Researchers Infiltrate Fake DeFi Startup to Expose North Korean IT Worker Scheme
cyb3rops · x · 2026-08-11
Security researchers created a fake DeFi startup and hired suspected North Korean IT workers from the Famous Chollima group, gaining rare insight into their operations. The investigation revealed how operatives work, collaborate, and access company resources after being hired. Using ANY.RUN sandbox environments, researchers observed their evolving toolset, remote access workflow, AI usage, and supporting infrastructure. The findings show that DPRK IT worker schemes pose not only hiring risks but also post-hire threats to code, systems, and intellectual property.
More from Safety
- Open-Source SynthID-Text-Detector: Reference Implementation for AI Text Watermarking — jedisct1 · 2026-08-11
- Classic McEliece Crypto Scheme Under Attack, Shattering Quantum-Proof Illusions — jedisct1 · 2026-08-11
- Does LLM Watering Degrade Quality? Researcher's 10-Point FAQ Debunks Myths — jonasgeiping · 2026-08-11
- Claude Enables Text Watermarks and Metadata Signatures for AI Content — APPSO · 2026-08-11
- Paper Reveals Encrypted CoT Flaw Allowing Reasoning Theft from Top LLMs — Alexander Panfilov · 2026-08-11
- Limit Autonomous Compute, Not Training Compute, for AI Safety — jachiam0 · 2026-08-11