BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

The annual phishing extravaganza: A fake DeFi trap catches North Korea's Lazarus hackers red-handed

秦晓峰
Odaily资深作者
@QinXiaofeng888
2026-08-14 07:28
This article is about 9502 words, reading the full article takes about 14 minutes
Real Madrid fan, math background, only uses AI to write code.
AI Summary
Expand
  • Core Takeaway: Security researchers infiltrated the "Famous Chollima" hacking group under North Korea's Lazarus syndicate by setting up a fake DeFi company, uncovering their complete workflow of infiltrating Western companies through forged identities, AI tools, and remote collaboration—while exposing their ever-evolving toolkit and infrastructure.
  • Key Elements:
    1. Researchers posed as recruiters and hired three North Korean operatives over several months, using the ANY.RUN sandbox environment to record their operational behavior, tool usage, and collaboration patterns in real time.
    2. The operatives used forged driver's licenses, stolen Social Security numbers, and mule accounts to complete the onboarding process. Some of the documents were processed with Google Gemini and carried SynthID watermarks, revealing traces of forgery.
    3. The attackers relied on AI tools such as ChatGPT and Google Gemini for coding, translation, and file modification, while using AstrillVPN, remote desktop software, and dedicated servers to covertly access corporate environments.
    4. The three operatives displayed insufficient skills during development, frequently searching for basic questions, and exposed more proxy servers and infrastructure details under selective network outages and CAPTCHA inducements.
    5. The investigation revealed that Famous Chollima aims for long-term infiltration within corporate environments, legitimately obtaining access to code, systems, and intellectual property—not just short-term attacks—making the threat notably persistent.

Original article by security company ANY.RUN 

Compiled by Odaily Planet Daily  Qin Xiaofeng (@QinXiaofeng 888 )

Editor's Note: Crypto enthusiasts who frequently fall victim to phishing are likely familiar with the North Korean hacker group Lazarus Group. Their most notable "campaigns" include, but are not limited to: the Bybit theft ($1.5 billion), the Ronin Network / Axie Infinity bridge attack ($620 million), the DMM Bitcoin / Ginco-related attack ($308 million), the Harmony Horizon Bridge attack ($100 million), and the Atomic Wallet attack ($100 million).

The key to these successful attacks lies in social engineering—hackers typically disguise themselves as legitimate job applicants, infiltrating crypto companies over long periods of time, waiting for the right moment.

Recently, security firm ANY.RUN joined forces with BCA LTD (a company dedicated to threat intelligence and hunting) and NorthScan (a threat intelligence program exposing North Korean IT worker infiltration). Together, the three parties coordinated efforts to effectively strike against North Korean hacker operatives.

Researchers created a fake DeFi startup and successfully recruited "Famous Chollima" operatives—specialists in human infiltration under the Lazarus Group—thereby gaining an inside view of North Korean IT worker operations. ANY.RUN's sandbox environment provided real-time visibility into the operatives' behavioral patterns, exposing their evolving toolset, remote access workflows, AI tool usage, and supporting infrastructure.

This investigation went beyond mere recruitment, offering an in-depth look at how these operatives collaborate after onboarding and how they obtain and exploit company resources. The findings show that the North Korean IT worker program poses more than just a hiring risk; once operatives infiltrate an organization, they can legitimately gain access to code, systems, intellectual property, and critical business processes.

Below is the joint report compiled by the three parties, translated by Odaily Planet Daily. Enjoy~

——————————

Introduction

Last December, we documented the complete infiltration cycle of "Famous Chollima" for the first time. From recruiting accomplices to help them get hired at Western companies, to forging documents, shipping laptops to middlemen's residences, and even using AI tools for real-time assistance and translation during interviews—we had it all under control.

In that investigation, we posed as middlemen willing to take interviews on their behalf and lend out laptops in exchange for a percentage of their salaries. The key was that those laptops were actually ANY.RUN sandbox environments, recording every click and every action they took. This provided us with a massive trove of indicators, hours of computer operation footage, and face-to-face encounter recordings—resulting in an unprecedented investigation that made headlines across numerous media outlets.

("Famous Chollima" recruiter, Aaron, codenamed "Blazing")

This was no easy feat—it required months of effort, learning their secrets while playing the role of their criminal accomplice. And today, we've decided to go even further.

