North Korean IT Workers Exposed: Fake Crypto Startup Study Reveals Recruitment Tactics
Researchers at cybersecurity firm BCA LTD and Telefónica Tech's NorthScane carried out a five-week investigation into suspected North Korean IT workers' recruitment tactics. They created a fake crypto startup, Ballena Azul, to study how these operatives operate.
The researchers found that the suspected workers relied heavily on AI tools to compensate for technical gaps and help with coding, writing, and document manipulation. They used ChatGPT for writing and coding, including answering basic questions and finishing assignments.
The investigation also revealed that the operatives often used external intermediary servers linked to earlier North Korean malware campaigns. Some of these servers were still active, suggesting a long-lived infrastructure that increases the window for compromise and detection evasion.
During the ruse, analysts identified servers associated with malware families tied to prior North Korean campaigns, including InvisibleFerret and BeaverTail/OtterCookie. The suspected workers used remote desktop software, crypto wallets, and services designed for sharing two-factor authentication codes.