YouTube)


Aaron Schulz (the North Korean hacker from the previous investigation) made a heroic return and expressed willingness to join Ballena Azul LTD, but in the end, we had some irreconcilable differences: he failed to provide an ID with a photo, "at least until we can pay the first salary." So, he ended up making a cameo appearance, but we are glad to know he is safe.


Extra Episode II: Cough Syrup


There was another interesting surprise. What would you do if your real-time translation software suddenly failed during a daily standup?


This happened to Jack during one of our daily standups. We noticed that as his speaking turn approached, he seemed more and more flustered in the corner of the meeting room, and we immediately realized that something was wrong on his end, most likely with his real-time translation tool.


So, he handled the situation like a man: by pretending to cough.


Cough Syrup (Watch Video on YouTube)


He was ready to fake a faint if necessary, so this time, we pretended not to notice.


Well, that's our final surprise, anecdote, or strange videotape.


Before we wrap up this episode, let's take a brief look back. Remember, although these guys are fun, they still pose a threat to our company and assets. Perhaps not willingly, perhaps not by choice, but they do pose a threat indeed.


So let's analyze their latest toolkit, update from what we've seen since our last encounter in December last year, and what has changed.


Famous Chollima New Toolkit and Infrastructure


This list includes only the tools we have observed in this new chapter, which may evolve over time or be different in different task force clusters.


· AnyDesk, Google Remote Desktop: Remote desktop software.


· AstrillVPN: VPN service.


· Browser Extensions: Saved Prompts for GPT, Simplify Copilot, AIApply, Final Round AI.


· ChatGPT: Writing and coding. They heavily rely on it to ask trivial questions about things they don't understand, even using it to complete tasks instead of asking us.


· Google Gemini: Image manipulation, especially document forgery.


· 2fa.cn: Sharing two-factor authentication among operatives. We noticed they no longer use authenticator.cc or otp.ee, which we saw in previous encounters.


· Cursor, Visual Studio Code, and Remix: Coding.


· MetaMask, Bitget Wallet: Cryptocurrency wallets.


· ip8.com: Checking their outbound IP address.


· Outlook.com: Previously, we only observed them using Gmail in these encounters.


· System Tools: dxdiag, systeminfo, wmic.


· VPS: Vultr, Gorilla Servers.


This operation concludes here. Unfortunately, it's time to say goodbye! A final reminder to all companies that while there is no foolproof plan, classic strategies still apply:


· Conduct thorough background checks and KYC. If you are a remote-first company, have them done regularly, and include in-person verifications.


· Train your recruitment staff to identify red flags. They are the first line of defense in protecting your company.


· Immediately block AstrillVPN, as well as any services that refuse to comply with takedown requests or law enforcement demands.


· If you encounter a Famous Chollima member, help make them truly "famous" by documenting their faces and sharing with the intelligence community. You will help raise awareness and may prevent an unwitting company from hiring a spy or facing sanctions.


Always Be Suspicious



Never Trust Anyone



Don't Forget to Smile, You're on Camera



Original Article Link


Recommended

Tencent Still Has a Dream

Aug 15, 11:27
Tencent Still Has a Dream

11,742 Shipping Addresses Exposed Alongside Trezor Orders

Aug 14, 19:01
11,742 Shipping Addresses Exposed Alongside Trezor Orders

Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Aug 14, 18:37
Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Tether Receives Fourth Audit, but Transparency Concerns Regarding USDT Remain Unresolved

Aug 14, 17:00
Tether Receives Fourth Audit, but Transparency Concerns Regarding USDT Remain Unresolved

Sandi's Buyback Arithmetic: 2030 EPS to See $787

Aug 14, 16:32
Sandi's Buyback Arithmetic: 2030 EPS to See $787

Hong Kong Dollar Stablecoin 'Great Exodus'

Aug 14, 14:27
Hong Kong Dollar Stablecoin 'Great Exodus'