Inside the fake crypto startup that fooled North Korean IT workers

Table of Contents

A laptop displaying a video conference with four participants wearing headsets, beside a signed document on a desk.

Share

Security researchers have uncovered a five week operation in which suspected North Korean IT workers were recruited into a completely fictional cryptocurrency startup and unknowingly monitored as they worked. The operation, known as Ballena Azul, gave researchers an unusual view into how North Korean operatives use false identities, remote access tools, VPN infrastructure and artificial intelligence while seeking legitimate employment in the crypto industry.

Key Takeaways

  • Security researchers created a fake DeFi startup called Ballena Azul to investigate suspected North Korean IT workers.
  • Three suspected operatives were hired and given controlled virtual machines that recorded their activity.
  • The workers used US identification documents, remote access software, VPN services and AI tools during the operation.
  • Researchers identified infrastructure previously associated with malware linked to North Korean campaigns.
  • The case shows how legitimate employment can give suspected operatives authorized access to company systems without requiring an initial cyberattack.
  • The researchers said the suspected workers were associated with the Famous Chollima operation, although government sources had not independently confirmed that attribution as of August 11.

Researchers Turned a Fake Startup Into a Controlled Experiment

The operation was conducted by cybersecurity researchers Mauro Eldritch of BCA LTD and Heiner García of NorthScan, with infrastructure provided by ANY.RUN. Rather than waiting for suspected North Korean workers to approach a real company, the researchers created Ballena Azul and advertised developer positions. A recruiter connected to the investigation supplied three candidates, who were given programming assignments and access to controlled virtual desktop environments. The researchers were able to monitor their activity throughout the engagement.

The hiring process itself exposed several warning signs. One candidate claimed to be based in Texas but supplied a California driver’s license and a New York bank account. Another provided a Texas license, a valid Social Security number and a Kansas City bank account. A third supplied a New York driver’s license that reportedly belonged to another person.

Researchers also found evidence that some identification documents had been processed using artificial intelligence tools. One image reportedly contained Google’s SynthID watermark, although the researchers did not establish exactly how the watermark was detected.

The Workers Left Behind Valuable Intelligence

Once inside the fake company, the suspected operatives behaved much like legitimate remote developers while simultaneously conducting reconnaissance of their working environments. All three reportedly ran commands including dxdiag, systeminfo and wmic to gather information about their machines. They also checked the apparent location of their internet connections. One worker installed Chrome Remote Desktop and connected a personal Google account to the controlled computer. This potentially exposed browsing history, saved passwords and browser extensions. The worker also logged into GitHub from the same environment.

The researchers identified additional tools associated with the operation, including services used to relay two factor authentication codes, remote access software and VPN infrastructure. AstrillVPN exit nodes were repeatedly observed, a service that has also been associated with North Korean IT worker activity. The browsers contained several AI powered job application and interview tools, including AIApply, Final Round AI and Simplify Copilot.

AI Became a Tool for the Suspected Operatives

The investigation also revealed extensive use of generative AI. According to the researchers, the workers used ChatGPT to assist with coding, writing and technical assignments, including tasks they appeared to struggle with independently. Google Gemini was reportedly used for image manipulation and document alteration. The researchers said the suspected workers did not necessarily need to deploy malware themselves to create a security risk.

Once an operative successfully obtains employment, legitimate credentials can provide access to source code, internal systems, communications and other sensitive company resources. That makes the hiring process itself a potential security boundary.

García described one of the more surprising findings from the investigation:

“Honestly, the biggest surprise was how much of it ran on improvisation.”

The researchers said the suspected workers did not appear to follow a rigid corporate process, instead relying heavily on improvisation and available tools.

The Infrastructure May Reveal More Than the Workers

One of the most valuable discoveries was the external infrastructure used before the workers connected to Ballena Azul’s controlled environments.

Researchers found servers associated with malware families including InvisibleFerret and BeaverTail/OtterCookie, which have previously been linked to campaigns targeting credentials, cryptocurrency wallets and other sensitive information. Some of the servers were already known to researchers, while others appeared to be previously undocumented infrastructure.

That distinction matters because infrastructure can be reused across multiple operations. Identifying a server used by an operative today may therefore provide intelligence about other campaigns or activities connected to the same network.

North Korean It Workers Remain a Crypto Industry Risk

The Ballena Azul investigation comes amid continued warnings about North Korean IT workers obtaining remote employment under false identities.

In July, Consensys disclosed that it had unknowingly engaged a North Korea linked developer through a third party before identifying the threat and terminating access. US authorities have also prosecuted facilitators accused of helping North Korean workers obtain remote jobs using stolen identities. The US Treasury has estimated that North Korean IT worker schemes generated hundreds of millions of dollars for the regime, making employment fraud part of a broader financial strategy rather than simply a cybersecurity problem.

For crypto companies, the danger is particularly significant because developers may have access to source code, wallets, infrastructure and financial systems.

The Fake Company Eventually Disappeared

After several weeks, the researchers ended the operation by introducing another fictional company executive who confronted the workers over inconsistencies in their identities and documentation. The confrontation caused the suspected operatives to leave the communication channels. Researchers then staged an internal dispute and presented Ballena Azul as a company collapsing because of a failed hiring decision.

According to the researchers, at least one of the suspected workers later contacted García privately to apologize and ask whether he was safe. The suspected operatives, they said, still do not know that Ballena Azul was never a real crypto startup.

Conclusion

The Ballena Azul operation demonstrates why North Korean IT worker campaigns pose a different kind of threat to crypto companies. The initial compromise may not involve malware or a stolen password. Instead, the attacker can enter through a legitimate hiring process and receive authorized access from the company itself.

For crypto firms, stronger identity verification, repeated checks after hiring, scrutiny of remote access patterns and careful monitoring of developer environments could become increasingly important as these operations become harder to distinguish from ordinary remote employment.

Disclaimer: This article is intended solely for informational purposes and should not be considered trading or investment advice. Nothing herein should be construed as financial, legal, or tax advice. Trading or investing in cryptocurrencies carries a considerable risk of financial loss. Always conduct due diligence before making any trading or investment decisions.