HomeMalware Analysis
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
HomeMalware Analysis
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN, the leading company in malware analysis and threat intelligence.

The article was written by Mauro and Heiner.

Key Takeaways

  • Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation.
  • The investigation followed the scheme beyond recruitment, showing how the operatives worked, collaborated, and accessed company resources after being hired.
  • ANY.RUN sandbox environments provided a live view of the operatives’ behavior, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure.
  • The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes.

Introduction

Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews.

During that investigation, we posed as facilitators willing to take job interviews and lend them laptops so they could find a job in exchange for a percentage of their salaries. The trick was that those laptops were actually ANY.RUN sandbox environments, recording every click and every movement they made. This gave us tons of indicators, endless hours of laptop and face-to-face footage, and an unprecedented investigation that made it to the top of many media outlets.

Aaron A.K.A “Blaze”, Famous Chollima Recruiter
Aaron A.K.A “Blaze”, Famous Chollima Recruiter from Episode 1

It was definitely not for the faint of heart, requiring months of dedication as we profiled them while acting as their partners in crime. But today, we want to raise the stakes.

This time, instead of playing facilitators, we posed as the founders of Ballena Azul LTD, a new DeFi protocol working directly with crypto whales across different chains and looking for new developers to build it. Developers we could trust with lots of money. More than you and all your friends could ever fit in your pockets. Numbers you can barely read without counting the commas. All while resisting the temptation to drain it to an embargoed nation far away to the East.

Ballena Azul LTD / Blue Whale LTD Website
Ballena Azul LTD / Blue Whale LTD Website

This new episode has it all: an overconfident CEO who does not run background checks on employees, fake developers with forged documents, mule bank accounts, journalists posing as venture capitalists, and an Italian lawyer who will blow everything up in the end.

This is Smile, You’re on Camera! Episode 2.

I hope you already have your popcorn ready.

Hello DEF CON

Watch the video on YouTube

Chapter I: The Chollimas

Let’s introduce our main antagonist. Take this as a short recap in case, you’re new to this series or need a refresher on what we are dealing with.

One of the many divisions operating under the Lazarus umbrella is Famous Chollima. Their goal is simple: get hired by Western companies.

They seek remote positions in industries where both intelligence and money are plentiful. Cryptocurrency, finance, and healthcare have historically been among their favorite targets, while more recent campaigns have expanded into pharmaceuticals, civil engineering, architecture, and other sectors.

To secure those positions, they rely on forged identities, fake résumés, proxy interviews, remote facilitators and ghost developers, all working together to convince companies that the person they hired is exactly who they claim to be.

DPRK Operatives caught
DPRK Operatives caught by Bitso Quetzal Team while interviewing for a position at the Company

Unlike a traditional intrusion, their objective is not to compromise an organization for a few hours or days, but to become a part of it. A successful placement can provide months or even years of continuous access to internal systems, source code, intellectual property and corporate decision-making, while simultaneously generating a legitimate salary that is ultimately channeled back to the DPRK regime.

This makes Famous Chollima a very different kind of threat. Malware operations can produce spectacular results overnight, as demonstrated by recent compromises involving cryptocurrency bridge signers. But those operations are also inherently noisy and carry a significant risk of discovery. An employee, on the other hand, is expected to be there.

The longer they remain trusted, the greater the opportunity to gather intelligence, influence decisions, and gradually become part of the organization itself. If enough operatives were to secure positions within the same company, they could eventually influence engineering decisions, code reviews, pull requests, approvals, or other trust-based processes without ever exploiting software vulnerability.

Knowing that they actively pursue these kinds of opportunities, we decided to create one ourselves.

Chapter II: The Company

The answer was Ballena Azul LTD / Blue Whale LTD.

On paper, it was exactly the kind of company Famous Chollima would love to work for: a DeFi protocol working alongside cryptocurrency whales across multiple blockchains and looking for experienced developers to help build the platform.

The protocol itself was simple. By combining NFTs and other on-chain mechanisms, whale wallets could voluntarily identify themselves and publicly signal ownership. The idea was to reduce unnecessary market speculation whenever large sums of money moved, avoiding rumors of exchange hacks, wallet drainers, exit scams, or other events that often trigger panic across the ecosystem.

