Researchers from BCA LTD and NorthScan used ANY.RUN infrastructure to create a fake DeFi company, Ballena Azul LTD, and observed suspected Famous Chollima operatives tied to the Lazarus ecosystem as they moved through recruitment, interviews, and onboarding. The workers allegedly relied on forged or stolen identity documents to obtain employment and were placed into controlled virtual desktop environments, allowing investigators to monitor their behavior while they attempted to carry out software development tasks for the company.
The operation captured the use of remote access tools, VPNs, AI assistants, cryptocurrency wallets, and proxy/VPS infrastructure, including Google Remote Desktop, AstrillVPN, ChatGPT, Google Gemini, and 2fa.cn. Researchers said the activity demonstrates that DPRK IT worker schemes extend beyond simple hiring fraud and can create a persistent insider threat with potential access to source code, internal systems, intellectual property, and trusted business processes; the findings were further amplified in social media posts linking the operation to Lazarus-linked #ITWorker and #FamousChollima activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A Bluesky post by the account lazarusholic linked to the AnyRun article and associated it with Lazarus-linked IT worker activity using the hashtags #ITWorker and #FamousChollima. The post served as social-media amplification of the published investigation.
An article titled "Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup" published the investigation’s findings, describing the DPRK IT worker scheme as a long-term insider threat rather than simple hiring fraud. The report linked the activity to Famous Chollima under the Lazarus umbrella and highlighted risks to source code, systems, intellectual property, and trusted business processes.
Silent Push publicly released new IP addresses associated with Astrill VPN, describing the service as heavily used by North Korean threat actors. The disclosure added infrastructure indicators relevant to tracking DPRK-linked operations.
Before the Ballena Azul employer-side operation, researchers from BCA LTD, NorthScan, and ANY.RUN conducted an earlier late-2025 investigation in which they posed as a facilitator willing to rent out an identity to suspected DPRK IT workers. The newer operation was described as a follow-on approach that shifted from facilitator impersonation to acting as the employer.
The monitored workers were seen using Google Remote Desktop, AnyDesk, AstrillVPN, GitHub, ChatGPT, Google Gemini, Visual Studio Code, Remix, MetaMask, testnet faucets, and browser extensions tied to AI-assisted work. Researchers also identified 2fa.cn for shared two-factor authentication and infrastructure including Vultr, Gorilla Servers, and operative proxy or vantage-point servers.
After receiving separate ANY.RUN virtual desktop instances instead of physical laptops, the operatives used tools such as dxdiag, systeminfo, and wmic to inspect their systems and checked apparent geolocation and exit IP information via ip8.com. This behavior helped researchers observe how the workers validated and prepared their assigned environments.
During Angelo Espree’s interview, a QR code redirected to a Canary Token that captured connection details including IP address and User-Agent. Submitted onboarding documents showed inconsistencies and signs of manipulation, including a Google Gemini SynthID watermark in Espree’s identity document metadata and a likely reused authentic ID image submitted by Lucas Theo.
Using facilitator and fake leadership personas, the researchers recruited candidates introduced by a recruiter identified as Angelo Cruz and hired Angelo Espree, Jack Anderson, and Lucas Theo into smart contract, front-end, and back-end development roles. During interviews and onboarding, the team collected identity documents, addresses, wallet details, and banking information from the candidates.
Researchers from BCA LTD and NorthScan created a fake company, Ballena Azul LTD, and used ANY.RUN virtual desktop environments to recruit and observe suspected Famous Chollima operatives linked to the Lazarus ecosystem. The operation was designed to document recruitment, onboarding, tooling, and infrastructure used by the workers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourceunchainedcrypto.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourcethehackernews.com
Open sourcebsky.app
Open sourcemalware.news
Open sourceany.run
Open sourcesilentpush.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.