Undercover Op Exposes North Korean IT Operatives Posing as Remote Workers
Security researchers successfully lured suspected North Korean IT operatives by creating a fake cryptocurrency startup and advertising developer jobs. This elaborate sting operation provided critical insights into the tactics and tools used by state-sponsored actors to infiltrate organizations and funnel funds back to their regime.
A collaborative effort by security researchers has unveiled the sophisticated methods employed by suspected North Korean IT operatives seeking remote work opportunities. By establishing a fabricated cryptocurrency startup, **Ballena Azul**, and offering developer positions, researchers managed to attract and monitor three individuals believed to be associated with North Korean cyber espionage efforts.
Every virtual machine issued to these hires was meticulously recorded, offering a unique glimpse into their initial reconnaissance and operational habits.
### The Onboarding Trail: Red Flags and Digital Footprints
The hiring process quickly revealed a series of inconsistencies and red flags. The first applicant claimed residency in Pasadena, Texas, yet submitted a California driver's license and a New York bank account. Crucially, image metadata showed the driver's license had been processed with **Google Gemini**, complete with a **SynthID** watermark β an invisible marker Google embeds in AI-generated or edited images. While **Google Gemini** can detect these watermarks, a negative result doesn't preclude editing by other AI tools.
The second operative provided a Texas license, a valid Social Security number, and a Kansas City bank account. The third presented a New York license belonging to another individual and an authentic iPhone 15 photograph with stripped GPS coordinates.
These findings align with a July 31 joint alert from multiple governments, warning employers about North Korean IT workers who seek contracts with the intent of remitting salaries to their parent agencies. The alert specifically highlighted the use of documents "forged or altered using image editing software" as a key indicator.
### A Sequel to Previous Investigations
This operation serves as a follow-up to a late 2025 investigation by **Mauro Eldritch** of **BCA LTD**, **Heiner GarcΓa** of **NorthScan**, and **ANY.RUN**, a provider of interactive malware analysis and threat intelligence. In that earlier effort, researchers posed as a facilitator willing to rent out their identity, an operation previously covered by The Hacker News.
This time, the researchers took on the role of the employer. A recruiter, actively searching **GitHub** for potential facilitators, brought in the first developer, who then vouched for two others.
### Initial Reconnaissance and Tooling
Upon gaining access to their work VMs, all three operatives immediately began reconnaissance. They executed `dxdiag`, `systeminfo`, and `wmic` commands to profile their machines and checked their connection's apparent country of origin. One individual went further, installing **Chrome Remote Desktop** and syncing their personal Google account, potentially exposing browsing history, saved passwords, and installed extensions. This operative also logged into **GitHub** from the sandboxed environment.
The observed tooling differed from the December operation. Researchers noted the use of **2fa.cn** for passing two-factor authentication codes, in contrast to the previous use of `authenticator.cc` and `otp.ee`. **Outlook.com** also appeared as a communication platform, alongside **Gmail**.
Their browsers were equipped with AI-powered job application and interview assistance extensions, including **AIApply**, **Final Round AI**, **Simplify Copilot**, and a saved-prompts tool for **ChatGPT**. Infrastructure was traced to **Vultr** and **Gorilla Servers**, with **AstrillVPN** exit nodes consistently observed. **Silent Push** has independently tracked **AstrillVPN** as a common fixture in North Korean operations.
### Recommendations and Attribution
Researchers recommend implementing periodic identity checks rather than a single check at hire, in-person verification for remote-first companies, enhanced recruiter training, and blocking **AstrillVPN**. The July 31 advisory further advises vigilance for a single account accessed from numerous IP addresses within a short timeframe and profile text that appears to be machine-translated.

Attribution for this operation rests with the researchers, who presented their findings at **DEF CON 34**. They describe the three individuals as suspected operatives of **Famous Chollima**, a designation used by **CrowdStrike** for North Korea's IT worker operations, which the research team places under the broader **Lazarus Group** umbrella. However, no government source has yet officially confirmed this identification, and the real names behind the personas remain unknown.