Fake Crypto Startup Reveals North Korean IT Worker Tactics
Cybersecurity researchers exposed the infrastructure and methods of North Korean state-sponsored IT workers through an elaborate investigation using a fake cryptocurrency startup as a honeypot.
Honeypot Reveals North Korean IT Worker Tactics
Cybersecurity researchers Mauro Eldritch of BCA LTD and Heiner García of Telefónica Tech, founder of NorthScane, orchestrated an elaborate investigation to expose how North Korean operatives infiltrate cryptocurrency companies. They constructed a fake cryptocurrency startup, Ballena Azul, as a honeypot to monitor suspected North Korean workers joining the team. The five-week operation, supported by cybersecurity platform ANY.RUN, provided unprecedented visibility into the methods, tools, and infrastructure these state-sponsored actors employ.
The setup was deceptively simple yet effective. A recruiter connected with the Famous Chollima threat group—the organization coordinating North Korean IT worker operations—presented three candidates: Jack Anderson, Angelo Espree, and Lucas Theo. At least two presented US identification documents. Once onboarded, the suspected workers were assigned programming tasks within isolated, monitored virtual desktop environments, giving researchers direct observation of their techniques and operational patterns.
Infrastructure and Technical Capabilities Exposed
The investigation uncovered critical infrastructure used by North Korean operatives. The workers relied on external servers as intermediary connection points before accessing controlled environments. Researchers traced these servers to previous distribution of known malware families—InvisibleFerret and BeaverTail/OtterCookie—linked to campaigns designed to steal credentials and cryptocurrency wallet data. Significantly, this infrastructure was recycled across multiple operations and remained active for extended periods, serving as both command-and-control systems and operational proxies.
The suspected workers compensated for technical gaps using artificial intelligence tools. They leveraged ChatGPT for coding assignments and writing tasks, and Google Gemini for image manipulation and document forgery. Additionally, they employed remote desktop software, cryptocurrency wallets, and services for sharing two-factor authentication codes. When researchers introduced deliberate technical problems—network outages and disappearing cursors—the workers quickly adapted, revealing an operation built more on improvisation than rigid processes.
Escalating Threat to Crypto Security
North Korean IT worker schemes represent an escalating threat to crypto and technology companies. According to the US Treasury, these operations generated nearly $800 million in 2024 alone, directly funding the Pyongyang regime’s weapons programs. Recent incidents validate this trend: Consensys disclosed identifying a North Korea-linked developer in July through a third-party service provider; US prosecutors charged four North Korean nationals in 2025 with stealing over $900,000 in cryptocurrency by assuming false identities in remote IT roles.
The danger extends beyond malware deployment. Once hired, these operatives gain legitimate access to source code, internal systems, and sensitive business data. Extended undetected presence means continuous salary payments funding hostile regimes. The exposed infrastructure reveals servers previously used for malware distribution that now serve operational purposes—patterns defenders can exploit to identify and block such infiltration attempts.
This investigation demonstrates that North Korean IT worker infrastructure is far more observable and trackable than previously understood. For cryptocurrency companies and blockchain projects, the findings underscore the critical importance of rigorous identity verification, geolocation controls, and behavioral monitoring for remote developers. Strengthening security around remote hiring practices protects not only individual companies but the entire cryptocurrency ecosystem against state-sponsored infiltration—a prerequisite for maintaining investor trust and market stability in digital assets.
Source: Telefónica Tech, via Cointelegraph. Not financial advice.