North Korean Hackers Use Fake Remote Jobs to Steal Identities

  • A joint investigation uncovered a North Korean infiltration scheme using remote IT workers linked to the Lazarus Group’s Famous Chollima division.
  • Researchers observed operators live through virtual Sandbox machines simulating real developer laptops.
  • The attackers use AI-based tools and identity takeover tactics rather than deploying Malware.
  • The operation exploits remote hiring to gain access to sensitive sectors such as finance and healthcare.
  • Companies are cautioned to raise awareness of suspicious remote hiring activities to prevent internal compromises.

A collaborative investigation led by Mauro Eldritch, founder of BCA LTD, along with NorthScan and ANY.RUN, revealed an extensive infiltration campaign by North Korea. The scheme involves remote IT workers connected to the Lazarus Group’s Famous Chollima division targeting Western companies mainly in finance, crypto, healthcare, and engineering, as stated in the findings released on December 2, 2025.

- Advertisement -

Investigators created a false developer identity and engaged with a recruiter using the alias “Aaron” or “Blaze,” impersonating a U.S. developer. The recruiter attempted to employ the fake candidate as a frontman to enable North Korean operatives access remotely. The process included stealing or borrowing identities, passing interviews using AI assistance, working through the victim’s laptop, and funneling salaries back to North Korea.

Instead of providing real laptops, the investigation deployed the ANY.RUN Sandbox, a virtual machine simulating active personal workstations with developer tools and U.S.-based proxy routing. This allowed the team to monitor operators live, control system crashes, and record activities covertly.

Inside these controlled environments, operators used a minimal but effective range of tools focusing on identity theft and remote access. The toolkit included AI-driven job automation tools such as Simplify Copilot and AiApply for auto-filling applications and generating interview responses. They also used browser-based one-time password (OTP) generators like OTP.ee and Authenticator.cc to bypass two-factor authentication after collecting personal documents. Persistent access was maintained through Google Remote Desktop configured with a fixed PIN via PowerShell commands. Routine system reconnaissance commands were executed to verify hardware legitimacy. Connections were consistently routed through Astrill VPN, a known Lazarus Group infrastructure.

In one instance, an operator left a Notepad message requesting sensitive details such as identification, social security numbers, and bank information, demonstrating the operation’s focus on full identity and workstation takeover without malware deployment.

- Advertisement -

This investigation highlights a growing threat vector through remote hiring. Attackers may gain entry via targeted interview requests, risking broad access to sensitive company data and managerial accounts. Raising employee awareness and providing channels for verifying suspicious activities can prevent infiltration and subsequent internal damage.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Solana Mobile to airdrop 2B SKR to Seeker users Jan 20 9pmET

Solana Mobile will airdrop its new SKR token on January 20, with a claim...

OpenAI’s ChatGPT Health links records and wellness apps now!

OpenAI launched ChatGPT Health on Wednesday to let users link medical records and wellness...

Strategy’s mNAV Hits 1x as Market Value Matches BTC At risk!

Strategy disclosed on its homepage that its enterprise multiple-to-Net Asset Value (mNAV) has fallen...

a16z Crypto buys BABY in $15M deal to boost Bitcoin DeFi Now

Babylon raised $15 million via a token sale to the digital asset arm of...

Black Cat SEO Poisoning Pushes Fake Apps, Installs Backdoor.

Black Cat used SEO poisoning to place fake software download pages high in search...
- Advertisement -

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Bitcoin (BTC) $ 91,231.00 2.41%
Ethereum (ETH) $ 3,167.95 3.61%
XRP (XRP) $ 2.17 5.47%
Bittensor (TAO) $ 271.56 7.04%
Polkadot (DOT) $ 2.15 3.37%
Cardano (ADA) $ 0.403195 3.77%
Chainlink (LINK) $ 13.44 3.97%
Hyperliquid (HYPE) $ 26.92 3.64%
Monero (XMR) $ 437.50 0.87%
Hedera (HBAR) $ 0.123681 3.73%
Toncoin (TON) $ 1.87 1.26%