In a months-long operation, cybersecurity researchers built a fictitious crypto startup to attract and monitor suspected North Korean IT workers, gathering intelligence on their methods, tools, and infrastructure. The ruse, which culminated in a staged confrontation, exposed how these remote workers operate and the evolving threat they pose to the crypto industry.
A fake company with real consequences
The operation, led by Mauro Eldritch of BCA LTD and Heiner García of Telefónica Tech, created a fake crypto startup called Ballena Azul. Using infrastructure provided by ANY.RUN, the researchers posed as company executives and hired three developers who were later suspected of being North Korean IT workers. The workers were given programming tasks inside controlled virtual desktop environments, allowing the researchers to observe their behavior, tools, and communication patterns without the workers knowing they were being studied.
Also read: Ravencoin plunges to all-time low as exploit threatens three-day chain reorganization
The investigation, which lasted five weeks, was designed to uncover the external servers and infrastructure that these workers use as intermediaries. According to García, some of the servers were linked to malware families such as InvisibleFerret and BeaverTail/OtterCookie, which are associated with North Korean campaigns targeting credentials and crypto wallet data. Other servers were previously unknown, highlighting the constant evolution of their operational infrastructure.
Why this matters for the crypto industry
North Korean IT workers have become a significant cybersecurity threat to the cryptocurrency sector. By infiltrating companies under false identities, they gain legitimate access to internal systems, source code, and sensitive data. The longer they remain undetected, the more they can extract — and the more they can earn, with funds allegedly supporting the Pyongyang regime’s weapons programs. The US Treasury estimated that such schemes generated nearly $800 million in 2024 alone.
Also read: South Korea removes Travel Rule threshold, expands AML checks to all crypto transfers
The Ballena Azul operation also revealed a heavy reliance on AI tools. The suspected workers used ChatGPT for coding and writing tasks, and Google Gemini for image alteration and document forgery. This dependency highlights a potential vulnerability: their skills may not be as advanced as their access suggests, but their ability to utilize AI makes them more adaptable and dangerous.
Intelligence gains and operational insights
The researchers deliberately introduced technical problems, such as network outages and disappearing mouse cursors, to observe how the workers reacted. García noted that their improvisation was striking, with no rigid playbook or polished corporate process. The workers left behind chat logs, AI conversations, crypto wallet information, VPN exit nodes, and hours of video footage — a treasure trove for threat intelligence.
The exposed servers are particularly valuable because such infrastructure is often recycled across operations. Identifying them allows security teams to block these servers and disrupt future attacks. This operation also builds on earlier work by García, who previously documented North Korean operatives recruiting freelancers for verified accounts and remote access, a scheme that has led to convictions of US “laptop farmers” who hosted machines for remote access.
Conclusion
The Ballena Azul operation is a clear example of proactive threat intelligence. By turning the tables on suspected North Korean IT workers, researchers gained critical insights into their methods and infrastructure. While the workers remain unidentified by government agencies, the findings underscore the persistent and evolving threat to the crypto industry. Companies must remain vigilant in vetting remote hires and monitoring for signs of infiltration, as the cost of a single undetected worker can be substantial.
FAQs
Q1: How did the researchers confirm the workers were North Korean?
They could not independently confirm their nationality or affiliation. The investigation was based on behavioral indicators, infrastructure ties, and connections to known threat groups. No government agency has publicly identified them.
Q2: What tools did the suspected workers use?
They used AI tools like ChatGPT and Google Gemini for coding and document forgery, along with remote desktop software, crypto wallets, and services for sharing two-factor authentication codes.
Q3: What should crypto companies do to protect against such threats?
Companies should implement rigorous identity verification, monitor remote workers for unusual behavior, restrict access to sensitive systems, and collaborate with threat intelligence experts to identify potential red flags.

Be the first to comment