Original Title: Smile, You're on Camera. Part 2: Hiring Lazarus APT's IT Workers in a Fake DeFi Startup
Original Source: ANY.RUN
Compiled by: Qin Xiaofeng, Odaily Planet Daily
Editor’s Note: Cryptocurrency enthusiasts who often fall for phishing scams have likely heard of the North Korean hacking group Lazarus Group, known for high-profile attacks including the Bybit ($1.5 billion) theft, the Ronin Network / Axie Infinity bridge attack ($620 million), DMM Bitcoin / Ginco-related attacks ($308 million), the Harmony Horizon Bridge attack ($100 million), and the Atomic Wallet attack ($100 million).
The key to the success of these attacks lies in social engineering—hackers often disguise themselves as normal job applicants, infiltrating cryptocurrency companies over the years, waiting for the right moment.
Recently, the security agency ANY.RUN collaborated with BCA LTD (a company focused on threat intelligence and hunting) and NorthScan (a threat intelligence program exposing North Korean IT worker infiltration) to effectively combat North Korean hacker operatives.
Researchers created a fake DeFi startup and successfully recruited agents from the North Korean Lazarus Group's human infiltration unit, known as “Famous Chollima,” gaining an internal perspective on the actions of North Korean IT workers. The ANY.RUN sandbox environment showcased the operatives' behavioral patterns in real-time, exposing their evolving toolsets, remote access workflows, use of AI tools, and supporting infrastructure.
This investigation went beyond mere recruitment, delving into how these operatives collaborate after being hired, how they acquire and utilize company resources. The findings indicate that North Korean IT workers pose not only recruitment risks; once operatives infiltrate an organization, they can legally access code, systems, intellectual property, and critical business processes.
Below is the report co-authored by the three parties, compiled by Odaily Planet Daily. Enjoy~
In December last year, we first documented the infiltration cycle of “Famous Chollima.” From recruiting accomplices to help them get hired by Western companies, to forging documents, transporting laptops to intermediaries' residences, and even using AI tools for real-time assistance and translation during interviews, we had it all covered.
In that investigation, we disguised ourselves as intermediaries willing to attend interviews on their behalf and lend out laptops in exchange for a percentage of their salaries. The key was that those laptops were actually the ANY.RUN sandbox environment, recording every click and every action they took. This provided us with a wealth of metrics, hours of computer operation footage, and face-to-face interaction videos, resulting in an unprecedented investigation that made headlines in numerous media outlets.
This was no easy task, requiring months of effort while playing the role of their criminal accomplices. Today, we decided to take it a step further.
This time, we no longer pretended to be intermediaries; instead, we transformed into the founders of Ballena Azul LTD. This is a brand new DeFi protocol company, directly collaborating with cross-chain cryptocurrency whales, looking for developers to build its platform. They are developers we can entrust with large sums of money—amounts far exceeding what you and all your friends have combined, so much that you can't even count the commas.
This new chapter has it all: a CEO who is overly confident and does not conduct background checks on employees; fake developers with forged documents; mule accounts used for money laundering; a journalist posing as a venture capitalist; and an Italian lawyer who ultimately triggers the entire situation.
Come on, the show has begun!
First, let’s briefly introduce our main adversaries. Famous Chollima is one of the many branches under the North Korean Lazarus organization. Their goal is simple and direct: to be hired by Western companies.
They target remote positions in industries with high intelligence value and funding. Cryptocurrency, finance, and healthcare have always been their preferred targets, and recent actions have expanded to pharmaceuticals, civil engineering, construction, and other fields. To secure these positions, they rely on forged identities, fake resumes, proxy interviews, remote assistants, and ghost developers, all collaborating to convince companies that the individuals they are hiring are indeed who they claim to be.
Unlike traditional intrusions, their goal is not to breach an organization within hours or days, but to become part of it. Successfully getting hired can provide months or even years of continuous access, including internal systems, source code, intellectual property, and corporate decision-making processes, while also earning a legitimate salary, ultimately funneling funds back to the North Korean regime.
This makes “Famous Chollima” a distinctly different threat. Malware operations can yield astonishing results overnight, but these actions are also highly noisy and come with significant exposure risks. In contrast, the risks associated with employee exposure are lower. The longer they are trusted, the greater their opportunities to collect intelligence, influence decisions, and gradually integrate into the organization. If enough operatives secure positions within the same company, they may ultimately influence engineering decisions, code reviews, pull requests, approvals, or other trust-based processes without exploiting any software vulnerabilities.
Knowing they actively seek such opportunities, we decided to create one for them.
