« All posts

Researchers Lure Lazarus's Fake IT Workers Into a Sham DeFi Startup

Researchers built a fake DeFi startup to hire and monitor North Korea's Famous Chollima IT worker operatives using ANY.RUN sandboxes.

Security researchers from BCA LTD, NorthScan, and ANY.RUN built a fictitious DeFi company, Ballena Azul LTD, to attract and hire operatives from Famous Chollima, a North Korean IT worker unit linked to the Lazarus Group. Unlike earlier investigations that focused on the recruitment pipeline, this operation went further by embedding suspected DPRK operatives as actual employees and observing their behavior from the inside.

The team issued company laptops that were actually ANY.RUN sandbox environments, capturing every action taken by the hired 'developers,' including remote access tools, AI-assisted communication, and supporting infrastructure. The setup revealed how these operatives collaborate, forge credentials, and attempt to gain legitimate access to source code, business systems, and decision-making processes.

For engineering teams, the findings show that DPRK IT worker schemes are not merely a hiring-fraud concern but an active insider-threat vector. Once embedded, operatives can influence code reviews, pull requests, and other trust-based engineering workflows without ever exploiting a software vulnerability.