Crypto

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

2 min read

Security researchers recently conducted a daring social experiment by creating a fraudulent cryptocurrency startup specifically designed to lure in foreign operatives. By launching a fake decentralized finance protocol called Ballena Azul and advertising for developers, the team managed to hire three individuals they suspect are North Korean agents. To monitor every move the newcomers made, the researchers provided them with virtual machines that recorded all activity, turning the workplace into a digital honey pot aimed at uncovering how these infiltrators operate within Western companies.

The deception began during the onboarding process, where the applicants submitted highly suspicious documentation. One candidate claimed to reside in Texas but provided a California driver’s license and a New York bank account. Upon closer inspection, researchers found that the identification image contained metadata indicating it had been processed with Google Gemini and bore a SynthID watermark, proving it was an AI-generated forgery. Other candidates utilized similar tactics, providing stolen Social Security numbers or licenses belonging to entirely different people, highlighting a sophisticated pipeline of identity theft used to bypass standard corporate screening.

Once inside the system, the suspects immediately shifted into reconnaissance mode. On their first day, they ran various commands to profile their hardware and determine the geographical origin of their internet connections. In one notable slip up, one operative installed Chrome Remote Desktop and synced his personal Google account to the secure environment, inadvertently granting the researchers access to his private browsing history and saved passwords. This behavior aligns with broader patterns identified by security firms like CrowdStrike and those mentioned in recent government alerts regarding state sponsored efforts to funnel salaries back to North Korean agencies.

Beyond individual errors, the operation revealed a suite of specialized tools used by these operatives to maintain their covers. The workers relied on AI powered interview assistants and specific VPN services to mask their locations while coordinating via third party sites to share two factor authentication codes. These findings underscore a growing threat where malicious actors do not need to hack into a network when they can simply be hired as legitimate employees. Experts now warn that traditional one time background checks are insufficient, urging companies to implement periodic identity verification and stricter monitoring of remote access tools to prevent such breaches.

Trade Horizon Daily

Find Finance News that Meets Your Needs

One brief, every trading morning. Markets, macro and the money behind the headlines.

No spam. Unsubscribe anytime.