Full Report
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The
Analysis Summary
# Threat Actor: Famous Chollima (Suspected)
## Attribution & Identity
* **Actor Identification:** North Korean (DPRK) IT Workers / State-sponsored operatives.
* **Aliases:** Famous Chollima (associated with the Lazarus Group umbrella).
* **Known Associations:** North Korean parent government agencies, BCA LTD, NorthScan research initiative, and various fraudulent "facilitators" who rent out US identities.
## Activity Summary
The article details a "honey pot" operation by security researchers (BCA LTD, NorthScan, and ANY.RUN) who created a fake Decentralized Finance (DeFi) startup named **Ballena Azul**. Between late 2025 and August 2026, the researchers successfully "hired" three North Korean operatives posing as remote developers. The operatives used forged identities to gain authorized access to internal systems, intending to remit salaries to the DPRK government and potentially conduct internal reconnaissance for future exploitation.
## Tactics, Techniques & Procedures
* **Identity Fraud:** Use of stolen or AI-altered California, Texas, and New York driver's licenses; use of valid Social Security Numbers (SSNs) belonging to US citizens.
* **AI Augmentation:** Using Google Gemini to process forged documents and employing AI job-application extensions (AIApply, Final Round AI, Simplify Copilot).
* **System Reconnaissance:** Immediate execution of profiling commands upon gaining access (`dxdiag`, `systeminfo`, `wmic`).
* **Evasion:** Using AstrillVPN to mask true geographic location and checking connection origin points.
* **Remote Access:** Installation of Chrome Remote Desktop to sync personal accounts and maintain persistent access.
* **Credential/Code Handling:** Using specialized services for 2FA interception (`2fa.cn`, `authenticator.cc`, `otp.ee`).
* **Social Engineering:** Utilizing a "vouching" system where one hired operative recommends another "friend" to infiltrate the organization further.
**MITRE ATT&CK IDs:**
* **T1133:** External Remote Services (VPN/Remote Desktop)
* **T1082:** System Information Discovery
* **T1566:** Phishing (via fraudulent job applications/GitHub engagement)
* **T1078:** Valid Accounts (gaining authorized employee status)
## Targeting
* **Sectors:** Cryptocurrency, Decentralized Finance (DeFi), and general Technology/IT sectors.
* **Geography:** Primarily targeting United States-based companies (notably hiring remote workers).
* **Victims:** Over 100 US companies have been victimized by similar schemes, earning the DPRK over $5 million.
## Tools & Infrastructure
* **VPNs:** AstrillVPN (specifically exit nodes).
* **Cloud Infrastructure:** Vultr, Gorilla Servers.
* **AI Tools:** Google Gemini (for image manipulation), ChatGPT (for interview/application prompts).
* **Communication/Auth:** 2fa[.]cn, authenticator[.]cc, otp[.]ee, Outlook[.]com, Gmail.
* **Productivity/Job Tools:** AIApply, Final Round AI, Simplify Copilot.
## Implications
This operation highlights a strategic shift where threat actors bypass traditional perimeter defenses by becoming "trusted insiders" through the hiring process. These operatives provide a dual threat: they generate direct revenue for the North Korean regime (circumventing sanctions) and provide a low-noise platform for high-impact corporate espionage or supply chain attacks once they gain access to source code repositories.
## Mitigations
* **Enhanced Identity Verification:** Conduct periodic identity checks throughout employment, not just at the time of hire.
* **In-Person Verification:** For remote-first companies, require a live, in-person video session or a third-party physical identity verification service.
* **Technical Controls:** Block known VPN services frequently used by DPRK actors, specifically **AstrillVPN**.
* **Image Forensics:** Train HR and security teams to check document metadata for AI-processing markers (e.g., Google SynthID watermarks or Gemini metadata).
* **Log Monitoring:** Monitor for "Day 1" reconnaissance commands (`systeminfo`, `wmic`) and the installation of unauthorized remote desktop software on corporate machines.