---
title: Researchers Ran a Fake Crypto Startup to Hire North Korean IT Workers and Watch Them Work
description: A fake crypto startup let researchers hire suspected North Korean IT workers and watch the Lazarus-linked operatives forge IDs and work from the inside.
author: Darie Nani (Editor-in-Chief)
date: 2026-08-13T13:36:33.017Z
updated: 2026-08-13T13:38:26.636Z
canonical: https://www.sovereignmagazine.com/article/researchers-fake-startup-north-korean-it-workers
image: https://cdn.nanimediahouse.com/lazarus-north-korean-it-workers-149555.webp
categories: Science &amp; Tech
content_type: News
region: Global
publication: Sovereign Magazine
schema_type: Article
---

To find out what happens after a Western company hires a North Korean state operative as a remote developer, a team of researchers set out to become the target on purpose. They set up a fake decentralized-finance startup called Ballena Azul LTD, advertised for engineers, hired the suspected operatives who applied, and watched everything those hires did from inside their own company.

The investigation, published on 10 August 2026 as "Smile, You're on Camera! Part 2: Lazarus IT Workers Exposed," was run by the malware-analysis firm ANY.RUN together with BCA LTD and the NorthScan threat-intelligence initiative. The researchers said the goal was to document how North Korean IT workers from the Famous Chollima faction, which operates under the Lazarus Group umbrella, get inside real companies and what they do once they are on the payroll. The operatives applied under fabricated personas, cleared the hiring process, and began working alongside the researchers who were watching them through ANY.RUN's sandbox environments.

## The operatives got hired, then got to work

The team hired the first operative under the persona Angelo Espree and assigned him to develop smart contracts. Two more followed: a persona named Jack Anderson, brought on as a frontend developer, and a persona named Lucas Theo, hired as a backend developer. A recruiter using the persona "Angelo Cruz" connected with the researchers through GitHub and helped facilitate the hiring. The engagement took place in mid-2026 and forms the second part of the work; Part One, revealed in December 2025, had documented the recruitment and interview cycle. Part Two follows the same scheme after the offer letter, tracking the operatives' actual work, how they collaborated inside one company, and how their toolset changed over time.

The interviews already carried tells. The researchers said the Jack Anderson persona visibly used live-translation tools during interviews and struggled with English. A returning figure from Part One, operating under the alias "Blaze," tried to rejoin the company but failed photo-ID verification.

## Forged US identities, some generated with AI

To pass as American hires, the operatives submitted forged credentials. Those included fake US driver's licenses claiming Texas and California addresses, Social Security numbers, and US bank accounts, among them accounts at Lead Bank and Citibank and a Wise account. The researchers said some of the forged documents carried Google Gemini processing metadata and SynthID watermarks, which indicated the identity documents had been generated with AI. One operative used stolen genuine identity documents rather than fabricated ones, meaning a real person's papers were reused without their knowledge.

Once inside, the operatives worked through a consistent toolkit. They used remote-access software including AnyDesk and Google Remote Desktop, ran AstrillVPN with multiple exit nodes, and checked their exit IP addresses through ip8.com. They shared a single two-factor-authentication service, 2fa.cn, across multiple operatives. Their infrastructure ran on virtual private servers from providers including Vultr and Gorilla Servers, and the researchers observed a shift from Gmail to Outlook. For the work itself and the fraud around it, the operatives relied on ChatGPT for coding help and routine tasks, Google Gemini for document forgery, and job-application AI extensions including AIApply, Final Round AI and Simplify Copilot. They coded in Cursor and Visual Studio Code and held cryptocurrency in MetaMask and Bitget wallets.

The researchers framed the danger as different in kind from a typical intrusion. Unlike malware operations that produce spectacular results overnight, they said, operatives embedded as employees are expected to be there and can provide months or even years of continuous access while drawing a legitimate salary that is ultimately channeled back to the DPRK regime.

> "DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes."
> — ANY.RUN, BCA LTD and NorthScan investigation

## The operatives kept slipping on operational security

The researchers recorded repeated mistakes. Google account synchronization exposed the operatives' browsing history, passwords and browser extensions. They accessed GitHub repositories directly with incomplete or copied code, and they failed to claim cryptocurrency testnet funds, the free test tokens developers normally collect without spending anything. On that point, one operative asked an AI tool, "all of them require real money now," a prompt the researchers cited as a sign of operational constraints. The operatives leaned on ChatGPT for basic technical guidance, and their language barrier stayed visible throughout.

The investigation was carried out by Mauro Eldritch, founder of BCA LTD, and Heiner García of the NorthScan initiative, working through ANY.RUN's platform. The researchers played roles inside the fake company, including a CEO and a co-founder who ultimately exposed the scheme.

That access is the stake for any company that hires remote engineers. A North Korean IT worker scheme does not need to breach a firewall when a hiring manager opens the door, hands over repository credentials and starts paying a salary. The operatives the researchers watched used stolen and AI-forged identities to clear that door, and the same personas, tools and payment rails are available to the next Famous Chollima team applying for the next remote role.

## FAQ

**Q: Who is the Lazarus Group?**
Lazarus Group is the umbrella name for North Korean state-linked hacking activity. The Famous Chollima faction, the group behind the IT worker scheme described here, operates under that umbrella.

**Q: Are the workers' names real people?**
No. Names such as Angelo Espree and Jack Anderson are fabricated personas the operatives applied under, not real applicants. In at least one case the operatives went further and used a real person's stolen identity documents without that person's knowledge.

**Q: How can employers detect them?**
The researchers observed several tells: a returning operative failed photo-ID verification, applicants used live translation and struggled with English in interviews, and forged identity documents carried Google Gemini metadata and SynthID watermarks indicating they were AI-generated. Once hired, the operatives exposed themselves through Google account synchronization that revealed browsing history and passwords, shared two-factor services used across multiple accounts, and reliance on remote-access tools such as AnyDesk and Google Remote Desktop.
