As North Koreans continue to infiltrate companies by securing remote IT jobs, a pair of <a href="https://bitcomme.com/southeastern-student-raises-concerns-over-financial-aid-delays-cybersecurity-incident/” title=”Southeastern student raises concerns over financial aid delays, cybersecurity incident”>cybersecurity researchers hit back by creating a fake startup to trap them and monitor their activities.
NorthScan’s Heiner García and Mauro Eldritch from Birmingham Cyber Arms LTD managed to hire a trio of suspected North Korean IT workers, who ultimately revealed all their tactics. Footage of their job interviews, video meetings, and activities has also been published online.
As bait, the researchers created a fake startup, Ballena Azul, which pretended to focus on decentralized finance for large holders of cryptocurrency, which North Koreans have been known to target to fund the country’s regime.
Researchers then reached out to a recruiter on the software platform GitHub, known for helping North Koreans land remote IT positions. Ballena Azul then interviewed and hired three suspected North Koreans, who claimed to reside in the US. As evidence, they provided state driver’s licenses and Social Security numbers. But they appeared to have been faked or stolen. For example, one of the IDs appeared to be a forgery generated by an AI image generator. Another state ID was likely stolen from a real person in New York.
During the interview process, the suspected North Koreans also refrained from using AI deepfakes to change and mask their real appearance. Still, one of the hired workers was caught repeatedly glancing off-screen during the interview “as if reading from a second monitor running a live translation tool,” the researchers said.
To monitor the hired North Korean workers, the cybersecurity researchers gave them access to a virtual desktop tool as part of the job. But it was actually remote monitoring software from Any.Run, which was able to record every file opened and every click made.
The monitoring showed the North Koreans were hiding their true whereabouts using the VPN service AstrillVPN. They also relied heavily on ChatGPT to help them answer questions and complete coding tasks. Saved AI prompts were stored and accessed from several browser extensions.
Recommended by Our Editors
FBI Warns About North Korean Hackers Adding Malicious QR Codes to Emails
The 10 Most Monumental VPN Hacks, Ranked
Upgradable Laptop Maker Framework Suffers Breach Affecting All Customers
Another interesting find was that the hired North Koreans struggled to perform their jobs. “They googled the basics, like how to build upgradeable smart contracts, imported an existing MetaMask wallet, and then struggled to scrape together some crypto from testnet faucets,” the researchers wrote.
García and Eldritch presented the findings during a talk at the DEF CON hacking convention last week. To conclude their investigation, the researchers confronted two of the hired North Korean workers about their forged work documentse they realized they had been exposed
Although the cybersecurity industry has been warning about North Korean IT workers infiltrating jobs for years now, the threat continues to persist. An FBI assistant director revealed last month that the North Koreans were able to recently secure a job at a federal government agency, according to the Federal News Network.
About Our Expert
Michael Kan
Principal Reporter
Experience
I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.
Since 2020, I’ve covered the launch and explosive growth of SpaceX’s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I’ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink’s cellular service.
I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.
I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I’m now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I’m always eager to learn more, so please jump in the comments with feedback and send me tips.
Areas of Expertise
Latest By Michael Kan
- FBI: Watch Out for Hackers Trying to Steal Your Nude Photos
- FCC Bans Odyssey Robot Drone Following Evidence It’s Actually From DJI
- Tesla Debuts Starlink On Cybercab as Elon Musk Eyes Industry Adoption
- FCC Preps to Ban Drones From Anzu Robotics Over DJI Licensing Deal
- Calif. City Declares Local Emergency After Cyberattack Disrupts 911 Calls
- More from Michael Kan
