Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
Researchers used a fake DeFi startup, Ballena Azul LTD / Blue Whale LTD, to recruit suspected Famous Chollima operatives and observe how a DPRK IT worker operation behaves after hire. The investigation exposed forged identities, remote access workflows, AI-assisted tooling, mule bank accounts, AstrillVPN exit nodes, and multiple operatives’ infrastructure and activity inside ANY.RUN environments. #FamousChollima #BallenaAzulLTD #BlueWhaleLTD #AstrillVPN #ANYRUN

Keypoints

  • Researchers created a fake DeFi startup to attract suspected Famous Chollima operatives and study their post-hire behavior.
  • The operation revealed how DPRK IT workers use forged identities, fake résumés, proxy interviews, and facilitators to get hired.
  • Once inside, the operatives accessed company resources, worked on code and smart contracts, and attempted to blend into normal employee workflows.
  • ANY.RUN sandbox environments captured live activity, including clicks, file access, network connections, chat logs, and face footage.
  • The team observed use of remote desktop tools, VPNs, browser extensions, AI tools like ChatGPT and Google Gemini, and shared 2FA infrastructure.
  • Metadata from submitted documents exposed inconsistencies, forged images, and evidence of stolen or repurposed identity documents.
  • The article warns that hiring a DPRK IT worker is not just an HR risk, but a path to long-term access to code, systems, intellectual property, and trusted processes.

MITRE Techniques

  • [T1133 ] External Remote Services – Operatives used remote access tools and VPNs to enter and work inside the virtual desktops (‘installed Google Remote Desktop’; ‘AstrillVPN exit nodes everywhere’).
  • [T1090 ] Proxy – They routed access through intermediary infrastructure to reach the VDIs (‘operative servers used as proxies and vantage points to jump into the VDIs’).
  • [T1036 ] Masquerading – They used forged identities, fake documents, and false company/persona details to appear legitimate (‘forged identities, fake résumés’; ‘driver’s license’).
  • [T1588.001 ] Obtain Capabilities: Malware – The group’s supporting infrastructure and tools were collected and analyzed as part of their operational stack (‘we observed in this new episode’).
  • [T1219 ] Remote Access Software – They installed and used remote access software to maintain control and work remotely (‘AnyDesk, Google Remote Desktop: Remote desktop software’).
  • [T1056 ] Input Capture – The operation relied on captured interactions and live monitoring of every click and movement inside the environment (‘recording every click and every movement they made’).
  • [T1119 ] Automated Collection – The sandbox captured extensive activity and data automatically during their use of the VDI (‘record every file opened, every network connection, and virtually every click made’).
  • [T1082 ] System Information Discovery – They ran system reconnaissance commands to inspect the host environment (‘dxdiag, systeminfo, and wmic to get a detailed overview of the system’).
  • [T1016 ] System Network Configuration Discovery – They checked their apparent location and exit IP using IP lookup services (‘checked where in the world they appeared to be by visiting legitimate IP lookup websites’).
  • [T1078 ] Valid Accounts – They logged into real Google and GitHub accounts on the provided environment (‘open his Google account’; ‘logging into his GitHub account’).
  • [T1027 ] Obfuscated Files or Information – They used image processing and watermarking to alter or disguise identity documents (‘processed with Google Gemini, and a SynthID watermark had been embedded’).
  • [T1110 ] Brute Force – The article references repeated CAPTCHA challenges and login-like verification pressure, but not password guessing; no clear direct use was shown, so this technique is not confidently supported.
  • [T1562.001 ] Disable or Modify Tools – They disrupted work through selective outages and cursor disappearance, reducing usability of the environment (‘we kept the selective network outages’; ‘made the mouse cursor disappear randomly’).

Indicators of Compromise

  • [IPv4 ] AstrillVPN exit nodes and DPRK-operated infrastructure used during the operation – 104.250.148.58, 192.200.115.226, and other 5 IPs
  • [IPv4 ] DPRK-operated VPS and related hosting observed as jump/proxy infrastructure – 89.187.185.11, 45.77.71.42, and other 1 IP
  • [Ethereum Address ] Wallets associated with the operatives and their activity – 0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd, 0xA3D6938f152C47A411263573Bb3AF324C25A8eba, and other 1 address
  • [Domain ] Services used for IP checking and 2FA sharing – ip8.com, 2fa.cn, and other 0 items
  • [Software/Tools ] Remote access, VPN, AI, and coding tools used by the group – AnyDesk, Google Remote Desktop, AstrillVPN, ChatGPT, Google Gemini, Cursor, and Visual Studio Code
  • [Bank Accounts / Financial Services ] Accounts and payment services tied to submitted identity details – Lead Bank, Citibank, Wise, and other 0 items
  • [File / Document Artifacts ] Forged or reused identity documents submitted during onboarding – Jack’s driving license, Angelo’s driving license, Lucas’s license metadata, and other 0 items


Read more: https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/