NewsCryptoInside the Fake Crypto Startup That Fooled Suspected North Korean IT Workers

Inside the Fake Crypto Startup That Fooled Suspected North Korean IT Workers

Author: Cointelegraph·

Key Takeaways

  • The Ballena Azul operation used a fake crypto company and a staged investor pitch to study suspected North Korean remote IT workers.
  • Researchers collected intelligence including chat logs, AI conversations, cryptocurrency wallet information, VPN exit nodes, and live video footage.
  • The workers relied on tools such as ChatGPT, Google Gemini, remote desktop software, cryptocurrency wallets, and shared two-factor authentication services.
  • The investigation identified intermediary servers that had been reused across campaigns and linked to malware families associated with North Korean operations.
  • The case adds to prior warnings from US authorities and companies that DPRK-linked remote hiring schemes pose a growing risk to crypto and Web3 firms.
Inside the Fake Crypto Startup That Fooled Suspected North Korean IT Workers

It is not every day that a journalist is asked to impersonate a venture capitalist to deceive suspected North Korean IT workers. Yet in June, this reporter joined a Zoom call under the alias "Aelin Ashriver," an investor from the fictional firm Definitive Communications, to meet the development team behind a crypto startup called Ballena Azul.

The workers on the call believed they were pitching their startup for venture capital backing. In reality, they had spent weeks laboring inside a sham crypto company deliberately constructed to study their methods, tools, and infrastructure. The operation was orchestrated by Mauro Eldritch, founder of cybersecurity firm BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScan. Cointelegraph participated in one stage of the investigation.

During the call, this reporter reinforced the ruse by hinting that Ballena Azul might even secure coverage in Cointelegraph — making at least one person on the call genuinely truthful.

Suspected DPRK IT workers pitch for venture capital backing from the fictitious Definitive Communications, played by Cointelegraph. Source: ANY.RUN

Building a Company for Suspected North Korean IT Workers

Eldritch and García constructed the fictitious Ballena Azul using infrastructure supplied by cybersecurity platform ANY.RUN. To bolster the company's apparent legitimacy, they leveraged an existing UK registration for an unrelated company of the same name that had been dissolved in 2022.

Eldritch adopted the persona of co-founder "Leonardo Nelson," while García operated under the alias "Andy Jones," posing as the company's team lead.

Related: North Korean cyber spies are no longer just remote threats

Among the most valuable intelligence gathered during the five-week operation were the external servers the workers used as intermediary connection points before accessing Ballena Azul's controlled virtual desktops. Such infrastructure is highly prized by researchers because it is frequently recycled across campaigns and can remain operational for extended periods. The discovery underscores a broader challenge for defenders: shared server infrastructure can span multiple employers and targeting campaigns, meaning that identifying and blocklisting a single node may disrupt operations far beyond the company where it was first detected.

García told Cointelegraph Magazine that the identified servers were associated with malware families tied to North Korean operations designed to steal credentials, cryptocurrency wallet data, and other sensitive information.

"Some of the servers we found were tied back to distributing InvisibleFerret and BeaverTail/OtterCookie in prior years and were active to this day," he said. "But some others were totally new and had zero intelligence about them, looking clean and keeping outside of mainstream block lists or threat feeds."

He added that the infrastructure could serve multiple functions, with servers previously used for malware distribution also operating as command-and-control nodes and as proxies for workers conducting their daily activities.

According to the researchers, the suspected workers do not need to deploy malware to constitute a threat. Once hired, they can obtain legitimate access to a company's internal systems, source code, and other sensitive data. The longer they evade detection, the longer they can continue collecting salaries that researchers say ultimately help finance the North Korean regime. This insider-access risk is particularly acute in the cryptocurrency sector, where remote-first hiring cultures, rapid team expansion, and direct exposure to digital asset infrastructure can amplify the consequences of a single compromised hire.

The operation also revealed that the group relied heavily on artificial intelligence tools to compensate for gaps in their technical knowledge. They used ChatGPT for writing and coding tasks, including answering basic questions and completing assignments they found challenging. For image alteration and document forgery, they preferred Google Gemini.

A suspected DPRK IT worker and ChatGPT team up in an attempt to obtain testnet crypto during the Ballena Azul operation. Source: ANY.RUN

Additional tools employed by the workers included remote desktop software, cryptocurrency wallets, and a service for sharing two-factor authentication codes. The use of shared 2FA services is a known hallmark of DPRK IT worker schemes, allowing multiple people to bypass authentication controls designed for a single legitimate employee.

North Korean IT workers have emerged as an escalating cybersecurity threat to the cryptocurrency sector. In July, Consensys disclosed that it had inadvertently engaged a North Korea-linked developer through a third-party service provider before identifying the threat and severing access.

In a separate case, US prosecutors charged four North Korean nationals in 2025 with using false identities to secure remote IT jobs, allegedly stealing more than $900,000 in cryptocurrency from two companies, including a US blockchain research and development firm.