The answer is Ballena Azul LTD.
On the surface, this is the company that “Famous Chollima” dreams of: a DeFi protocol collaborating with cryptocurrency whales across multiple blockchains, seeking experienced developers to help build the platform.
The protocol itself is quite simple. By combining NFTs and other on-chain mechanisms, whale wallets can voluntarily identify themselves and publicly declare ownership. The idea is to reduce unnecessary market speculation during large fund movements, avoiding rumors of trading platforms being hacked, wallets being stolen, or exit scams that could trigger ecosystem panic.
Everything must appear authentic and credible. A professional website, corporate branding, documentation, an online presence, and most importantly, a coherent product. We do this not because we expect investors to believe us, but because we anticipate they will (take the bait).
I transformed into Leonardo Nelson, co-founder of Ballena Azul LTD. My business partner Benito will join our meeting from Italy. Meanwhile, Heiner again plays Andy Jones, the developer and assistant from the first episode. This time he is the technical director of Ballena Azul, personally recommended to me by Benito.
For infrastructure, we chose the most trusted provider: ANY.RUN. Now, everything is ready, just missing developers.
Fortunately, Andy happens to know the right candidate for the position: Angelo Cruz, an ambitious recruiter from “Famous Chollima.”
Angelo Cruz met Andy on GitHub. They started chatting, and soon Cruz persuaded Andy to collaborate, with Andy acting as his trusted assistant to help his developers find jobs.
Andy agreed and quickly introduced Angelo to Ballena Azul LTD (our company), calling it a fantastic opportunity. According to the plan, Ballena Azul LTD would become another lamb to the slaughter. After all, we trust Andy's judgment; we welcome anyone he selects.
Interview with Famous Chollima (Watch video on YouTube)
To create a false sense of trust, Andy suggested that he could lend them his brother's ID, but it was ultimately not used. Soon after, Angelo introduced us to our first engineer: Angelo Espree (the show begins).
Angelo Espree was the first person to accept a position at Ballena Azul LTD, becoming the first North Korean IT worker to join our company and the first individual in our investigation files.
Before the interview, Andy and Angelo agreed on a simple story: they would tell the CEO (me) that Benito already knew Angelo and had personally vouched for him, agreeing to let him join the company.
And so, our first interview began. Angelo is a Real Madrid fan with a background in mathematics, and he would be responsible for developing the company's smart contracts.
Angelo's interview (Watch video on YouTube)
During the interview, we asked Angelo to scan a QR code to confirm his attendance. He complied, of course, falling into the oldest trap. The QR code quietly redirected him to one of our Canary Tokens, recording the trigger's IP address, user agent, and other information. At the time, it seemed like a minor mistake. But later, it became key evidence in exposing a larger conspiracy. We will discuss this later. For now, we were just happy to have made a new friend.
As friends, we explained that Ballena Azul is a completely trust-based environment, and we only intended to recruit people we could genuinely trust. Angelo already had someone in mind: his friend Jack Anderson (one leads to another, continuing to recommend other hacker organization members).
Jack was noticeably quieter and not very fluent in English. Throughout the interview, we noticed him glancing off-screen, as if looking at a real-time translation tool running on another monitor—one of the standard tools of "Famous Chollima." Like Angelo, Jack also studied mathematics and supports Real Madrid, and he was quite serious. Nevertheless, he convinced us, and we welcomed him to join Ballena Azul LTD as a front-end developer.
Jack's interview (Watch video on YouTube)
Things were interconnected; in this line of work, everyone needs someone they can trust. Jack recommended Lucas Theo, a senior back-end developer. We interviewed him. He understood the job requirements, showed a keen interest in the position, and even talked to us about his dog Lulú, his honeymoon in the Philippines, and his love for hiking. We had no reason to doubt him.
So, we welcomed him into the Ballena Azul family as well.
Lucas's interview (Watch video on YouTube)
At this point, they formed the perfect team to execute a daring heist. And on our side, we had a room full of "Chollima" waiting to be tamed.
But you know, any clever lie requires documentation—lots of documentation.
It was time to sign contracts and solidify our alliance. But as an experienced CEO, I needed to conduct a simple background check on the new employees. Asking for identification should be sufficient, right? I also requested their addresses, cryptocurrency wallets, and bank account information—standard onboarding paperwork.
Jack sent a driver's license from Austin, Texas (allegedly where he lived), along with a valid social security number and a bank account from Lead Bank in Kansas City.
Lazarus Jack's fake driver's license
Angelo was much bolder. He claimed to live in Pasadena, Texas, but sent a driver's license from California and a Citibank account from New York.