This time, instead of posing as middlemen, we transformed ourselves into the founders of Ballena Azul LTD—a brand-new DeFi protocol company working directly with cross-chain crypto whales, looking for developers to build its platform. These were developers we could entrust with enormous sums of money—amounts so large they'd dwarf everything you and all your friends have, so much that you'd lose count of the commas.

Ballena Azul LTD / Blue Whale LTD Website

Ballena Azul LTD website

This new chapter had everything: an overconfident CEO who doesn't run background checks on employees; fake developers holding forged documents; mule accounts used for money laundering; a journalist disguised as a venture capitalist; and an Italian lawyer who ultimately set off the bomb.

Come on, the show has begun!

Chapter 1: The Chollimas

First, let's briefly introduce our main adversaries. Famous Chollima is one of the many sub-groups under North Korea's Lazarus organization. Its goal is simple and direct: to get employed by Western companies.

They target remote positions in industries where both intelligence value and financial rewards are exceptionally high. Cryptocurrency, finance, and healthcare have historically been their top targets, while recent operations have expanded into pharmaceuticals, civil engineering, construction, and other sectors. To secure these positions, they rely on fake identities, fabricated resumes, proxy interviews, remote facilitators, and ghost developers—all working in concert to convince companies that the person they're hiring is who they claim to be.

DPRK Operatives caught

(North Korean operatives caught by the Bitso Quetzal team during a company interview)

Unlike traditional intrusions, their goal isn't to breach an organization within hours or days—it's to become part of it. Successful onboarding provides months or even years of continuous access, including internal systems, source code, intellectual property, and corporate decision-making processes, all while earning legitimate salaries and ultimately funneling funds back to the North Korean regime.

This makes "Famous Chollima" a distinctly different kind of threat. Malware operations can produce dramatic results overnight, but they're also noisy and carry significant exposure risk. By contrast, employee infiltration carries lower risk. The longer they're trusted, the greater their opportunities to gather intelligence, influence decisions, and gradually integrate into the organization. If enough operatives secure positions within the same company, they could eventually influence engineering decisions, code reviews, pull requests, approvals, or other trust-based processes—without exploiting a single software vulnerability.

Knowing they actively seek such opportunities, we decided to create one for them.

Chapter 2: The Company

The answer was Ballena Azul LTD.

On the surface, it was everything "Famous Chollima" could dream of: a DeFi protocol working with crypto whales across multiple blockchains, seeking experienced developers to help build the platform.

The protocol itself was simple. By combining NFTs with other on-chain mechanisms, whale wallets could voluntarily identify themselves and publicly declare ownership. The idea was to reduce unnecessary market speculation during large fund movements, preventing ecosystem-panicking rumors of exchange hacks, wallet thefts, or exit scams.

Ballena Azul LTD on OpenSea NFT Marketplace

Ballena Azul LTD on the OpenSea NFT Marketplace

Everything had to look authentic. A professional website, corporate branding, documentation, online presence, and—most importantly—a product that made sense. We did this not because we expected investors to believe it, but because we anticipated they would take the bait.

Ballena Azul LTD registration in the UK

(Ballena Azul LTD's existing registration with Companies House in the UK helped enhance the company's legitimacy. This entity is unrelated to our operation.)

I assumed the identity of Leonardo Nelson, co-founder of Ballena Azul LTD. My business partner Benito would join our meetings from Italy. Meanwhile, Heiner once again played Andy Jones—the developer and facilitator from the first installment. This time, he was Ballena Azul's technical lead, personally recommended to me by Benito.

For infrastructure, we chose the most trusted provider: ANY.RUN. Now, everything was in place—all we needed was developers.

Fortunately, Andy happened to know the right person for the job: Angelo Cruz, an eager-to-please "Famous Chollima" external recruiter.

Chapter 3: The Horse Trader

Angelo Cruz met Andy on GitHub. They started chatting, and before long, Cruz convinced Andy to collaborate, with Andy serving as his trusted facilitator to help his developers find jobs.

