← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 10, 2026 · 12:45via Malware.news

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Brief

Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN, the leading company in malware analysis and threat intelligence.

The article was written by Mauro and Heiner. Key Takeaways Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. The investigation followed the scheme beyond recruitment, showing how the operatives worked, collaborated, and accessed company resources after being hired. ANY.

RUN sandbox environments provided a live view of the operatives’ behavior, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure.

Read more on Malware.news