Angelo's driver's license
The most interesting part was hidden in the metadata. Multiple EXIF entries showed that the image had been processed by Google Gemini and embedded with a SynthID watermark. Combined with obvious visual inconsistencies, the forgery was almost glaringly obvious, yet he was completely unaware.
Metadata of Angelo's driver's license
If this was bold enough, Lucas was even more skilled.
He did not send documents in his name but shared a driver's license belonging to Pui Chin Teoh from New York, along with a Wise bank account. Unlike Angelo's documents, the metadata indicated that this was a real photo taken with an iPhone 15.
Unfortunately for us, the GPS coordinates had been stripped. We suspect Pui Chin is a real person who may have taken a photo of their driver's license for KYC processes or similar purposes, and this photo was later leaked, ultimately falling into Lucas's hands.
Metadata of Lucas's driver's license
At this point, we had forged identities, stolen social security numbers, mule accounts used for money laundering, possible accomplice safe houses, and cryptocurrency wallets with transaction histories.
So, it was finally time for my all-star team to get to work. We weren't ready with the laptops to be shipped, but that was no problem. We told them that our supplier had set up virtual desktops for us, and they could start working immediately. That supplier was ANY.RUN.
Capturing face-to-face footage and recording everything happening inside the machines were equally important, as both provided different pieces of the same puzzle. ANY.RUN allowed us to record every file opened in the system, every network connection, and almost every click, with not a byte escaping our real-time monitoring. These instances were specially tailored for this operation, running like a true VDI for hours.
We launched three independent instances, assigning each developer their own environment; it was time to observe their work.
On the first day, Angelo and the team used almost the same methods as other North Korean hackers to scout their machines. They first ran dxdiag (DirectX Diagnostic Tool), systeminfo, and wmic to gather detailed system information, then checked their displayed geographical location by visiting a legitimate IP query site (this time IP8).
Everything seemed normal, so Angelo felt safe enough to log into his Google account, install Google Remote Desktop (as we saw in the first episode), and sync his account with the machine.
Yes, sync his account.
A costly misclick worth millions
For those unfamiliar with how Google account syncing works, this means that all stored information for that user would be available on this device, including browsing history, search history, saved passwords, and installed extensions. Just because of a misclick, all his information was in our hands. In previous investigations, this allowed us to identify the toolset of "Famous Chollima," including the AI tools they used during the job application process.
However, he seemed unaware, simply continuing to log into his GitHub account as if everything were normal.
The team was making rapid progress on multiple fronts, but that didn’t mean they were doing things right.
Jack was trying to create a front end that didn’t look so generic like Vibe code, which resembled half of the websites on the internet, while Angelo and Lucas struggled with the back end and smart contracts.
They searched for basic knowledge on Google, such as how to build scalable smart contracts, imported an existing MetaMask wallet, and then struggled to gather some cryptocurrency from the testnet faucet. At one point, they even pasted the testnet URL into the wallet address bar, eventually complaining to ChatGPT, "Now they all require real money."
Angelo using ChatGPT
Then, they continued working in their code repository, and since they failed to receive tokens from any faucet, they could only develop using completely fictional assets. At this moment, we seriously doubted whether this was the right business decision. The next quarterly report for Ballena Azul does not look optimistic.
Perhaps it was just a bad day at work; everyone has those days. So, we decided to make things a bit worse.
Previously, we had introduced artificial failures and network interruptions to slow down the agents, then immediately blamed them for "breaking" the laptops we lent them. This time, we retained selective network interruptions while also making the mouse cursor randomly disappear.
(Angelo debugging selective network interruptions)
Whenever they complained, we told them that an IT support person from our vendor would connect to resolve the issue.
What happened next unexpectedly reminded us of what Aaron did to Andy in the first episode, except this time it was between Angelo and one of our "IT support" personnel: chatting through Notepad.
Are you there? (Watch video on YouTube)
Their vibecoding session continued, and now they were struggling to resolve an NPM installation failure while dealing with occasional network interruptions, all while switching between ChatGPT's results in Remix and Visual Studio, hoping everything would go smoothly.
Debugging Node.js issues with ChatGPT
They were busy, understaffed, and under-skilled, with the first week's deadline looming, which was the perfect time to summon an old villain from this series------"Captcha Hell."
(Angelo trapped in an endless captcha loop)
After dealing with a few minutes of captchas, a network failure "forced the VDI to be destroyed," and all unsaved progress was instantly lost.