Ballena Azul LTD on OpenSea NFT Marketplace
Ballena Azul LTD on OpenSea NFT Marketplace

Everything had to look legitimate. A professional website, corporate branding, documentation, an online presence and, most importantly, a product that made sense. Not because we expected investors to believe it, but because we expected them to.

Ballena Azul LTD registration in the UK
An existing Ballena Azul LTD registration in the UK Companies House helped reinforce the company’s legitimacy. This entity is unrelated to our operation

I became Leonardo Nelson, co-founder of Ballena Azul LTD. My business partner, Benito, would be joining our meetings from Italy. At the same time, Heiner returned as Andy Jones, the developer and facilitator from Episode 1. This time he was Ballena Azul’s Team Lead and had been personally recommended to me by Benito.

For the infrastructure, we turned to our most trusted provider: ANY.RUN. Now all we needed were developers.

Give your SOC faster access to investigation context.
Cut MTTR by up to 21 minutes per case.

Accelerate Threat Investigations

Fortunately, Andy knew just the right person for the job: Angelo Cruz, a recruiter from Famous Chollima who was eager to make a name for himself.

Chapter III: The Horse Trader

Angelo Cruz met Andy on GitHub, definitely a strange place to make friends.

Angelo’s comment on GitHub looking for facilitators
Angelo’s comment on GitHub looking for facilitators

They started chatting and before long, Cruz convinced Andy they should work together, with Andy acting as his trusted facilitator to help his developers find jobs. Andy agreed and soon introduced Angelo to Ballena Azul LTD as the perfect opportunity. According to the plan, Ballena Azul LTD would become just another company to rob. After all, we trusted Andy’s judgment. Whoever he chose was welcome aboard.

Interview with the Chollima

Watch the video on YouTube

To generate a false sense of trust, Andy offered to lend them his brother’s ID, but at the end it was not necessary. Not long afterwards, Angelo introduced us to our first engineer: Angelo Espree.

Chapter IV: The Team

Angelo Espree was the first to accept a position at Ballena Azul LTD, making him the first DPRK IT Worker to step inside our company. He would also become the first dossier in our investigation.

Before the interview, Andy and Angelo agreed on a simple story. They would tell me, the CEO, that Benito already knew Angelo, personally vouched for him, and had approved bringing him into the company.

That was how our first interview began. A Real Madrid supporter with a background in mathematics, Angelo would be responsible for developing the company’s smart contracts.

Angelo’s Interview

Watch the video on YouTube

During the interview, we asked Angelo to scan a QR code to confirm his attendance. He did, and of course, fell for the oldest trick in the book. The QR code silently redirected him to one of our Canary Tokens, which recorded information about anyone who triggered it, including their IP address, User-Agent, and more. At the time, it seemed like a small mistake. Later, it would become a key piece of evidence in uncovering a much broader conspiracy. But we’ll get to that later. For now, we were simply happy to have made new friends.

As friends, we explained that Ballena Azul operated as a fully trust-based environment and that we intended to recruit only people we could genuinely rely on. Angelo already had someone in mind: his friend Jack Anderson.

Happiness
Happiness

Jack was noticeably quieter and struggled with English. Throughout the interview, we caught him repeatedly glancing off-screen, as if reading from a second monitor running a live translation tool, something we had already documented as part of Famous Chollima’s standard toolkit in Episode 1. Like Angelo, Jack had studied mathematics, supported Real Madrid, and didn’t laugh easily. He nevertheless convinced us, and we welcomed him to Ballena Azul LTD as our Front-end Developer.

Jack’s Interview

Watch the video on YouTube

One thing leads to another, and in this line of work everyone needs someone they can trust. Jack had Lucas Theo, a seasoned Backend Developer. We interviewed him. He understood the role, showed genuine interest in the position, and even told us about his dog, Lulú, his honeymoon in Philippines and his love for hiking. We had no reason to distrust him.

So, we welcomed him to the Ballena Azul family as well.

Lucas’ Interview

Watch the video on YouTube

With that, they had assembled the perfect crew for a master heist. We, on the other hand, had a stable full of Chollimas waiting to be broken in.

But you know, every good lie needs paperwork. A lot of paperwork.

