Lazarus Group Caught in Phishing Trap by ANY.RUN
The North Korean hacker group Lazarus Group has been caught red-handed in a phishing operation. The group, known for its sophisticated social engineering tactics, was lured into a trap by security firm ANY.RUN and its partners BCA LTD and NorthScan.
The investigation involved creating a fake DeFi startup called Ballena Azul LTD, which the hackers believed to be a legitimate opportunity. They were recruited as developers and given access to the company's systems, but unbeknownst to them, they were actually being monitored in real-time by ANY.RUN's sandbox environment.
The 'Famous Chollima' operatives, part of the Lazarus Group, relied on fake identities, fabricated resumes, and proxy interviews to convince companies that they were who they claimed to be. They targeted remote positions in high-value industries such as cryptocurrency, finance, and healthcare, with some operations expanding into pharmaceuticals, civil engineering, construction, and other sectors.
The North Korean IT worker program poses a significant threat, allowing operatives to gain legitimate access to code, systems, intellectual property, and critical business processes. Once on board, they can influence decisions and eventually integrate into the organization, making it difficult for companies to detect their presence.