Days went by, and the thoroughbreds were rampaging in the stable, leaving behind not only erroneous code but also a plethora of traces: AstrillVPN exit nodes scattered around the globe, chat logs, conversations with AI agents, wallet addresses, and hours of facial recordings.
(Building dreams)
But better than all of this, they exposed something more interesting, caught in the act: the agent servers used as proxies and jump points to access the VDI.
This discovery was highly valuable, as their servers often had long lifespans, were frequently recycled, and sometimes hosted multiple families of malware, reflecting the evolution of their actions over time, and accumulating a wealth of tags in the threat intelligence field by the end of their lifecycle.
One of the servers was like this, but the other two servers were hardly discovered, only marked as "scanners" ("this host performs port scanning") and------rather oddly------"honeypots."
However, as days passed, not only did our intelligence collection grow, but Ballena Azul LTD was also expanding. It grew to the point of attracting someone's attention, a venture capitalist eager to meet the next crypto unicorn team.
Mr. Aelin Ashriver works for Definitive Communications (abbreviated as Def-Comm) and expressed interest in funding our dreams. We conducted several "rehearsals" with the team, practicing our team salute: "Hello, Def Comm, we are Ballena Azul LTD!" When the big day finally arrived, everything went smoothly.
During the meeting, Mr. Ashriver asked if we were interested in gaining some media attention, mentioning he could help, even claiming to have close ties with Cointelegraph.
In reality, Mr. Ashriver is Yohan Yun, Cointelegraph's correspondent in Korea, who has always been our accomplice. And you, dear reader, thought our plot twist was over, didn't you?
Definitive Communications decided to invest in Ballena Azul LTD, and you could almost see dollar signs stamped on their retinas. They seemed to have tasted the flavor of money rolling in. Securing one of the first positions in a startup usually means gaining a trusted position, and they could almost feel the cold wallet private keys at their fingertips.
We were reaching the peak. But all that rises... must eventually fall. Thus, our downfall began.
I said we had more twists. Trust me, this is not the last one.
So far, Heiner (Andy) and I (Leonardo Nelson) have been working daily with Jack, Angelo, and Lucas. But if you've been paying attention, there's another name in this equation: Mr. Benito, my co-founder (played by our friend Alejo). He had been busy with work and life in Milan, trusting us to manage everything while he was away. However, when he returned, he found we had turned the house into a stable, and he was very unhappy about it.
Mr. Anderson's multiple lives (Watch video on YouTube)
The first to run away was Angelo, completely terrified. Jack took longer to understand what was happening (mainly relying on real-time translation tools). Benito took full advantage of this, throwing out one Matrix reference after another while we were nearly bursting with laughter ("I'll be as candid as I can, Mr. Anderson," "Are you living a double life, Mr. Anderson?"). Once Jack finally understood the situation, he also left directly.
But it didn't end there. Our Telegram channel turned into a shouting match between me------the betrayed CEO------and Andy------an employee with a rather loose attitude towards labor laws.
I accused him (Andy) of bringing in "illegal labor," still pretending not to fully understand what was really happening, and told him this would get me into trouble.
He retaliated by saying he had to quickly assemble a team under immense pressure, and that the money I paid him was not enough to complete the task. He had done his best under the existing conditions.
The argument continued for a while until I decided to end not only our working relationship but also our friendship, telling him that if he had anything else to say, he could relay it through my assistant or Benito.
In a genuinely respectful human gesture (I mean it), Angelo privately reached out to Andy, asking if he was okay and expressing regret for what had happened between us.
We never heard from the rest of the team again; they still do not know they were the targets of counter-espionage.
If our second season cannot arrange for a returning character who mysteriously disappeared in the first season, what kind of good show would that be?
By the time we formed the team, we were already too deep to back out, so we did what others would do in this situation: keep moving forward and recruit our fifth Beatle. But this one is an old acquaintance of yours and ours. You can listen for yourself and probably recognize that voice.
You’re still alive! (Watch video on YouTube)
Aaron Schulz (the North Korean hacker from the last investigation) made a heroic return and expressed his willingness to join Ballena Azul LTD, but ultimately, we had some irreconcilable differences: he failed to provide a photo ID, "at least wait a month until we can issue the first paycheck." So, he only made a brief cameo, but we were glad to know he was okay.
And there’s another interesting surprise. What would you do if your real-time translation software suddenly failed during the daily stand-up meeting?
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.












![[SCAN 2026 Final Interview] ②J0y_B0y: The Four Students from Jordan's Applied Science Private University Unite](/public-static/25_d4737ee605.png?format=avif)
















