Security Report: Fake DeFi Startup Exposes North Korean IT Worker Infiltration

banteg · x · 2026-08-27

Security researchers created a fake DeFi startup and hired suspected North Korean IT workers from the Famous Chollima group, providing a rare inside view of the operation. The investigation tracked the scheme beyond recruitment, showing how operatives worked, collaborated, and accessed company resources. Using ANY.RUN sandbox environments, researchers observed live behavior, exposing evolving toolsets, remote access workflows, AI usage, and supporting infrastructure. The findings indicate that DPRK IT worker schemes pose significant risks beyond hiring, as operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes.

Original post →

More from Safety

Safety channel →