Fake DeFi employer exposes suspected North Korean IT worker tactics

BCA LTD, the NorthScan research initiative and sandbox provider ANY.RUN created a fake decentralised-finance protocol called Ballena Azul, advertised developer roles and hired three people they assess as suspected North Korean IT workers. The researchers monitored every virtual machine issued by the fictitious employer after each candidate completed an interview, signed a contract and received access.
The engagement was designed to observe the recruitment route into a company rather than an intrusion. A recruiter searching GitHub for facilitators delivered the first developer; that person vouched for a friend, who in turn vouched for a third candidate. The researchers said none exploited a vulnerability: all three entered through ordinary hiring and onboarding processes.
Identity documents and authorised access
One candidate claimed to be in Pasadena, Texas, but provided a California driving licence and a New York bank account. BCA LTD and its partners said image metadata indicated that the licence had been processed with Google Gemini, while a SynthID watermark was a separate finding. Google’s Gemini app can check for SynthID, but detection applies only to material created or edited with Google AI models; a negative result cannot exclude editing by other tools.
Another applicant supplied a Texas licence, a valid Social Security number and a Kansas City bank account. The third provided a New York licence belonging to another person and an authentic iPhone 15 photograph from which GPS coordinates had been removed. The researchers did not identify the real people behind the personas.
The risk is not confined to a fraudulent application. A successful placement can give an operator an employee account, expected access to source code and access to internal systems. The July 31 joint advisory cited forged or altered documents as a warning sign and said North Korean IT workers seek contracts in order to remit salaries to parent agencies. In a separate case, the US Justice Department sentenced two US facilitators in April over a scheme involving more than 100 US companies, at least 80 stolen identities and more than $5 million earned for North Korea.
Observed activity in the work environment
On the first day, all three workers ran dxdiag, systeminfo and wmic to profile their virtual machines and checked the apparent country of their connections. One installed Chrome Remote Desktop, synchronised a personal Google account with the sandbox and then logged into GitHub. The account sync exposed browsing history, saved passwords and installed extensions to the monitored environment.
The researchers observed 2fa.cn for passing two-factor authentication codes between operators, whereas their December operation had seen authenticator.cc and otp.ee. Outlook.com appeared alongside browser extensions for AI-assisted applications and interviews, including AIApply, Final Round AI, Simplify Copilot and a saved-prompts tool for ChatGPT. The report also cited Vultr, Gorilla Servers and AstrillVPN exit nodes.
The team presented the work at DEF CON 34 and described the individuals as suspected Famous Chollima operatives, a CrowdStrike label for North Korea’s IT worker activity within the wider Lazarus umbrella. That attribution remains the researchers’ assessment: the eleven-government advisory names no vendor actor cluster, and no government source reviewed by the report had confirmed the identification as of August 11.
What employers can change
The Ballena Azul exercise reinforces that trusted access can be created at the recruitment stage. As threats involving AI agents shows in its account of threats involving AI agents, organisations need controls that account for legitimate credentials as well as technical exploits. Businesses can make remote hiring harder to abuse by training recruiters, conducting periodic identity checks, using in-person verification where practical, and reviewing accounts reached from many locations in a short period.
Teams should also assess VPN and remote-access signals in context, including AstrillVPN where it conflicts with policy, while avoiding reliance on any single image-forensics check. The practical implication is to treat employee verification, endpoint monitoring and access review as continuing controls throughout a worker’s tenure.

