Sting startup hired three suspected Pyongyang IT workers

Sting startup hired three suspected Pyongyang IT workers.

CSBadmin
2 Min Read

Hiring teams should scrutinize identity documents from remote candidates: researchers who posed as a crypto startup and hired three people they believe were North Korean operatives found AI-edited IDs and mismatched paperwork in the onboarding process.

The operation was a sequel to a 2025 sting by threat intelligence firm BCA LTD, the NorthScan research initiative, and sandbox provider ANY.RUN. This round, the researchers flipped roles and played employer, setting up a sham DeFi protocol named Ballena Azul. A recruiter hunting for facilitators on GitHub found the first developer, and that person vouched for a friend, who vouched for the third. Each company-issued virtual machine logged what the workers did.

All three came through the standard hiring pipeline, interview and contract included, and none of them abused the test environment. A placement that holds in the wild puts the operative inside the company. Once inside, the operative can work with source code and internal systems through a genuine employee account.

The paperwork tells the story. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a New York bank account; the researchers said the image metadata showed it had been processed with Google Gemini, and they also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit. For the second hire, the identity package paired a Kansas City-based bank account with a valid Social Security number and a Texas license. The third submitted someone else’s New York license along with a real iPhone 15 photo that had its GPS coordinates removed.

The July 31 joint alert from U.S. and South Korea says North Korean IT workers take contracts intending to remit salaries to their parent agencies, listing image-editing-forged documents among the signals employers should watch for.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.