- Researchers posed as a crypto startup and hired three suspected North Korean operatives to study their methods.
- All three used AI-generated or altered IDs, with one image carrying a Google SynthID watermark.
- Operatives employed AI tools for interviews and attempted to exfiltrate credentials before detection.
At DEF CON 34 in Las Vegas this month, security researchers revealed they built a fake DeFi protocol called Ballena Azul to lure and observe suspected North Korean IT workers. The team, comprising Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and ANY.RUN, hired three individuals they believe were operatives, giving them full access to a monitored virtual machine.
The hiring process exposed significant flaws in standard vetting. The first operative claimed to live in Texas but submitted a California driver’s license and a New York bank account; metadata showed the image was processed with Google Gemini and contained a SynthID watermark. The third candidate submitted a genuine iPhone photo with stripped GPS data, highlighting that “forged or altered using image editing software” is a key red flag, per a joint advisory from 11 governments issued on July 31.
Once hired, each operative engaged in reconnaissance on their first day, running system profiling commands and checking their apparent geolocation. One then installed Chrome Remote Desktop and synced his personal Google account, exposing his browsing history and passwords. They used the tool 2fa.cn to pass two-factor codes, a shift from previously observed services. Their browsers also carried AI extensions like AIApply and Simplify Copilot for job applications and interview assistance.
The researchers noted that all operatives used AstrillVPN to mask their traffic, a tool that Silent Push has tracked as a fixture of North Korean operations. While the fake company ran for an unspecified period, no one exploited the environment for malicious code.
Consequently, the team advises periodic identity checks, in-person verification, and blocking AstrillVPN. The July 31 advisory also notes that a single account reached from many addresses in a short time frame is a warning sign. Attribution rests with the researchers, who link the trio to the Famous Chollima cluster under the Lazarus umbrella, though no government source has confirmed that identification.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
