Post

Smile, You're on Camera. Part 2 Hiring Lazarus APT's IT Workers in a Fake DeFi Startup

Smile, You're on Camera. Part 2 Hiring Lazarus APT's IT Workers in a Fake DeFi Startup

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. The investigation followed the scheme beyond recruitment, showing how the operatives worked, collaborated, and accessed company resources after being hired. ANY.RUN sandbox environments provided a live view of the operatives’ behavior, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure. The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes. 🚀

One of the many divisions operating under the Lazarus umbrella is Famous Chollima. Their goal is simple: get hired by Western companies. They seek remote positions in industries where both intelligence and money are plentiful. Cryptocurrency, finance, and healthcare have historically been among their favorite targets, while more recent campaigns have expanded into pharmaceuticals, civil engineering, architecture, and other sectors. To secure those positions, they rely on forged identities, fake résumés, proxy interviews, remote facilitators, and ghost developers, all working together to convince companies that the person they hired is exactly who they claim to be. 💼

Unlike a traditional intrusion, their objective is not to compromise an organization for a few hours or days, but to become a part of it. A successful placement can provide months or even years of continuous access to internal systems, source code, intellectual property, and corporate decision-making, while simultaneously generating a legitimate salary that is ultimately channeled back to the DPRK regime. This makes Famous Chollima a very different kind of threat. An employee, on the other hand, is expected to be there. The longer they remain trusted, the greater the opportunity to gather intelligence, influence decisions, and gradually become part of the organization itself. If enough operatives were to secure positions within the same company, they could eventually influence engineering decisions, code reviews, pull requests, approvals, or other trust-based processes without ever exploiting software vulnerabilities. 🔍

This time, instead of playing facilitators, researchers posed as the founders of Ballena Azul LTD, a new DeFi protocol working directly with crypto whales across different chains and looking for new developers. On paper, it was exactly the kind of company Famous Chollima would love to work for: a DeFi protocol working alongside cryptocurrency whales across multiple blockchains and looking for experienced developers. 🌐

Read full article

This post is licensed under CC BY 4.0 by the author.