Wednesday, August 12, 2026
Home » Fake Crypto Startup Traps Suspected North Korean IT Workers and Exposes Their Methods

Fake Crypto Startup Traps Suspected North Korean IT Workers and Exposes Their Methods

Inside the Fake DeFi Startup Built to Study Suspected North Korean Operatives

by Daphne Dougn

Cybersecurity researchers spent five weeks operating a fictitious DeFi company to observe suspected North Korean operatives, revealing reused attack infrastructure, forged identities, AI-assisted work and the risks created when fraudulent developers obtain legitimate corporate access.

MARKET INSIDER — Cybersecurity researchers created a fake cryptocurrency startup and hired suspected North Korean IT workers, turning a familiar infiltration scheme against the alleged operatives and quietly recording their tools, communications and network infrastructure for five weeks.

The workers believed they were developing Ballena Azul, a crypto company preparing to seek venture-capital backing. In reality, the entire workplace—including its executives, virtual desktops and investor pitch—had been constructed by researchers to study how suspected Democratic People’s Republic of Korea, or DPRK, personnel obtain remote jobs and operate after entering a company.

The investigation highlights a growing threat to crypto businesses: malicious actors may not need to hack their way through security systems if they can pass recruitment checks and receive authorized access as employees or contractors.

Key Highlights

  • Researchers operated a fake crypto startup for five weeks to monitor suspected North Korean IT workers inside controlled virtual desktops.
  • The operation exposed chat records, cryptocurrency wallets, VPN exit nodes, remote-access tools and previously unidentified servers.
  • Some infrastructure had reportedly been associated with malware used to steal credentials and crypto-wallet information.
  • The workers relied heavily on generative AI for coding, writing, troubleshooting and allegedly modifying identity documents.
  • US authorities say DPRK IT-worker schemes generated nearly $800 million in 2024, helping finance North Korea’s weapons programs.
  • The case shows why identity checks alone are insufficient protection for crypto companies, software developers and financial institutions.

Researchers built a company to observe suspected operatives

Ballena Azul was created by Mauro Eldritch, founder of cybersecurity company BCA LTD, and Heiner García, a cyber-threat intelligence analyst at Telefónica Tech and founder of NorthScan. Cybersecurity platform ANY.RUN supplied the controlled infrastructure used in the investigation.

The researchers assumed invented managerial identities. Eldritch posed as co-founder “Leonardo Nelson,” while García became “Andy Jones,” the startup’s team leader.

An existing UK corporate registration for an unrelated company named Ballena Azul added apparent legitimacy. British Companies House records show that Ballena Azul Ltd was incorporated in May 2021 and dissolved in October 2022. The researchers did not control that former business but used its publicly available corporate history as part of the fictitious startup’s cover, according to UK Companies House

The operation began after García contacted a recruiter through GitHub whom researchers associated with Famous Chollima, a threat cluster linked by cybersecurity specialists to North Korean remote-worker schemes.

García said the startup needed developers. The recruiter introduced three candidates using the names “Jack Anderson,” “Angelo Espree” and “Lucas Theo,” at least two of whom presented what appeared to be US identification.

The investigation does not establish publicly that every participant was a North Korean national. The attribution rests on the researchers’ assessment of recruitment connections, network behavior, supporting infrastructure and operational techniques. The individuals should therefore be described as suspected DPRK-linked workers rather than definitively identified North Korean agents.

The fake workplace recorded their activity

After being onboarded, the developers received programming tasks and access to virtual desktops controlled by the research team.

That arrangement allowed Eldritch and García to observe how the workers completed assignments, communicated with colleagues, addressed technical problems and connected to company resources. The researchers deliberately introduced complications, including selective network failures and disappearing mouse cursors, to see how the workers responded under pressure.

The exercise produced hours of video recordings as well as chat logs, AI conversations, cryptocurrency-wallet information, remote-access activity and VPN exit nodes, according to the researchers’ report published by ANY.RUN investigation

One of the more unexpected conclusions was that the operation appeared less disciplined than the researchers had anticipated.

García said much of the workers’ behavior depended on improvisation rather than a standardized corporate process. That finding complicates the common perception of state-linked operations as uniformly sophisticated. Individual workers may have uneven technical abilities while still participating in a broader system supported by recruiters, false documents, intermediary servers and remote-access infrastructure.

The absence of an inflexible playbook may also make detection more difficult. A company cannot assume that every suspected operative will make the same technical mistake or display an identical working pattern.

