Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

The Hacker News by The Hacker News
August 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalAug 11, 2026Insider Threat / Cyber Espionage

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.

The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a New York bank account.

The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit.

The second supplied a Texas license, a valid Social Security number, and a bank account in Kansas City. The third sent a New York license belonging to someone else, a genuine iPhone 15 photograph with the GPS coordinates stripped.

A successful placement gives the operative a real employee account and real access to source code and internal systems. The July 31 joint alert says North Korean IT workers seek contracts with the intent of remitting their salaries to parent North Korean agencies. It also names documents “forged or altered using image editing software” among the signals employers should watch for.

In April, the Justice Department sentenced two US facilitators over a separate scheme that placed workers at more than 100 US companies on at least 80 stolen identities and earned North Korea more than $5 million. Google’s Gemini app can check an image for a SynthID watermark, but it only detects content created or edited by Google’s AI models. A negative result does not rule out AI editing by other tools.

The operation was a sequel. A joint investigation by Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and ANY.RUN, a provider of interactive malware analysis and threat intelligence, spent late 2025 posing as a facilitator willing to rent out his identity. The Hacker News covered that operation in December.

This time they became the employer, building a fake DeFi protocol called Ballena Azul. A recruiter trawling GitHub for facilitators delivered the first developer. That developer vouched for a friend, who vouched for a third.

Nobody exploited anything.

Each operative came in through the hiring process, cleared an interview, signed a contract, and was given access to a work VM. The researchers write that these schemes are “not only a hiring risk” because once a placement holds, the worker’s access is also authorized and expected.

Day one was reconnaissance. All three ran dxdiag, systeminfo, and wmic to profile their machines, then checked what country their connection appeared to originate from. One then installed Chrome Remote Desktop and synced his personal Google account to the sandbox, handing over his browsing history, saved passwords and installed extensions. He logged into GitHub on the same machine.

The tooling observed in this engagement differed from December. The researchers saw 2fa.cn used for passing two-factor codes between operators; the December operation had used authenticator.cc and otp.ee. Outlook.com appeared where only Gmail had before.

Their browsers carried AI job-application and interview-assistance extensions: AIApply, Final Round AI, Simplify Copilot and a saved-prompts tool for ChatGPT. The report places infrastructure on Vultr and Gorilla Servers and says AstrillVPN exit nodes ran throughout.

Silent Push has separately tracked Astrill as a fixture of North Korean operations.

The researchers advise periodic identity checks rather than one at hire, in-person verification for remote-first companies, recruiter training, and blocking AstrillVPN. The July 31 advisory further notes a single account reached from many addresses in a short window and profile text that reads like machine translation.

The report presents the Gemini-processing metadata and the SynthID watermark as separate findings but does not explain how the watermark itself was detected.

Attribution rests with the researchers, who presented the work at DEF CON 34 in Las Vegas this month. They describe the three as suspected Famous Chollima operatives. CrowdStrike uses that name for North Korea’s IT worker operation, while the team places it under the wider Lazarus umbrella.

The eleven-government alert names no vendor actor cluster at all. As of August 11, no government source reviewed for this article had confirmed that identification. The real names behind the three personas are unknown, and the report gives no dates for how long the fake company ran.



Source link

The Hacker News

The Hacker News

Next Post
Stocks making the biggest moves premarket: Riot Platforms, Hims & Hers Health, Intel & more

Stocks making the biggest moves premarket: Riot Platforms, Hims & Hers Health, Intel & more

Recommended.

PicoCELA Inc. Announces Closing of Public Offering

PicoCELA Inc. Announces Closing of Public Offering

May 27, 2025
Iterate.ai CEO On Betting Big On The Channel: ‘It’s Core To Our Strategy’

Iterate.ai CEO On Betting Big On The Channel: ‘It’s Core To Our Strategy’

January 5, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio