Close Menu
NCIJ Network NCIJ Network
    What's Hot

    South Africa school uses cattle dung to generate biogas for cooking meals

    August 14, 2026

    The Jason Arday affair must not spell the end for diversity. Here’s how – and why – we should defend it | Joseph Harker

    August 14, 2026

    After 2 Plasma Donor Deaths, Company Pauses Clinics in Canada

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • South Africa school uses cattle dung to generate biogas for cooking meals
    • The Jason Arday affair must not spell the end for diversity. Here’s how – and why – we should defend it | Joseph Harker
    • After 2 Plasma Donor Deaths, Company Pauses Clinics in Canada
    • Mark Zuckerberg’s AI Manifesto Is 6,500 Words—and Barely Says Anything
    • Belgium’s eID Authentication Opens Citizen Accounts to RCE
    • ‘Bitcoin Is Burning’: Red Team Turns to Chinese AI to Find Flaws
    • Timor green pigeon nears extinction after decades of inaction, study warns
    • Mojtaba Khamenei’s Appointment of Mohsen Rezaei Is Planning for a Long War
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 11, 2026Insider Threat / Cyber Espionage

    Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.

    The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a New York bank account.

    The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit.

    The second supplied a Texas license, a valid Social Security number, and a bank account in Kansas City. The third sent a New York license belonging to someone else, a genuine iPhone 15 photograph with the GPS coordinates stripped.

    A successful placement gives the operative a real employee account and real access to source code and internal systems. The July 31 joint alert says North Korean IT workers seek contracts with the intent of remitting their salaries to parent North Korean agencies. It also names documents “forged or altered using image editing software” among the signals employers should watch for.

    In April, the Justice Department sentenced two US facilitators over a separate scheme that placed workers at more than 100 US companies on at least 80 stolen identities and earned North Korea more than $5 million. Google’s Gemini app can check an image for a SynthID watermark, but it only detects content created or edited by Google’s AI models. A negative result does not rule out AI editing by other tools.

    Cybersecurity

    The operation was a sequel. A joint investigation by Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and ANY.RUN, a provider of interactive malware analysis and threat intelligence, spent late 2025 posing as a facilitator willing to rent out his identity. The Hacker News covered that operation in December.

    This time they became the employer, building a fake DeFi protocol called Ballena Azul. A recruiter trawling GitHub for facilitators delivered the first developer. That developer vouched for a friend, who vouched for a third.

    Nobody exploited anything.

    Each operative came in through the hiring process, cleared an interview, signed a contract, and was given access to a work VM. The researchers write that these schemes are “not only a hiring risk” because once a placement holds, the worker’s access is also authorized and expected.

    Day one was reconnaissance. All three ran dxdiag, systeminfo, and wmic to profile their machines, then checked what country their connection appeared to originate from. One then installed Chrome Remote Desktop and synced his personal Google account to the sandbox, handing over his browsing history, saved passwords and installed extensions. He logged into GitHub on the same machine.

    The tooling observed in this engagement differed from December. The researchers saw 2fa.cn used for passing two-factor codes between operators; the December operation had used authenticator.cc and otp.ee. Outlook.com appeared where only Gmail had before.

    Their browsers carried AI job-application and interview-assistance extensions: AIApply, Final Round AI, Simplify Copilot and a saved-prompts tool for ChatGPT. The report places infrastructure on Vultr and Gorilla Servers and says AstrillVPN exit nodes ran throughout.

    Silent Push has separately tracked Astrill as a fixture of North Korean operations.

    Cybersecurity

    The researchers advise periodic identity checks rather than one at hire, in-person verification for remote-first companies, recruiter training, and blocking AstrillVPN. The July 31 advisory further notes a single account reached from many addresses in a short window and profile text that reads like machine translation.

    The report presents the Gemini-processing metadata and the SynthID watermark as separate findings but does not explain how the watermark itself was detected.

    Attribution rests with the researchers, who presented the work at DEF CON 34 in Las Vegas this month. They describe the three as suspected Famous Chollima operatives. CrowdStrike uses that name for North Korea’s IT worker operation, while the team places it under the wider Lazarus umbrella.

    The eleven-government alert names no vendor actor cluster at all. As of August 11, no government source reviewed for this article had confirmed that identification. The real names behind the three personas are unknown, and the report gives no dates for how long the fake company ran.

    Built Crypto Fake hired Korean North researchers startup Suspected Workers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Belgium’s eID Authentication Opens Citizen Accounts to RCE

    Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

    Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy

    Ukraine shuts down 94 fraudulent call centers, seize millions in cash

    Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    South Africa school uses cattle dung to generate biogas for cooking meals

    August 14, 2026

    The Jason Arday affair must not spell the end for diversity. Here’s how – and why – we should defend it | Joseph Harker

    August 14, 2026

    After 2 Plasma Donor Deaths, Company Pauses Clinics in Canada

    August 14, 2026

    Mark Zuckerberg’s AI Manifesto Is 6,500 Words—and Barely Says Anything

    August 14, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    South Africa school uses cattle dung to generate biogas for cooking meals

    August 14, 2026

    The Jason Arday affair must not spell the end for diversity. Here’s how – and why – we should defend it | Joseph Harker

    August 14, 2026

    After 2 Plasma Donor Deaths, Company Pauses Clinics in Canada

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.