CyberSecurityNews

North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees


A joint undercover investigation has pulled back the curtain on how North Korean IT worker operatives don’t just slip past hiring checks; they settle in, gain trusted access, and quietly work from inside legitimate companies for months at a time.

The research, conducted by threat intelligence specialists Mauro Eldritch (BCA LTD) and Heiner García (NorthScan), in partnership with malware analysis firm ANY.RUN, followed up on an earlier operation documenting recruitment cycles used by Famous Chollima, a group tied to the broader Lazarus ecosystem.

Rather than stopping at the recruitment phase, researchers set up a complete honey-company: a decentralized finance (DeFi) startup called Ballena Azul LTD, equipped with a professional website, branding, and a plausible blockchain pitch.

Ballena Azul Registration Document (Image Source: ANY.RUN)

The goal was to attract real Famous Chollima operatives as job applicants and observe their post-hire activities in granular detail.

North Korean IT Workers Use AI-Forged IDs

Posing as founders and technical leads, researchers connected on GitHub with a recruiter linked to the group. The recruiter introduced a series of developers who vouched for one another, creating a small internal network that mirrored standard DPRK placement schemes once a foothold is established.

Three operatives were ultimately hired across smart contract, frontend, and backend development roles.

Standard onboarding paperwork exposed the fabricated nature of the workers’ identities almost immediately. One submitted driver’s license contained EXIF metadata confirming it was generated using Google Gemini and stamped with a SynthID watermark, demonstrating sophisticated AI document forgery.

DPRK Operatives (Image Source: ANY.RUN)

Another document belonged to a real individual, indicating the use of stolen or leaked identity material.

Instead of shipping physical laptops, the research team provided virtual access via isolated sandbox environments that resembled a virtual desktop infrastructure. As detailed in the ANY.RUN Undercover Investigation Report, researchers recorded every file opened, command executed, and network connection initiated without exposing real corporate assets.

Ballena Azul NFT Marketplace
Ballena Azul NFT Marketplace (Image Source: ANY.RUN)

The captured telemetry revealed a standardized operational toolkit:

  • Initial Reconnaissance: Executing basic system commands and verifying external IP addresses via lookup sites.
  • Remote Management: Installing Google Remote Desktop and syncing personal Google accounts to exfiltrate passwords and browsing histories.
  • Generative AI Assistance: Utilizing ChatGPT to troubleshoot development tasks and write code.
  • Real-Time Translation: Deploying live translation software to bypass English fluency barriers during team meetings.

Network analysis also revealed AstrillVPN exit nodes, proxy servers used to access virtual desktops, and recycled infrastructure with existing threat intelligence tags confirming that operatives regularly reuse tools across distinct DPRK cyber threats.

Operational VectorTools & Infrastructure UsedPrimary Purpose
Identity CreationGoogle Gemini, SynthID, Stolen IDsCreating plausible onboarding personas
Remote ControlGoogle Remote Desktop, AstrillVPN, VultrEstablishing persistent remote access
Development AssistanceChatGPT, Live Translation SoftwareCoding, troubleshooting, and translation
InfrastructureOutlook.com, 2fa.cn, Gorilla ServersAccount management and multi-factor authentication

Unlike traditional malware intrusions aimed at immediate exploitation, this infiltration style relies on long-term patience.

Embedded operatives gain sustained access to proprietary source code, internal communications, and software deployment pipelines while drawing steady salaries that fund regime activities.

When multiple operatives infiltrate a single organization, they can influence code reviews and pull requests without triggering security alarms.

Addressing these complex insider threat risks requires organizations to treat hiring verification as a continuous process rather than a one-time onboarding checkpoint.

Earlier researchers posed as a facilitator to expose how operatives like “Blaze” recruit intermediaries, rent stolen identities, and remotely operate hijacked laptops via AnyDesk and Google Remote Desktop, revealing an AI-driven job-application toolkit and reliance on Astrill VPN.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link