Exposed servers may provide the most valuable intelligence

The external servers used by the suspected workers were among the investigation’s most significant findings.

Before reaching Ballena Azul’s controlled virtual desktops, the workers connected through intermediary infrastructure. Such servers can obscure an operator’s physical location and make overseas workers appear to be connecting from countries acceptable to employers or freelance platforms.

Researchers said some of the identified servers had previously been connected to InvisibleFerret, BeaverTail and OtterCookie, malware families associated with campaigns targeting credentials, browser data and cryptocurrency wallets.

Some of those servers remained active despite their alleged involvement in earlier malicious activity. Others had no existing records in commonly used threat-intelligence feeds or blocklists, making them potentially valuable new indicators for cybersecurity teams.

Infrastructure can also be repurposed. A server previously used to distribute malware may later act as a proxy, a command-and-control endpoint or an intermediary for routine remote work.

That overlap is important because it connects employment fraud with more conventional cyber operations. A remote developer may appear to be performing ordinary software work while relying on infrastructure previously associated with malicious campaigns.

The researchers’ findings may help businesses, exchanges and security providers identify related activity elsewhere. However, individual internet addresses cannot prove attribution on their own. Infrastructure may be compromised, shared, resold or used by several unrelated actors, so any indicators need to be evaluated alongside identity, device and behavioral evidence.

Legitimate access may be more dangerous than malware

The Ballena Azul operation illustrates why a North Korean IT worker does not necessarily need to install malicious software to create significant risk.

Once hired, a developer may receive legitimate credentials for source-code repositories, internal communications, cloud environments, payment systems and product-development tools. Security controls may treat that person as a trusted user because the access was formally approved during onboarding.

For a crypto company, the consequences can be particularly severe. Software engineers may work with smart contracts, private application programming interfaces, treasury systems or deployment procedures. Even when an employee cannot directly transfer funds, knowledge of the system’s architecture could make a later attack easier.

Access can also facilitate intellectual-property theft, credential collection or the introduction of concealed vulnerabilities into source code. A fraudulent worker who remains undiscovered for months may receive wages while gradually learning which systems and employees are most valuable.

This changes the cybersecurity problem from a conventional perimeter attack into an identity and governance failure. Firewalls and malware scanners provide limited protection when an attacker has been invited inside and granted access consistent with an employee’s assigned role.

Generative AI lowered the skills barrier

The suspected workers repeatedly turned to generative AI when they struggled with assignments, according to the researchers.

They used ChatGPT for writing, coding and answering relatively basic technical questions. The investigators also observed the use of Google Gemini for image modification and suspected document forgery. Other services included remote-desktop software, cryptocurrency wallets and a tool for sharing two-factor authentication codes.

AI did not make the workers uniformly capable. It helped them compensate for gaps in knowledge and produce work that might appear credible during recruitment or early employment.

This creates a new challenge for hiring teams. A technically weak candidate can use AI assistance during written interviews, coding assessments and routine tasks, delaying the point at which an employer recognizes discrepancies between claimed experience and actual ability.

The technology can also improve language, generate professional messages, alter profile images and help maintain several constructed identities. None of these uses proves state involvement, but together they can make identity fraud cheaper and more scalable.

The pattern is part of a broader development in North Korean cyber operations. South Korean cybersecurity company Genians reported that Kimsuky, a separate North Korea-linked espionage group, had assembled tools for running AI models locally. The software could potentially help analyze stolen documents, automate parts of cyber operations and produce more convincing phishing material.

Genians’ findings were not independently verified, but they suggest North Korean groups may be progressing from the use of public chatbots toward locally operated AI systems that can process sensitive data without sending it to outside providers, according to Reuters

The financial scale extends beyond individual employers

North Korean remote-worker operations have become a significant source of revenue for Pyongyang, according to US authorities.

The  US Treasury Department said in March that DPRK-orchestrated IT-worker schemes generated nearly $800 million during 2024. It said the proceeds supported North Korea’s weapons-of-mass-destruction programs.

The schemes commonly involve workers using stolen or fabricated identities to obtain jobs at companies in the United States and other countries. Salaries may then pass through intermediaries, payment platforms, front businesses or cryptocurrency accounts before funds reach DPRK-linked networks.

Revenue from legitimate-looking employment is only one component of the risk. Access obtained through those jobs can create opportunities for theft.