Chapter V: The Imposters

It was time to sign the contracts and seal our alliance. But as an experienced CEO, I needed to run a quick background check on my new employees. Surely asking for an ID would be enough, right? I also requested their address, cryptocurrency wallets, and banking details. Standard onboarding paperwork.

Jack sent a driver’s license from Austin, Texas, where he supposedly lived, along with a valid SSN and a bank account at Lead Bank in Kansas City.

Lazarus Jack’s Fake License
Jack’s driving license

Angelo was far more daring. He claimed to be living in Pasadena, Texas, yet sent us a California driver’s license together with a Citibank account in New York.

Angelo’s driving license
Angelo’s driving license

The most interesting part was hidden in the metadata. Several EXIF entries revealed that the image had been processed with Google Gemini, and a SynthID watermark had been embedded as well. Between that and the obvious visual inconsistencies, the forgery was almost trivial to detect, unbeknownst to him.

Lazarus investigation: Angelo’s License Metadata
Angelo’s License Metadata

If that seemed bold, Lucas managed to raise the stakes even further.

Instead of sending documents under his own name, he shared a New York driver’s license belonging to Pui Chin Teoh, together with a bankaccount from Wise. Unlike Angelo’s document, the metadata showed it was an authentic photograph originally taken with an iPhone 15.

Unfortunately for us, the GPS coordinates had been stripped. Our best guess was that Pui Chin is a real person who had photographed their own driver’s license for a KYC process or similar, only for that image to later be leaked and eventually find its way into Lucas’ hands.

Lazarus investigation Lucas license metadata
Lucas’s License Metadata

By now, we had fake identities, stolen SSNs, mule bank accounts, possible facilitator safe houses, and cryptocurrency wallets with transaction history.

So, it was finally time to put my all-star team to work. We still didn’t have laptops ready to ship, but that wasn’t a problem. We told them our provider had set us up with virtual desktops so they could start right away.

That provider was ANY.RUN.

Reduce investigation risk without exposing systems.
Give your SOC visibility before impact spreads.

Reduce Operational Risk

Chapter VI: The North Korean Job

Capturing face-to-face footage is just as important as capturing everything happening inside the machine. Both provide different pieces of the same puzzle. ANY.RUN was the perfect solution for this, allowing us to record every file opened, every network connection, and virtually every click made inside the system. Not a single byte could move without us noticing in real time. These instances were especially crafted for this operation, lasting for hours just like a real VDI would do.

We spun up three separate instances and handed each developer their own environment. It was time to watch them work.

On the first day, Angelo and the team scouted their machines using almost the exact same playbook from Episode 1. They started with dxdiag(DirectX Diagnostic Tool), systeminfo, and wmic to get a detailed overview of the system, then checked where in the world they appeared to be by visiting legitimate IP lookup websites, in this case IP8.

Everything looked good, so Angelo felt safe enough to open his Google account, install Google Remote Desktop, just as we’d seen in Episode 1, and sync his account with the machine.

Yes, sync his account. Just like in Episode 1.

Lazarus investigation misclick
A misclick worth millions

For those unfamiliar with how Google account synchronization works, it means that all the user’s stored information becomes available on that device, including browsing history, search history, saved passwords, and installed extensions. All of his, from a single misplaced click. In Episode 1, this allowed us to identify the entire Famous Chollima toolset, including the AI tools they used throughout the job acquisition process.

However, he didn’t seem to notice and simply moved on to logging into his GitHub account. Business as usual.

A hard day’s work

Watch the video on YouTube

The team advanced on multiple fronts at a rapid pace, which isn’t to say they were doing things the right way.

Jack struggled to deliver a frontend that didn’t look completely vibe-coded and identical to half the internet, while Angelo and Lucas wrestled with the backend and the smart contracts.

They googled the basics, like how to build upgradeable smart contracts, imported an existing MetaMask wallet, and then struggled to scrape together some crypto from testnet faucets. At one point, they even pasted the testnet URL into the wallet address field before eventually complaining to ChatGPT that “all of them require real money now.”

Lazarus: Angelo using ChatGPT
Angelo using ChatGPT

They then carried on working in their repository, now with entirely imaginary assets after failing to claim funds from any faucet. At this point, we were seriously questioning whether this had been the right business decision. Ballena Azul’s next quarterly report was not looking promising.

