Loading market data...

Researchers Posed as DeFi Startup to Track North Korean IT Workers

Researchers Posed as DeFi Startup to Track North Korean IT Workers

Researchers from BCA LTD, NorthScan, and ANY.RUN set up a fake DeFi startup called Ballena Azul LTD to hire suspected North Korean IT workers and watch what they do. The three developers they brought on board are all believed to be part of Famous Chollima, a unit tied to the Lazarus Group that specializes in placing fake IT workers at Western companies. The operation, detailed in a report released this week, shows how these operatives lean on AI tools and forged documents to get through the door.

How the sting worked

The researchers built Ballena Azul as a legitimate-looking startup and used ANY.RUN's sandbox as the work environment, recording every action the hired developers took. That gave them a front-row seat to the onboarding process and the day-to-day work. The developers submitted forged US credentials during onboarding, including driver's licenses, stolen Social Security numbers, and accounts at Lead Bank, Citibank, and Wise.

The forgeries and AI use

The forgeries weren't perfect. Metadata on one fake license showed it was processed with Google Gemini and carried an embedded SynthID watermark, exposing the forgery. The workers also used AI tools like ChatGPT to write code they didn't understand and to complete assignments, and they relied on live translation tools during interviews and standups. That's a pattern that's become common in these schemes, but the level of detail here is striking.

Infrastructure and ties to Lazarus

The operation logged AstrillVPN exit nodes, servers hosted on Vultr and Gorilla Servers, and cryptocurrency wallets with transaction history. One operative server was already tagged across threat intelligence feeds, meaning it had been recycled from earlier campaigns. That's a direct link to the broader Lazarus infrastructure. TRM Labs attributes 76% of 2026 crypto-hack losses through April to DPRK crews, with theft reaching $2 billion in 2025. So this isn't just a hiring risk.

The broader risk

The report argues that DPRK IT worker schemes aren't just about getting a paycheck. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes. That's a much bigger threat than a few lines of code. An Ethereum-funded project previously identified 100 suspected North Korean IT workers across 53 crypto projects, so this is a known problem. The question is how many more are out there.

The researchers didn't say whether they reported the workers to authorities, but the report is a clear warning to companies that think they've vetted their remote hires. The next step is likely for firms to tighten their own onboarding checks, especially around document verification and AI-generated content.