Angelo’s comment on GitHub looking for facilitators

Angelo's comment on GitHub looking for facilitators

Andy agreed and soon introduced Angelo to Ballena Azul LTD (our company), calling it a golden opportunity. As planned, Ballena Azul LTD would become another lamb to the slaughter. After all, we trusted Andy's judgment—anyone he picked, we welcomed.

Interview with Famous Chollima (Watch on YouTube)

To create a false sense of trust, Andy offered to lend them his brother's ID card, though it never ended up being used. Before long, Angelo introduced us to our first engineer: Angelo Espree (here we go).

Chapter 4: The Team

Angelo Espree was the first to accept a position at Ballena Azul LTD, becoming the first North Korean IT worker to enter our company—and Subject #1 in our investigation files.

Before the interview, Andy and Angelo agreed on a simple cover story: they would tell the CEO (me) that Benito already knew Angelo and had personally vouched for him, approving his addition to the company.

And so, our first interview began. Angelo was a Real Madrid fan with a mathematics background, tasked with developing the company's smart contracts.

Angelo's interview (Watch on YouTube)

During the interview, we asked Angelo to scan a QR code to confirm his attendance. He did—and of course, fell for the oldest trick in the book. The QR code silently redirected him to one of our Canary Tokens, recording the triggerer's IP address, user agent, and more. At the time, it seemed like a minor slip. But later, it became key evidence in exposing a much larger conspiracy. We'll get to that shortly. For now, we were just happy to make new friends.

As friends, we explained that Ballena Azul was a completely trust-based environment, and we only intended to recruit people we could genuinely rely on. Angelo had someone in mind: his friend Jack Anderson (one referral leading to another, continuing the chain of recruiting other hacker group members).

Jack was noticeably more reserved and less fluent in English. Throughout the interview, we repeatedly caught him glancing off-screen, as if looking at a real-time translation tool running on another monitor—another standard tool in the "Famous Chollima" arsenal. Like Angelo, Jack had studied mathematics and supported Real Madrid, and he was quite stoic. Nevertheless, he convinced us, and we welcomed him to Ballena Azul LTD as a frontend developer.

Jack's interview (Watch on YouTube)

Things cascaded one after another—in this line of work, everyone needs someone they can trust. Jack recommended Lucas Theo, a senior backend developer. We interviewed him. He understood the job requirements, showed genuine interest in the position, and even chatted with us about his dog Lulú, his honeymoon in the Philippines, and his love of hiking. We had no reason to suspect him.

So, we equally welcomed him into the Ballena Azul family.

Lucas's interview (Watch on YouTube)

And just like that, they formed the perfect team for pulling off an epic heist. On our side, we had a room full of "thousand-mile horses," waiting to be tamed.

But you know, any good lie needs documentation—lots of it.

Chapter 5: The Impostors

It was time to sign contracts and cement our alliance. But as an experienced CEO, I needed to run a simple background check on new hires. Asking for identification documents should be enough, right? I also requested their addresses, cryptocurrency wallets, and bank account information—standard onboarding paperwork.

Jack sent over a Texas Austin driver's license (claiming he lived there), along with a valid Social Security number and a bank account at Lead Bank in Kansas City.

Lazarus Jack’s Fake License

Lazarus Jack's fake driver's license

Angelo was bolder. He claimed to live in Pasadena, Texas, yet sent a California driver's license, along with a Citibank account from New York.

Lazarus Angelo's driving license

Angelo's driver's license

The most interesting part was hidden in the metadata. Multiple EXIF entries revealed that the image had been processed with Google Gemini and embedded with a SynthID watermark. Combined with obvious visual inconsistencies, the forgery was almost blatantly obvious—yet he had no idea.

Lazarus investigation: Angelo’s License Metadata

Metadata from Angelo's driver's license

If that was bold, Lucas took it to another level.

Instead of sending documents in his own name, he shared a New York driver's license belonging to Pui Chin Teoh, along with a Wise bank account. Unlike Angelo's file, the metadata showed this was a genuine photo taken with an iPhone 15.

Unfortunately for us, the GPS coordinates had been stripped. We suspect Pui Chin is a real person who photographed their license for KYC purposes or similar, and that photo was later leaked and eventually fell into Lucas's hands.

Lazarus investigation Lucas license metadata

wallet
Safety
Welcome to Join Odaily Official Community