Employee of the Month

Watch the video on YouTube

Maybe it was just a bad day at work. Everyone has those.

But it never rains but pours. So, we decided to make it a little worse.

In Episode 1, we introduced artificial crashes and network outages to slow the operatives down, then immediately scolded them for “breaking”the laptops we’d lent them. This time, we kept the selective network outages but also made the mouse cursor disappear randomly.

Lazarus research: Angelo debugging network outage
Angelo debugging a selective network outage

Whenever they complained, we told them that one of our provider’s IT support agents would connect and fix the issue.

What followed was an unexpected reminiscence of something Aaron did with Andy in Episode 1, except this time between Angelo and one of our “IT Support” agents: chatting via Notepad.

Are you there?

Watch the video on YouTube

Their vibecoding session continued, now wrestling with a faulty NPM installation and dealing with the occasional network outages while juggling ChatGPT results between Remix and Visual Studio, hoping for the best.

Lazarus: Debugging Node.js issues
Debugging Node.js issues with ChatGPT

They were busy, short-staffed, short-skilled, and had first-week deadlines looming over them, so this was the perfect time to summon an old villain from this series: Captcha Hell.

Lazarus: endless CAPTCHA loop
Angelo stuck in an endless CAPTCHA loop

After dealing with CAPTCHAs for a couple of minutes, a network failure “forced the VDI to be disposed of”, wiping out all unsaved progress.

The days went by with the Chollimas prancing all over the stable, leaving behind not only faulty code but plenty of tracks: AstrillVPN exit nodes everywhere, chat logs, conversations with AI agents, wallets, and hours of live face footage.

Lazarus investigation: dream building
Building the dream

But better than all of that, they exposed something far more interesting, caught in flagrante: operative servers used as proxies and vantage points to jump into the VDIs.

This particular finding is highly valuable, as their servers tend to be long-lived, are often recycled, sometimes host multiple malware families reflecting the evolution of their campaigns over time, and by the end of their lifecycle accumulate tags across the entire threat intelligence landscape.

This was the case for one of them, but not for the other two, which had barely been seen and were tagged simply as “scanner” (“this host conducts port scans”) and, oddly enough, “honeypot”.

But as the days went by, not only did our intelligence collection grow, so did Ballena Azul LTD. It grew so much that it caught the attention of someone who wanted to meet the team behind the next crypto unicorn: a VC investor.

Chapter VII: The Investor

Mr. Aelin Ashriver worked for Definitive Communications (abbreviated as Def-Comm, which sounds remarkably similar to DEF CON, the conference where we presented this work) and was interested in funding our dream. We held multiple “practice” sessions with the team, rehearsing our team salute: “Hello Def Comm, we’re Ballena Azul LTD!” When the big day finally arrived, everything went smoothly.

At one point during the meeting, Mr. Ashriver asked whether we’d be interested in getting some media attention, mentioning that he could help with that and even claiming to be quite close to Cointelegraph. Of course he was.

Mr. Ashriver was, in reality, Yohan Yun, a South Korean correspondent for Cointelegraph and was our partner in crime all the time. And you, dear reader, thought we were done with the plot twists.

Definitive Communications decided to fund Ballena Azul LTD, and you could almost see the dollar signs branded into their retinas. They could already taste the money pouring in. Securing one of the first spots at a startup often meant landing a trusted position, and they could practically feel those cold wallet private keys at the tip of their hooves.

We were climbing to the top. But everything that goes up… eventually comes down. And so, our downfall began.

Chapter VIII: The Lawyer

I told you we had more plot twists. And believe me, this isn’t the last one.

So far, Heiner (Andy) and I (Leonardo Nelson) had been working with Jack, Angelo and Lucas on a daily basis. But if you’ve been paying attention, there’s one missing name in this equation: Mr. Benito, my co-founder (played by our friend Alejo). He had been in Milan, busy with work and life, and trusted us to keep the house in order while he was away. When he returned, however, he found that we’d turned the house into a stable, and he was not happy about it.

The Many Lives of Mr. Anderson

Watch the video on YouTube

The first to run away was Angelo, completely terrified. Jack took longer to understand what was happening (remember he relied on a rather unusual live translation tool). Benito took full advantage of that and landed one Matrix reference after another while we tried to keep a straight face (“I’ll be as forthcoming as I can be, Mr. Anderson”, “Are you living two lives, Mr. Anderson?”). Once Jack finally understood the situation, he simply left.