The US Treasury stated in March that North Korean IT worker schemes generated nearly $800 million in 2024 to help fund the Pyongyang regime's weapons-of-mass-destruction programs.

Inside Fake Crypto Company Ballena Azul

The operation was set in motion when García connected with a recruiter through GitHub who had been linked to Famous Chollima, a threat group associated with North Korean IT worker operations. Famous Chollima is tracked by multiple cybersecurity firms as a cluster of activity focused on placing DPRK operatives into remote developer roles at Western technology and crypto companies. García indicated that Ballena Azul needed software developers, and the recruiter supplied three candidates: "Jack Anderson," "Angelo Espree," and "Lucas Theo." At least two of them presented US identification.

The trio was assigned various programming tasks within controlled virtual desktop environments, enabling García and Eldritch to monitor their workflows in real time.

Angelo Espree was one of the developers onboarded through a recruiter associated with DPRK operations. Source: ANY.RUN

The researchers also deliberately introduced technical disruptions — including selective network outages and disappearing mouse cursors — to observe how the suspected workers responded and which tools they turned to under pressure.

"Honestly, the biggest surprise was how much of it ran on improvisation," García said. "There was no rigid playbook, no polished corporate process behind them."

Over their many weeks inside the controlled environments, the suspected North Koreans left behind an extensive intelligence cache for the researchers: chat logs, AI conversation histories, cryptocurrency wallet information, VPN exit nodes, and hours of live video footage. Their network connections also exposed the intermediary servers that became one of the investigation's most significant discoveries.

The heavy reliance on AI was not unique to the workers ensnared in the Ballena Azul operation. Reuters reported on Monday that another North Korean hacking group, Kimsuky, was using AI for more offensive purposes. The group was reportedly running AI tools locally to automate cyberattacks, analyze stolen data, and produce more convincing phishing campaigns.

Evolving Playbook of Remote DPRK IT Workers

This was not the first time Cointelegraph has participated in exposing suspected North Korean workers. In February 2025, García and Cointelegraph conducted a job interview with a suspected operative who called himself "Motoki." The developer claimed to be Japanese but abruptly ended the interview after being asked to introduce himself in his native language.

García nevertheless maintained communication. Motoki eventually offered to send García money to purchase a computer he could access remotely, enabling him to work through a local machine instead of connecting via VPN — a tactic designed to bypass the restrictions imposed by employers and freelance platforms.

Related: From Sony to Bybit: How Lazarus Group became crypto's supervillain

García later documented suspected North Korean operatives recruiting freelancers to provide verified accounts, identities, and remote access to their computers. In one variant of the scheme, operatives worked through machines physically located in the United States, making them appear to employers and freelance platforms as US-based contractors.

In May, two US "laptop farmers" — individuals who hosted clusters of computers that North Koreans could access remotely — were sentenced to 18 months in prison for facilitating DPRK IT workers posing as US-based employees. The schemes generated more than $1.2 million and affected nearly 70 companies.

Taking Ballena Azul Down

All deceptions must eventually conclude. The researchers introduced "Benito Camella," Ballena Azul's co-founder, who had ostensibly been attending to other business in Milan while the company expanded.

Upon his return, Camella confronted the workers over discrepancies in their identities and documentation. The confrontation rapidly emptied the chat room. Espree departed the video call first; Anderson remained longer before realizing the scheme was unraveling.

"Are you living two lives, Mr. Anderson?" Camella asks Jack Anderson during the confrontation. Source: ANY.RUN

The researchers sustained the deception even after the meeting ended. In the company's Telegram channel, the "CEO" accused "Andy Jones" of bringing in "illegal workers" and jeopardizing the company. "Jones" responded that he had been under pressure to build a team quickly and was not being compensated adequately. He maintained that he had done the best he could with the resources available.

The staged dispute culminated with the fake CEO terminating both their professional relationship and friendship, preserving the illusion that Ballena Azul had collapsed due to a disastrous hiring decision.

One of the suspected North Koreans later contacted García privately to apologize for what had transpired and to ask whether he was all right. According to the researchers, they never heard from the rest of the group again.

To this day, the researchers say, the suspected workers remain unaware that they spent weeks inside an environment purpose-built to extract intelligence from them. For companies hiring remote developers, particularly in crypto and Web3, the operation's findings reinforce guidance from US federal agencies including the FBI and Department of State: verify identities through video interviews requiring live, contextual responses, scrutinize requests for remote desktop access or shared authentication devices, and monitor for indicators such as consistent VPN routing through unrelated geographies.

Magazine: Do the Coldcard attacks mean all hardware wallets are now insecure?

Editor's note: Cointelegraph could not independently confirm the nationality or affiliation of the suspected DPRK IT workers, and no government agency has publicly identified them.