News
Platform news and market context
News
Platform news and market context
How a Fake Crypto Firm Became a High-Tech Honeypot for Suspected North Korean Operatives
Cybersecurity researchers created a fictitious crypto startup, Ballena Azul, to lure and study suspected North Korean IT workers, successfully gathering intelligence on their infrastructure, tools, and methods over five weeks without the targets' knowledge.

A group of suspected North Korean IT professionals was lured into working for a fraudulent cryptocurrency startup, completely unaware that their every move was being meticulously monitored to gather valuable intelligence.
In an unusual turn of events, a Cointelegraph reporter was even invited to participate in the deception. In June, I joined a Zoom call masquerading as “Aelin Ashriver,” an investor from the non-existent firm Definitive Communications, to meet with the development team of the crypto startup, Ballena Azul. During the call, I enhanced the ruse by hinting that I might be able to secure some press coverage for Ballena Azul in Cointelegraph, a statement that, ironically, contained a grain of truth.
Setting the Trap
The entire operation was orchestrated by Mauro Eldritch, the founder of cybersecurity company BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScane. The IT workers on the video call believed they were making a pitch to secure venture capital funding for their startup. In reality, they had spent weeks operating within a counterfeit crypto company that Eldritch and García had built specifically to study their techniques and infrastructure.
To construct the fake company, the researchers utilized infrastructure from the cybersecurity platform ANY.RUN. They bolstered the project's credibility by using the name of a real, but unrelated, UK company called Ballena Azul, which had been dissolved in 2022. Eldritch adopted the persona of co-founder “Leonardo Nelson,” while García played the role of the company's team lead, “Andy Jones.”
Valuable Intelligence Uncovered
The five-week investigation yielded significant findings, particularly the external servers the workers used as intermediary points before accessing Ballena Azul’s controlled virtual desktops. This kind of infrastructure is a prized discovery because it is frequently reused across different operations and can stay active for extended periods.
García explained to Magazine that these servers were connected to malware families previously associated with North Korean campaigns designed to steal credentials, cryptocurrency wallet data, and other sensitive information.
“Some of the servers we found were tied back to distributing InvisibleFerret and BeaverTail/OtterCookie in prior years and were active to this day,” he stated. García also noted that such infrastructure often serves multiple roles, with servers used for malware distribution also functioning as command-and-control systems and as proxies for operators conducting their daily tasks.
The researchers emphasized that these workers pose a threat even without deploying malware. Upon being hired, they can obtain legitimate access to a company's internal systems, source code, and other confidential data. The longer they go undetected, the more salaries they can collect, which intelligence agencies say are used to fund the North Korean regime.
A Reliance on AI and Other Tools
The sting operation revealed that the group depended heavily on artificial intelligence tools to fill gaps in their technical expertise. They utilized ChatGPT for assistance with writing and coding, including for answering basic questions and finishing tasks they found difficult. For tasks involving image manipulation and document forgery, their preferred tool was Google Gemini.
This reliance on AI is not limited to the workers fooled by the Ballena Azul operation. A recent Reuters report on Monday indicated that another North Korean hacking group, Kimsuky, was using AI for more offensive purposes. That group was reportedly running AI tools on local machines to automate cyberattacks, analyze stolen data, and create more persuasive phishing campaigns.
Beyond AI, the workers in the Ballena Azul sting also used remote desktop software, various crypto wallets, and a service designed for sharing two-factor authentication codes.
The Broader Threat of DPRK IT Workers
The infiltration of the cryptocurrency industry by North Korean IT workers represents a growing cybersecurity risk. In July, Consensys disclosed that it had unknowingly engaged a developer linked to North Korea through a third-party service provider before the threat was identified and access was revoked.
In a separate incident from 2025, U.S. prosecutors charged four North Korean nationals with using fraudulent identities to secure remote IT positions, from which they allegedly stole over $900,000 in cryptocurrency from two companies, one of which was a U.S. blockchain R&D firm.
The financial scale of these operations is significant. The U.S. Treasury stated in March that North Korean IT worker schemes generated close to $800 million in 2024, with the proceeds helping to finance Pyongyang’s weapons of mass destruction programs.
This was not the first time Cointelegraph had a minor part in uncovering suspected North Korean operatives. In February 2025, García and Cointelegraph held a job interview with a suspected agent named “Motoki.” The developer, who claimed to be Japanese, abruptly ragequit the interview after being asked for a self-introduction in his native language.
Despite the abrupt end to the interview, García maintained contact with Motoki. Eventually, Motoki offered to send García money to purchase a computer that he could then access remotely. This would have allowed him to work through a local U.S. machine, bypassing geographic restrictions on employer and freelance platforms.
García subsequently documented a scheme where suspected North Korean operatives recruit freelancers to supply verified accounts, identities, and remote access to their computers. This setup enables operatives to appear as U.S.-based contractors to potential employers. In May, two U.S. "laptop farmers," who hosted computer clusters for remote access by North Koreans, were sentenced to 18 months in prison for their role in schemes that generated more than $1.2 million and impacted nearly 70 companies.
The Operation's Dramatic Finale
The elaborate ruse began when García established contact through GitHub with a recruiter who had connections to Famous Chollima, a threat group known for its association with North Korean IT worker operations. García claimed Ballena Azul needed to hire software developers, and the recruiter proposed three candidates: “Jack Anderson,” “Angelo Espree,” and “Lucas Theo.” At least two of them provided what appeared to be U.S. identification.
The trio was assigned various programming tasks within controlled virtual desktop environments, which enabled García and Eldritch to observe their work methods. The researchers also intentionally created technical glitches, such as selective network failures and disappearing mouse cursors, to monitor how the workers responded and what tools they used under pressure.
“Honestly, the biggest surprise was how much of it ran on improvisation,” García commented. “There was no rigid playbook, no polished corporate process behind them.”
Over their weeks inside the controlled environment, the suspected North Koreans left behind a wealth of data for the researchers. This included chat logs, AI conversations, cryptocurrency wallet details, VPN exit nodes, and hours of live video footage.
As all deceptive operations must conclude, the researchers introduced a new character: “Benito Camella,” the supposed co-founder of Ballena Azul who had allegedly been away on business in Milan. Upon his “return,” Camella confronted the workers about inconsistencies in their identities and documentation. The video call quickly emptied as the confrontation unfolded. Espree was the first to leave, while Anderson remained longer before he too grasped that the scheme was collapsing.
“Are you living two lives, Mr. Anderson?” Camella asked Jack Anderson during the tense exchange.
Even after the meeting concluded, the researchers continued the charade. In the company’s Telegram channel, the fake CEO accused “Andy Jones” of endangering the company by bringing in “illegal workers.” “Jones” retorted that he had been pressured to assemble a team quickly on an insufficient budget and had done his best under the circumstances. This staged argument culminated in the fake CEO terminating their professional relationship and friendship, creating a believable narrative that Ballena Azul had failed due to a catastrophic hiring error.
Sometime later, one of the suspected North Koreans reached out to García privately to apologize for the turmoil and to ask if he was okay. According to the researchers, they have had no further contact with the rest of the group. To this day, the researchers say, the workers have no idea that they spent weeks inside an environment specifically designed to extract intelligence from them.
Discussion about this post
No comment yet
Be the first to share your opinion!