Once the three of us were alone, we had a laugh to decompress and I could finally say that it was the last time using that costume, even if Benito thought the cap suited me well. But that wasn’t the end of it. Our Telegram channel turned into a screaming match between me, the betrayed CEO, and Andy, the employee with a rather lax attitude towards employment law.

I accused him of bringing in “illegal workers”, still pretending not to fully understand what was really going on, and told him he was going to get me into trouble.

He fired back that he’d been under enormous pressure to build a team quickly and that I wasn’t paying him enough to do it. He’d done the best he could with what he had.

The argument went on for a while until I decided to end not only our partnership, but our friendship as well, telling him that if he had anything else to say, he could channel it through my assistant or through Benito.

In a gesture of humanity that I genuinely respect (and I mean it), Angelo reached out to Andy privately to ask whether he was alright and to say he was sorry about what had happened between us.

We never heard from the rest of the group again, who, to this day, still have no idea they were being reverse-spied on.

Reduce Tier 1-to-Tier 2 escalations by up to 30%.
Give your SOC clearer evidence for faster decisions.

Reduce SOC Workload

Bonus Chapter I: Fool me thrice

What kind of second season would this be if we couldn’t feature a returning character who mysteriously disappeared without a trace in the first one?

By the time we had assembled the team, we were already too deep to back out, so we did what anyone else would do in our situation: keep going and hire our fifth Beatle. But this one was an old acquaintance, both for you and for us. See for yourself, you probably recognize that voice.

You’re alive!

Watch the video on YouTube

Aaron Schulz (“Blaze” from Episode 1) made a heroic return and was willing to join Ballena Azul LTD, but in the end, we had certain irreconcilable artistic differences: he failed to provide a photo ID “at least for a month, until we were able to pay the first salary.” So, he ended up making a short cameo, but we’re glad to know he’s OK.

Still, there’s one curious surprise left. What would you do if your live translation software suddenly acted up in the middle of the daily stand-up?

Bonus Chapter II: Cough Syrup

This happened to Jack during one of our daily stand-ups. We noticed him panicking in his corner of the meeting as his turn to speak got closer, and we immediately understood that something was acting up on his side, most likely his live translation tool.

So, he handled the situation like a man.

Cough syrup

Watch the video on YouTube

He was ready to fake passing out if he had to, so we just let him get away with it this time.

Now, that was our last surprise, fun fact, or weird tape to show.

Before closing this episode, let’s backtrack for a moment and remember that, funny as these guys are, they still pose a threat to our companies and assets. Maybe not willingly, maybe not by choice, but they still do.

So, let’s analyze their latest toolset, updating what we’ve seen and what has changed since our last engagement last December.

Famous Chollima New Toolset & Infrastructure

This list includes only the tools we’ve observed in this new episode, which may vary over time or across different operative clusters.

  • AnyDesk, Google Remote Desktop: Remote desktop software.
  • AstrillVPN: VPN service.
  • Browser extensions: Saved Prompts for GPT, Simplify Copilot, AIApply, Final Round AI.
  • ChatGPT: Writing and coding. They rely heavily on it to ask mundane questions about things they don’t understand, even completing assignments instead of asking us.
  • Google Gemini: Image alteration, especially document forgery.
  • 2fa.cn: Sharing 2FA codes across operatives. We noticed they are no longer using authenticator.cc or otp.ee, as in previous engagements.
  • Cursor, Visual Studio Code and Remix: Coding.
  • MetaMask, Bitget Wallet: Cryptocurrency wallets.
  • ip8.com: Checking their exit IP address.
  • Outlook.com: Previously, we had only observed them using Gmail during these engagements.
  • System tools: dxdiag, systeminfo, wmic.
  • VPS: Vultr, Gorilla Servers

This concludes our engagement. Sadly, it’s time to say goodbye!

Until next time, Famous Chollima

Last time we had to part ways, we closed Episode 1 with this very same title: half bad omen, half veiled threat. Whichever it was, it came true, and we’rereusing it here because we still believe this won’t be our last encounter.

And it probably won’t be yours either. At the end of the day, there’s no silver bullet, but the classic playbook still applies:

Do your background checks and KYC. If you’re a remote-first company, make them periodic and include in-person verification.

