Recent investigations have unveiled sophisticated methods employed by North Korean IT operatives to infiltrate legitimate companies. These individuals utilize AI-generated identities and remote desktop technologies to secure employment and gain trusted access within organizations.
Researchers from BCA LTD and NorthScan, in collaboration with malware analysis firm ANY.RUN, conducted an undercover operation by establishing a fictitious decentralized finance (DeFi) startup named Ballena Azul LTD. This honey-company was designed with a professional website and branding to attract operatives from the group known as Famous Chollima, linked to the Lazarus Group.
Through GitHub, the researchers connected with a recruiter associated with the group, who introduced several developers. These individuals vouched for each other, forming a network that mirrors typical North Korean placement strategies. Three operatives were hired for roles in smart contract, frontend, and backend development.
During the onboarding process, discrepancies in the provided identification documents were noted. One driver’s license contained metadata indicating it was generated using Google Gemini and bore a SynthID watermark, highlighting the use of advanced AI in document forgery. Another document belonged to a real individual, suggesting the use of stolen identity information.
Instead of providing physical hardware, the research team granted access to isolated virtual desktop environments. This setup allowed for comprehensive monitoring of the operatives’ activities without exposing actual corporate assets. The telemetry data revealed a standardized toolkit employed by the operatives:
- Initial Reconnaissance: Executing system commands and verifying external IP addresses.
- Remote Management: Installing Google Remote Desktop and syncing personal Google accounts to exfiltrate passwords and browsing histories.
- Development Assistance: Utilizing ChatGPT for coding tasks and troubleshooting.
- Real-Time Translation: Deploying live translation software to overcome language barriers during meetings.
Network analysis identified the use of AstrillVPN exit nodes and proxy servers to access virtual desktops. The infrastructure used by these operatives was consistent with known North Korean cyber threat tools, indicating a pattern of tool reuse across different operations.
Unlike traditional cyber intrusions that aim for immediate exploitation, this method focuses on long-term infiltration. Embedded operatives gain sustained access to proprietary source code, internal communications, and software deployment pipelines. Their presence allows them to influence code reviews and pull requests without raising security alarms, all while drawing salaries that fund North Korean regime activities.
This case underscores the evolving tactics of state-sponsored cyber operations. Organizations must enhance their vetting processes, incorporating thorough identity verification and continuous monitoring to detect and prevent such sophisticated infiltration attempts.