Researchers hired suspected North Korean IT workers to expose their post-hire playbook

Three hires used forged identities, Gemini-altered documents, remote access tools and AI coding assistants inside a sandboxed workplace.

By · Published

Why it matters

Remote hiring is an insider-security boundary: a fraudulent employee can arrive with valid credentials and legitimate access to code, wallets and internal systems.

Researchers hired suspected North Korean IT workers to expose their post-hire playbook — Three hires used forged identities, Gemini-altered documents, remote access tools and AI coding assistants inside a sandboxed workplace.

Mauro Eldritch (@MauroEldritch) and Heiner Garcia Perez say they hired three suspected North Korean IT workers into a fake cryptocurrency startup, then recorded how the developers used forged identities, AI tools and remote access infrastructure after receiving legitimate access to the workplace.

The researchers detailed the operation in an investigation published by ANY.RUN on August 10th. They attributed the workers to Famous Chollima, a North Korea-linked operation known for placing developers at Western businesses under false identities. CrowdStrike has tracked Famous Chollima activity since at least 2018, while Microsoft uses the name Jasper Sleet for a North Korea-aligned remote-worker operation. (any.run)

Eldritch, the founder of threat intelligence business BCA LTD and leader of Bitso's Quetzal threat research team, ran the project with Garcia Perez, a financial-crime and cyber threat intelligence analyst associated with NorthScan. The pair had previously posed as facilitators offering laptops and interview assistance to suspected operatives. Their second experiment followed the scheme through onboarding and into day-to-day engineering work. (any.run)

The fake startup offered access worth stealing

Eldritch and Garcia Perez created Ballena Azul LTD, or Blue Whale LTD, as a fictional decentralized finance protocol serving large cryptocurrency holders. They built a website, branding, documentation and an online presence, then presented themselves as executives recruiting remote developers.

A suspected Famous Chollima recruiter introduced three candidates for smart-contract, front-end and back-end engineering roles. The researchers interviewed and hired all three. Ballena Azul then requested the identity, address, banking and cryptocurrency-wallet information that an employer might collect during onboarding. (any.run)

The documents contained multiple warning signs. One candidate claimed to live in Pasadena, Texas, while presenting a California driver's license and New York banking details. ANY.RUN's report says metadata showed that the license image had been processed with Google Gemini and contained a SynthID watermark. Another candidate supplied a photograph of a New York license bearing a different person's name. A third submitted a Texas license, a Social Security number and banking details.

Those findings line up with established North Korean remote-worker tradecraft. The FBI says the schemes use stolen identities, pseudonymous accounts, proxy computers and facilitators who receive employer-issued devices. Microsoft has separately documented AI-enhanced photographs, fabricated profiles, tailored resumes, VPN accounts and payment records associated with suspected North Korean workers. (fbi.gov)

Legitimate credentials opened the door

Instead of shipping physical laptops, the researchers gave each hire a virtual desktop built by ANY.RUN. Three isolated environments recorded files, network connections and user activity while appearing to operate like ordinary corporate machines.

The workers first inspected the systems with Windows utilities including dxdiag, systeminfo and wmic, checked their visible IP addresses and installed remote-access software. One worker synchronized a Google account with the virtual desktop, exposing account data to the instrumented environment before opening GitHub and beginning work. (any.run)

The observed toolset included AnyDesk, Google Remote Desktop and AstrillVPN, along with ChatGPT, Gemini, Cursor, Visual Studio Code and Remix. Browser extensions included Saved Prompts for GPT, Simplify Copilot, AIApply and Final Round AI. The researchers also observed a service used to share two-factor authentication codes, cryptocurrency wallets and virtual private servers that acted as intermediary access points. (any.run)

AI appeared throughout the workflow. The workers used ChatGPT for coding and troubleshooting, while the Gemini-linked license showed how generative tools can support identity fabrication before an interview begins. Google has previously observed North Korean actors using Gemini to draft cover letters, research salaries and jobs, generate code and support fake-worker applications. (cloud.google.com)

The developers' technical performance was uneven, according to the report. They searched for basic smart-contract instructions, moved ChatGPT responses between development tools and struggled to obtain test cryptocurrency. Skill level, however, was secondary to the access they had obtained. Ballena Azul treated them as employees, giving them credentials and permission to interact with code and business systems.

That distinction makes the remote-worker scheme an insider threat rather than a conventional account compromise. Mandiant has observed suspected North Korean workers performing assigned duties while holding permissions to modify code or administer systems. The Justice Department says related operations have affected hundreds of U.S. businesses, using laptop farms and stolen identities to generate millions of dollars for overseas workers. (cloud.google.com)

The FBI recommends repeated identity verification, careful review of shipping and work locations, restrictions on remote desktop software and monitoring for unauthorized access tools. The ANY.RUN experiment shows why those checks must continue after the employment contract is signed: a fraudulent hire can use valid credentials, approved devices and normal engineering workflows without exploiting a software vulnerability. (fbi.gov)

Reader comments

Conversation for this story loads after sign-in.