Train your recruiters to spot the red flags. They’re the first line of defence protecting your company.

Block AstrillVPN immediately, along with every service that refuses to cooperate with takedowns or law enforcement requests.

If you spot a Famous Chollima, make them really famous by recording their face and sharing it with the intelligence community. You’ll help spread awareness and might prevent an unsuspecting company from hiring a spy or even facing sanctions.

Always doubt.

Lazarus investigation IT workers
Always Doubt

Trust no one.

Lazarus investigation IT worker scheme
Trust No One

And don’t forget to smile, you’re on camera! 🙂

How ANY.RUN Supports Investigations Like This

This investigation produced several layers of evidence, from live activity inside the virtual desktops to accounts, wallets, VPN infrastructure, browser data, and network connections linked to the operatives.

ANY.RUN provided the controlled environment needed to capture that activity as it unfolded, preserve the evidence, and examine each action without exposing real corporate systems.

For researchers and security teams, this kind of visibility makes it easier to understand how identities, infrastructure, tools, and behavior come together within an operation.

Trusted by 74% of Fortune 100 companies.
Scale investigations without adding operational friction.

Strengthen Security Operations

About ANY.RUN

ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOCs, MSSPs, and enterprise security teams investigate threats faster and make response decisions based on clear behavioral evidence.

Its Interactive Sandbox allows teams to analyze malware, phishing pages, suspicious files, and URLs in a controlled environment while observing the full attack chain in real time. Threat Intelligence built on investigations from more than 15,000 organizations and 600,000 security professionals helps teams enrich alerts, uncover related activity, and bring current threat context into detection, hunting, and response workflows.

ANY.RUN is SOC 2 Type II attested, reflecting its commitment to strong security controls and customer data protection.

IOCs

  • IPv4: 62[.]33[.]223[.]165 // INVESTSTROY-NET (InvestStroyTrest)
  • IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS
  • IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS
  • IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS
  • IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node
  • IPv4: 192[.]200[.]115[.]226 // AstrillVPN exitnode
  • IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node
  • IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node
  • IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node
  • 0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd
  • 0xA3D6938f152C47A411263573Bb3AF324C25A8eba
  • 0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0

Further Reading

  • ANY.RUN Blog: Smile, You’re on Camera! Episode 1
  • InsomniHack Switzerland: Smile, You’re on Camera!
Mauro
Mauro Eldritch
+ posts

Mauro Eldritch is an Argentinian-Uruguayan hacker, founder of BCA LTD and DC5411 (Argentina / Uruguay). He has spoken at various events, including DEF CON (12 times). He is passionate about Threat Intelligence and Biohacking. He currently leads Bitso’s Quetzal Team, the first in Latin America dedicated to Web3 Threat Research.

Follow Mauro on:
X
LinkedIn
GitHub

Heiner García Pérez
Heiner García Pérez
Strategic Intelligence and Cyber Threat Intelligence Analyst |  + posts

Heiner García Pérez is a Strategic Intelligence and Cyber Threat Intelligence Analyst specializing in Financial Crimes with experience in the cybersecurity, military, and mining sectors, ensuring a high degree of confidentiality and commitment.

Follow Heiner on:
LinkedIn
Medium

mauro-eldritch
Mauro Eldritch
Mauro Eldritch is an Argentinian-Uruguayan hacker, founder of BCA LTD and DC5411 (Argentina / Uruguay). He has spoken at various events, including DEF CON (12 times). He is passionate about Threat Intelligence and Biohacking. He currently leads Bitso’s Quetzal Team, the first in Latin America dedicated to Web3 Threat Research.

Follow Mauro on:
X
LinkedIn
GitHub
heiner-garcia-perez
Heiner García Pérez
Strategic Intelligence and Cyber Threat Intelligence Analyst
Heiner García Pérez is a Strategic Intelligence and Cyber Threat Intelligence Analyst specializing in Financial Crimes with experience in the cybersecurity, military, and mining sectors, ensuring a high degree of confidentiality and commitment.

Follow Heiner on:
LinkedIn
Medium

What do you think about this post?

8 answers

  • Awful
  • Average
  • Great

No votes so far! Be the first to rate this post.

0 comments