Fake Crypto Startup Infiltrates Suspected North Korean IT Hires
Researchers ran a five-week operation that built a fake crypto firm, recruited developers and recorded the tools, servers and methods used by suspected North Korean IT workers.
In a five-week operation, cybersecurity researchers created a fictitious crypto company named Ballena Azul to observe how suspected North Korean IT workers operate and connect to employer networks. The team set up the startup environment on the ANY.RUN platform and used an existing UK company registration from 2022 to add apparent legitimacy. Team members assumed false identities as founders and leads, and a reporter joined a recruitment call posing as a venture investor.
Recruiters on GitHub supplied candidate contacts. The researchers onboarded several developers into controlled virtual desktop environments and assigned real programming tasks so they could record live behavior. The operation captured chat logs, AI conversation transcripts, crypto wallet details, VPN exit nodes and hours of video showing participants working and communicating.
Investigators mapped a set of external servers that participants used as stepping stones before reaching the controlled desktops. Analysis linked some of those servers to known malware families, including infrastructure previously associated with InvisibleFerret and BeaverTail/OtterCookie. Other intermediary servers appeared new and were not present on mainstream blocklists. García, one of the investigators, pointed out that the same servers can be reused for distributing malware, for command-and-control, or as proxies for routine access.
Researchers found heavy use of artificial intelligence tools to fill technical gaps. Participants relied on ChatGPT for coding and writing tasks and used Google Gemini for image alteration and document forgery. They also used remote desktop software, crypto wallets and services for sharing two-factor authentication codes. To observe tool choices and reactions, the team introduced controlled technical problems such as selective network outages and disappearing mouse cursors; responses indicated an ad hoc, improvisational approach rather than a fixed, formal process.
At least two participants presented U.S. identification during onboarding. When the researchers staged a confrontation by reintroducing a fictional co-founder named Benito Camella, the chatroom emptied quickly. During the simulated collapse of Ballena Azul the fake co-founder asked, “Are you living two lives, Mr. Anderson?” One participant left immediately and another remained for a time before apparently recognizing the setup. After the operation ended, one of the individuals later contacted a researcher to apologize and check on the researcher’s wellbeing.
The researchers noted previous legal actions tied to similar tactics: U.S. prosecutors charged four individuals in 2025 over the use of false identities to obtain remote IT jobs and steal cryptocurrency, and two U.S.-based hosts were sentenced for providing clusters of machines used to make remote workers appear locally based. A U.S. Treasury estimate found schemes involving remote IT hires generated nearly $800 million in 2024.
The investigative team cautioned it could not independently verify the nationality or formal affiliation of the recruited workers, and no government agency has publicly attributed the individuals to any state. The researchers said the collected data is intended to help defenders track reused infrastructure and improve vetting of remote developers and contractors.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








