Researchers Pose as DeFi Startup to Hire and Expose North Korean Lazarus IT Workers
banteg · x · 2026-08-11
ANY.RUN, in collaboration with BCA LTD and NorthScan, created a fake DeFi startup to hire and monitor suspected North Korean Lazarus APT (Famous Chollima) IT workers. Using ANY.RUN sandbox environments, the team observed their behavior, revealing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure. The investigation shows that DPRK IT worker infiltration is not just a hiring risk; once inside, operatives can gain legitimate access to code, systems, IP, and business processes.
Related event: Security Firms Trap North Korean Hackers with Fake DeFi Startup(2 posts)→
More from Safety
- CMU Introduces WeClawArena: Benchmark for Cross-User Agent Collaboration and Security — CarnegieMellonU · 2026-08-11
- AI Safety: Can 'Lab Spoofing' Bypass Model Alignment? — IasonGabriel · 2026-08-11
- 1Password Research: Over 53% of AI-Generated Vulnerability Patches Are FLAWED — cyb3rops · 2026-08-11
- Over 1,300 Frontier AI Researchers Warn of Humanity-Endangering Arms Race — nordicinst · 2026-08-11
- EU Reveals Official Labels for Disclosing AI-Generated Content — RSync25 · 2026-08-11
- Can smart glasses combined with facial recognition easily identify you on the street? — Tiny_Major_7514 · 2026-08-11