Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

https://hackernoon.imgix.net/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-nm83bml.webp

Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, andANY.RUN, the leading company in malware analysis and threat intelligence.

The article was written by Mauro and Heiner.

Key Takeaways

  • Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation.
  • The investigation followed the scheme beyond recruitment, showing how the operatives worked, collaborated, and accessed company resources after being hired.
  • ANY.RUN sandbox environments provided a live view of the operatives’ behavior, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure.
  • The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more