US federal prosecutors charged four North Korean nationals in June 2025 with using false identities to secure remote work and allegedly stealing more than $900,000 in cryptocurrency from two employers. Prosecutors said one defendant took approximately $175,000 after gaining access to virtual assets, while another allegedly stole about $740,000 by modifying smart-contract source code.

The accusations remain allegations unless proved in court, but the case demonstrates the financial exposure created when developers receive access to blockchain infrastructure, according to US Department of Justice

Laptop farms help workers appear locally based

Remote hiring controls frequently rely on location signals such as internet addresses, device records and regional account information. DPRK-linked networks have responded by using computers physically located inside the country where a worker claims to live.

So-called laptop farms consist of employer-issued or privately supplied computers hosted by facilitators. Overseas workers connect remotely to those devices, causing company systems to see a domestic internet connection even though the person controlling the machine may be thousands of kilometers away.

In May, two US nationals were sentenced to 18 months in prison for facilitating separate laptop-farm schemes. US Department of Justice said their activities enabled North Korean IT workers to appear US-based, generated more than $1.2 million and affected nearly 70 companies. 

Another 2025 case involved an Arizona woman sentenced to more than eight years in prison. Prosecutors said her operation helped overseas workers obtain positions at more than 300 US companies and generated over $17 million for herself and North Korea.

These cases show why checking a candidate’s internet location is not sufficient. A connection originating in New York, California or another expected location may only indicate where the intermediary computer is situated—not where the worker is physically present.

The workers were eventually confronted

After five weeks, the researchers introduced another fictitious executive named “Benito Camella,” described as a Ballena Azul co-founder returning from business in Milan.

During a video meeting, Camella challenged the workers about discrepancies in their identities and documents. One participant left the call quickly, while another remained until it became clear that the supposed company was unraveling.

The researchers continued the deception in Ballena Azul’s Telegram channel. The fake chief executive accused team leader Andy Jones of recruiting illegal workers and exposing the company to serious risk. Jones claimed he had been under pressure to build a team rapidly and was inadequately paid.

The staged dispute ended with the apparent collapse of the startup and the termination of the executives’ professional and personal relationship.

One suspected worker later contacted García privately to apologize and ask whether he was safe. According to the investigators, the other participants disappeared and apparently never realized that the startup had been created to monitor them.

What crypto companies should learn from Ballena Azul

The central lesson is that remote-worker fraud cannot be treated solely as a recruitment problem.

Identity verification at the start of employment remains important, but sophisticated schemes can combine stolen records, altered documents, local intermediaries and laptop farms. Controls should therefore continue after hiring.

Live interviews can help establish whether the person performing the job matches the candidate who was assessed. Companies should verify identity through more than one independent channel and examine unexplained inconsistencies across résumés, employment history, location records and payment details.

Technical access should follow the principle of least privilege. Developers should receive only the permissions necessary for their current work, with sensitive actions requiring additional approval. Code changes, smart-contract deployments, treasury activity and access to production credentials need separation of duties and auditable review.

Companies should also monitor unusual remote-access patterns without treating geography as conclusive proof of misconduct. Indicators may include frequent device changes, persistent use of remote-control tools, logins that conflict with working hours, shared authentication methods or multiple employees using closely related infrastructure.

Crypto businesses face a greater need for these controls because source-code access can sometimes become financial access. An undetected change to a smart contract or transaction-signing process may have irreversible consequences.

Why the investigation matters to investors

For investors, the Ballena Azul case demonstrates that human-capital controls have become part of operational and financial risk assessment.

Crypto exchanges, blockchain developers, custodians and decentralized-finance platforms often operate internationally and hire remote technical specialists. That approach gives companies access to global talent, but it can also weaken traditional workplace checks.

Boards and investors should ask how portfolio companies verify remote workers, control source-code access, review software deployments and respond to compromised identities. They should also examine whether contractors supplied by third parties receive the same scrutiny as direct employees.

A company can have strong encryption and sophisticated blockchain security while remaining vulnerable through its hiring process. The cost of failure may include stolen assets, intellectual-property loss, sanctions exposure, incident-response expenses and lasting reputational damage.

Ballena Azul was fictitious, but the risk it exposed is real. The suspected workers did not have to breach the startup’s defenses because the researchers deliberately hired them. Genuine businesses may be doing the same thing unknowingly—and may not discover the mistake until access has already been converted into financial or strategic harm.

You may also like