Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
Brief
Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN , the leading company in malware analysis and threat intelligence .
The article was written by Mauro and Heiner.
Key Takeaways
- Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives , providing a rare inside view of a DPRK IT worker operation.
- The investigation followed the scheme beyond recruitment , showing how the operatives worked, collaborated, and accessed company resources after being hired.
- ANY.RUN sandbox environments provided a live view of the operatives’ behavior , exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure.
