In a nutshell: A fake crypto start-up set up by security researchers exposed three suspected North Korean IT operatives on their very first day of work through forged documents, telltale VM activity and typical obfuscation patterns such as AstrillVPN use.
Security researchers built the fictitious DeFi company Ballena Azul to document the hiring methods of North Korean IT workers. All three candidates hired were exposed on their very first day of work on a monitored sandbox machine.
The threat intelligence firm BCA LTD, the research initiative NorthScan and the sandbox provider ANY.RUN founded the fictitious DeFi company Ballena Azul in order to covertly observe hiring processes. Through an intermediary active on GitHub, the researchers gained access to an initial developer, who in turn referred further candidates — a classic referral chain. All three submitted application files showed signs of forgery: one applicant listed an address in Texas but submitted a California driver’s license and a New York bank account. The image data showed traces of editing by Google’s AI model Gemini, including a SynthID watermark. The second applicant submitted a Texas driver’s license with a valid Social Security number and a bank account in Kansas City, while the third submitted a New York driver’s license belonging to a different person along with a genuine iPhone 15 photo from which the GPS coordinates had previously been removed.
All three candidates went through the regular hiring process, including an interview, contract, and access to a prepared, fully monitored work VM. On their very first day of work, they ran system commands such as dxdiag, systeminfo and wmic to reconnoiter the machine and checked the apparent country of origin of their internet connection. One operative additionally installed Chrome Remote Desktop and synced his personal Google account with the sandbox, exposing browser history, saved passwords and extensions; he also logged into GitHub on the same machine. AI-powered job application and interview extensions such as AIApply, Final Round AI and Simplify Copilot were found on the machines, as well as a tool for managing saved ChatGPT prompts. To obscure their activity, the operatives used the service 2fa.cn to exchange two-factor codes between multiple participants and consistently relied on AstrillVPN exit nodes; the associated infrastructure was hosted with Vultr and Gorilla Servers.
For CISOs, the practical relevance lies in the concrete detection patterns, which also apply beyond this investigation: forged or image-edited identity documents, a single account used within a short period from numerous different addresses, and profile texts that appear machine-translated. A joint advisory issued by eleven governments on 31 July 2024 explicitly names these indicators and points out that North Korean IT workers specifically target remote contracts in order to funnel salaries to higher-level authorities in North Korea. In April, the US Department of Justice had already convicted two US citizens who supported a comparable scheme, which, according to authorities, generated more than 5 million US dollars for North Korea via more than 100 affected US companies and at least 80 stolen identities.
The researchers, who presented their findings at DEF CON 34 in Las Vegas, attribute the three individuals to the group Famous Chollima, which they place within the broader Lazarus ecosystem. For companies, they recommend not conducting identity verification only once at the time of hiring but performing it on a recurring basis, planning in-person verification for fully remote teams, specifically training recruiters to recognize such patterns, and specifically blocking or at least monitoring access via AstrillVPN.
Source: www.it-daily.net · Published 16 August 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.