Fake Crypto Startup Uncovers Suspected North Korean Operatives
Cybersecurity researchers in the US used a fake cryptocurrency company to expose three developers suspected of being North Korean operatives. The deception involved recruiting the workers through GitHub and providing them with virtual machines that recorded their activity.
The researchers observed the workers using location-masking technology, AI-assisted work, and servers associated with malware families linked to North Korean campaigns. They also found questionable identity documents and remote-access software.
A reporter posed as a venture capital investor to further deceive the workers, who claimed to live in the United States but provided identification and banking information that raised questions about their identities.