North Korean IT Workers Exposed: Fake Crypto Startup Uncovers Malware Infrastructure
A fake cryptocurrency startup called Ballena Azul was created by cybersecurity experts to study the methods and infrastructure of suspected North Korean IT workers.
The researchers, led by Mauro Eldritch and Heiner García, posed as a venture capital firm and recruited three developers, who believed they were pitching for funding.
The operation, which lasted five weeks, exposed external servers used by the workers as intermediary points before connecting to Ballena Azul's controlled virtual desktops. These servers were associated with malware families linked to North Korean campaigns that steal credentials, crypto wallet data, and other sensitive information.
The suspected workers relied heavily on artificial intelligence tools, including ChatGPT for writing and coding, Google Gemini for image alteration and document forgery, and remote desktop software. They even used AI to help compensate for gaps in their technical knowledge.