Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, andANY.RUN, the leading company in malware analysis and threat intelligence.
The article was written by Mauro and Heiner.
Key Takeaways
- Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation.
- The investigation followed the scheme beyond recruitment, showing how the operatives worked, collaborated, and accessed company resources after being hired.
- ANY.RUN sandbox environments provided a live view of the operatives’ behavior, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure.
- The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE