Fabricated Startup Engages Suspected North Korean IT Operators
Cybersecurity experts Mauro Eldritch and Heiner García orchestrated a covert five-week operation by establishing a fictitious cryptocurrency startup named “Ballena Azul.” The team communicated via Zoom with suspected North Korean IT engineers who believed they were participating in genuine startup activities aimed at securing venture capital. To enhance credibility, the researchers registered a real UK company using the same name. Eldritch assumed the role of co-founder “Leonardo Nelson,” while García acted as project lead “Andy Jones.” The North Korean participants remained unaware of the true nature of the operation.
Unveiling Critical Infrastructure Linked to Malicious Activities
The investigation identified multiple key servers serving as intermediary nodes connecting operators to virtual desktops controlled by the fake company. Several of these servers were previously linked to North Korean malware campaigns such as InvisibleFerret and BeaverTail/OtterCookie. Others were not listed in known threat intelligence databases, suggesting deployment of new infrastructure by the North Korean team.
Researchers found that these servers functioned not only as malware distribution points but also as command-and-control centers and proxy relays. Experts noted that the IT operators posed a threat without directly releasing malware, as their legitimate access to core source code and internal systems of target companies enabled long-term infiltration and covert data exfiltration. Such operations may indirectly fund North Korea’s government programs.
Increasing Reliance on Artificial Intelligence Tools
The suspected North Korean developers reportedly utilized AI assistance extensively, employing ChatGPT for coding support and technical queries, while Google Gemini was used for image manipulation and document forgery. This adaptation reflects efforts to compensate for skill gaps. Beyond AI, the team employed remote desktop applications, encrypted wallets, and multi-factor authentication code sharing services to facilitate their tasks.
Recruitment Channels and Behavioral Patterns Exposed
García’s engagement commenced via a GitHub recruiter associated with the “Famous Chollima” threat group, leading to the onboarding of remote developers identified as “Jack Anderson,” “Angelo Espree,” and “Lucas Theo.” The team distributed programming assignments through controlled virtual desktops and simulated network outages to monitor responses. These tactics enabled collection of critical evidence including chat logs, VPN exit nodes, and live video streams.
Similar cases involving North Korean remote IT operators have repeatedly surfaced within the cybersecurity community. In 2025, U.S. prosecutors indicted four North Korean IT personnel for remotely stealing over $900,000 in cryptocurrency under false identities. Authorities highlighted these operations as financial backers for North Korea’s nuclear weapons and weapons of mass destruction programs.
Disruption and End of the Deception
In the operation’s concluding phase, the impersonated co-founder “Benito Camella” reappeared to question discrepancies in developer identities and documentation. Developer Espree exited the video conference first, followed by Anderson, who recognized the deception and ceased participation. The fake company’s Telegram channel subsequently featured public disputes between the impersonated CEO and “Andy Jones,” culminating in announcements of departures and contract terminations. The sham startup effectively dissolved due to recruitment mismanagement.
Post-operation, at least one suspected North Korean participant privately apologized to García, though others ceased communication. The researchers emphasize that the individuals involved remained unaware they were under intelligence observation.
Implications for Blockchain Security Oversight
This extended covert recruitment exercise offers a rare, detailed view of how North Korean remote IT teams operate, revealing their technical capabilities, infrastructure choices, and recruitment methods. Although these personnel may not always engage in direct cyberattacks, their insider access poses risks to blockchain and cryptocurrency platforms. The findings underscore the necessity for regulators and industry stakeholders to intensify scrutiny on remote teams operating in sensitive segments to guard against indirect manipulations and fund diversions.