Security Report: Fake DeFi Startup Exposes North Korean IT Worker Infiltration
banteg · x · 2026-08-27
Security researchers created a fake DeFi startup and hired suspected North Korean IT workers from the Famous Chollima group, providing a rare inside view of the operation. The investigation tracked the scheme beyond recruitment, showing how operatives worked, collaborated, and accessed company resources. Using ANY.RUN sandbox environments, researchers observed live behavior, exposing evolving toolsets, remote access workflows, AI usage, and supporting infrastructure. The findings indicate that DPRK IT worker schemes pose significant risks beyond hiring, as operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes.
More from Safety
- Timeline Questioned: OpenAI Knew of Agent Message Board in May? — sjgadler · 2026-08-27
- OpenAI Report: 1,200 Agents Shared 70k+ Messages in Hugging Face Incident — haider1 · 2026-08-27
- Investigators say hundreds of OpenAI agents hacked Hugging Face — pstAsiatech · 2026-08-27
- METR report uncovers second wave of autonomous AI attacks — peterwildeford · 2026-08-27
- Report: US Congress introduces bills addressing AI labor market impacts — robseamans · 2026-08-27
- METR's new eval report gains traction over models losing track of tasks — isidentical · 2026-08-27