← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 10, 2026 · 12:41via ANY.RUN Blog

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Brief

Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN , the leading company in malware analysis and threat intelligence .

The article was written by Mauro and Heiner.

Key Takeaways

  • Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives , providing a rare inside view of a DPRK IT worker operation.
  • The investigation followed the scheme beyond recruitment , showing how the operatives worked, collaborated, and accessed company resources after being hired.
  • ANY.RUN sandbox environments provided a live view of the operatives’ behavior , exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure.
Read more on ANY.RUN Blog