{"id":22466,"date":"2026-08-10T12:41:39","date_gmt":"2026-08-10T12:41:39","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=22466"},"modified":"2026-08-10T12:41:40","modified_gmt":"2026-08-10T12:41:40","slug":"lazarus-group-it-workers-investigation-part-two","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/","title":{"rendered":"Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>Editor\u2019s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner Garc\u00eda from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and <\/em><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a><em>, the leading company in malware analysis and threat intelligence<\/em>.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>The article was written by Mauro and Heiner.<\/em> <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Key Takeaways<\/strong> <\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Researchers created a fake DeFi startup and <strong>hired suspected Famous Chollima operatives<\/strong>, providing a rare inside view of a DPRK IT worker operation. <\/li>\n\n\n\n<li><strong>The investigation followed the scheme beyond recruitment<\/strong>, showing how the operatives worked, collaborated, and accessed company resources after being hired. <\/li>\n\n\n\n<li><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> sandbox environments provided <strong>a live view of the operatives\u2019 behavior<\/strong>, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure. <\/li>\n\n\n\n<li>The findings show that DPRK IT worker schemes are <strong>not only a hiring risk<\/strong>. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes. <\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Introduction<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Back in December, we were <strong>the first ever to fully record the Famous Chollima infiltration cycle<\/strong>. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators\u2019 houses, and even using AI tools for live assistance and translation during interviews.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During that investigation, we posed as facilitators willing to take job interviews and lend them laptops so they could find a job in exchange for a percentage of their salaries. The trick was that those laptops were actually <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN <\/strong>sandbox environments<\/a>, recording every click and every movement they made. This gave us tons of indicators, endless hours of laptop and face-to-face footage, and <strong><a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation\/\" target=\"_blank\" rel=\"noreferrer noopener\">an unprecedented investigation <\/a><\/strong>that made it to the top of many media outlets. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"463\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-1024x463.png\" alt=\"Aaron A.K.A \u201cBlaze\u201d, Famous Chollima Recruiter\" class=\"wp-image-22469\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-1024x463.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-300x136.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-768x348.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-1536x695.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-2048x927.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-370x167.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-270x122.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Famous-Chollima-Recruiter-Exposed-740x335.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Aaron A.K.A \u201cBlaze\u201d, Famous Chollima Recruiter from Episode 1<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">It was definitely not for the faint of heart, requiring months of dedication as we profiled them while acting as their partners in crime. But today, we want to raise the stakes.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This time, instead of playing facilitators, we posed as the founders of <strong>Ballena Azul LTD<\/strong>, a new DeFi protocol working directly with crypto whales across different chains and looking for new developers to build it. Developers we could trust with <em>lots of money<\/em>. More than you and all your friends could ever fit in your pockets. Numbers you can barely read without counting the commas. All while resisting the temptation to drain it to an embargoed nation far away to the East. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"629\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1024x629.png\" alt=\"Ballena Azul LTD \/ Blue Whale LTD Website\" class=\"wp-image-22471\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1024x629.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-300x184.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-768x472.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1536x943.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-2048x1258.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-370x227.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-270x166.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-Blue-Whale-LTD-Website-740x454.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Ballena Azul LTD \/ Blue Whale LTD Website<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This new episode has it all: <strong>an overconfident CEO <\/strong>who does not run background checks on employees, <strong>fake developers <\/strong>with forged documents, <strong>mule bank accounts<\/strong>, <strong>journalists posing as venture capitalists,<\/strong> and <strong>an Italian lawyer <\/strong>who will blow everything up in the end. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This is Smile, You\u2019re on Camera! Episode 2. <\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I hope you already have your popcorn ready.  <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Hello DEF CON\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/XojM5RUyvGs?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Hello DEF CON<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/XojM5RUyvGs\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter I: The Chollimas<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s introduce our main antagonist. Take this as a short recap in case, you\u2019re new to this series or need a refresher on what we are dealing with. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the many divisions operating under the <strong>Lazarus <\/strong>umbrella is <strong>Famous Chollima<\/strong>. Their goal is simple: get hired by Western companies. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They seek remote positions in industries where both intelligence and money are plentiful. Cryptocurrency, finance, and healthcare have historically been among their favorite targets, while more recent campaigns have expanded into pharmaceuticals, civil engineering, architecture, and other sectors. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To secure those positions, they rely on forged identities, fake r\u00e9sum\u00e9s, proxy interviews, remote facilitators and ghost developers, all working together to convince companies that the person they hired is exactly who they claim to be. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-1024x1024.png\" alt=\"DPRK Operatives caught\" class=\"wp-image-22474\" style=\"width:668px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-1024x1024.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-300x300.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-150x150.png 150w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-768x769.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-1534x1536.png 1534w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-70x70.png 70w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-370x370.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-270x270.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught-740x741.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DPRK-Operatives-caught.png 1636w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>DPRK Operatives caught by Bitso Quetzal Team while interviewing for a position at the Company<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Unlike a traditional intrusion, their objective is not to compromise an organization for a few hours or days, but to become a part of it. A successful placement can provide months or even years of continuous access to internal systems, source code, intellectual property and corporate decision-making, while simultaneously generating a legitimate salary that is ultimately channeled back to the DPRK regime. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This makes Famous Chollima a very different kind of threat. Malware operations can produce spectacular results overnight, as demonstrated by recent compromises involving cryptocurrency bridge signers. But those operations are also inherently noisy and carry a significant risk of discovery. An employee, on the other hand, is expected to be there. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The longer they remain trusted, the greater the opportunity to gather intelligence, influence decisions, and gradually become part of the organization itself. If enough operatives were to secure positions within the same company, they could eventually influence engineering decisions, code reviews, pull requests, approvals, or other trust-based processes without ever exploiting software vulnerability. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Knowing that they actively pursue these kinds of opportunities, we decided to create one ourselves. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter II: The Company<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The answer was <strong>Ballena Azul LTD \/ Blue Whale LTD<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On paper, it was exactly the kind of company Famous Chollima would love to work for: <strong>a DeFi protocol working alongside cryptocurrency whales<\/strong> across multiple blockchains and looking for experienced developers to help build the platform. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The protocol itself was simple. By combining NFTs and other on-chain mechanisms, whale wallets could voluntarily identify themselves and publicly signal ownership. The idea was to reduce unnecessary market speculation whenever large sums of money moved, avoiding rumors of exchange hacks, wallet drainers, exit scams, or other events that often trigger panic across the ecosystem. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"677\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-1024x677.png\" alt=\"Ballena Azul LTD on OpenSea NFT Marketplace\" class=\"wp-image-22475\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-1024x677.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-300x198.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-768x508.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-1536x1015.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-2048x1353.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-370x245.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-270x178.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-on-OpenSea-NFT-Marketplace-740x489.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Ballena Azul LTD on OpenSea NFT Marketplace<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Everything had to look legitimate. A professional website, corporate branding, documentation, an online presence and, most importantly, a product that made sense. Not because we expected investors to believe it, but because we expected them to.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"842\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-1024x842.png\" alt=\"Ballena Azul LTD registration in the UK\" class=\"wp-image-22478\" style=\"width:766px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-1024x842.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-300x247.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-768x631.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-1536x1263.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-2048x1684.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-370x304.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-270x222.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Ballena-Azul-LTD-registration-740x608.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>An existing Ballena Azul LTD registration in the UK Companies House helped reinforce the company\u2019s legitimacy. This entity is unrelated to our operation<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I became Leonardo Nelson, co-founder of Ballena Azul LTD. My business partner, <strong>Benito<\/strong>, would be joining our meetings from Italy. At the same time, Heiner returned as <strong>Andy Jones<\/strong>, the developer and facilitator from <a href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation\/\" target=\"_blank\" rel=\"noreferrer noopener\">Episode 1<\/a>. This time he was Ballena Azul\u2019s Team Lead and had been personally recommended to me by Benito. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the infrastructure, we turned to our most trusted provider: <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN<\/strong><\/a>. Now all we needed were developers. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nGive your SOC faster access to investigation context. <br><span class=\"highlight\">Cut MTTR by up to 21 minutes per case.<\/span>\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=lazarus-group-it-workers-investigation-part-two&#038;utm_term=100826&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nAccelerate Threat Investigations<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<p class=\"wp-block-paragraph\">Fortunately, Andy knew just the right person for the job: <strong>Angelo Cruz<\/strong>, <strong>a recruiter from<\/strong> <strong>Famous Chollima <\/strong>who was eager to make a name for himself. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter III: The Horse Trader<\/strong>  <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Angelo Cruz met Andy on <strong>GitHub<\/strong>, definitely a strange place to make friends. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"963\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-963x1024.png\" alt=\"Angelo\u2019s comment on GitHub looking for facilitators\" class=\"wp-image-22480\" style=\"aspect-ratio:0.9404355812122802;width:728px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-963x1024.png 963w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-282x300.png 282w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-768x816.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-1445x1536.png 1445w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-370x393.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-270x287.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub-740x786.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-comment-on-GitHub.png 1592w\" sizes=\"auto, (max-width: 963px) 100vw, 963px\" \/><figcaption class=\"wp-element-caption\"><em>Angelo\u2019s comment on GitHub looking for facilitators<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">They started chatting and before long, Cruz convinced Andy they should work together, with Andy acting as <strong>his trusted facilitator <\/strong>to help his developers find jobs. Andy agreed and soon <strong>introduced Angelo to Ballena Azul LTD<\/strong> as the perfect opportunity. According to the plan, Ballena Azul LTD would become just another company to rob. After all, we trusted Andy\u2019s judgment. Whoever he chose was welcome aboard. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Interview with the Chollima\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/MEBYVMKnXGE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Interview with the Chollima<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/MEBYVMKnXGE\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To generate a false sense of trust, Andy offered to lend them his brother\u2019s ID, but at the end it was not necessary. Not long afterwards, Angelo introduced us to <strong>our first engineer: Angelo Espree<\/strong>. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter IV: The Team<\/strong>  <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Angelo Espree was the first to accept a position at Ballena Azul LTD, making him the <strong>first DPRK IT Worker<\/strong> to step inside our company. He would also become the first dossier in our investigation. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before the interview, Andy and Angelo agreed on a simple story. They would tell me, the CEO, that Benito already knew Angelo, personally vouched for him, and had approved bringing him into the company. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That was how <strong>our first interview began<\/strong>. A Real Madrid supporter with a background in mathematics, Angelo would be responsible for developing the company\u2019s smart contracts. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Angelo\u2019s Interview\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/6VipWEyRXkY?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Angelo\u2019s Interview<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/6VipWEyRXkY\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the interview, we asked Angelo to <strong>scan a QR code <\/strong>to confirm his attendance. He did, and of course, fell for the oldest trick in the book. The QR code silently redirected him to one of our <strong>Canary Tokens<\/strong>, which recorded information about anyone who triggered it, including their <strong>IP address<\/strong>, User-Agent, and more. At the time, it seemed like a small mistake. Later, it would become a key piece of evidence in uncovering <strong>a much broader conspiracy<\/strong>. But we\u2019ll get to that later. For now, we were simply happy to have made new friends. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As friends, we explained that Ballena Azul operated as a fully trust-based environment and that we intended to recruit only people we could genuinely rely on. Angelo already had someone in mind: <strong>his friend Jack Anderson<\/strong>. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"628\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-1024x628.png\" alt=\"Happiness\" class=\"wp-image-22481\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-1024x628.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-300x184.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-768x471.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-1536x941.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-2048x1255.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-370x227.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-270x165.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-interview-740x454.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Happiness<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Jack was noticeably quieter and struggled with English. Throughout the interview, we caught him repeatedly glancing off-screen, as if reading from a second monitor <strong>running a live translation tool<\/strong>, something we had already documented as part of Famous Chollima\u2019s standard toolkit in Episode 1. Like Angelo, Jack had studied mathematics, supported Real Madrid, and didn&#8217;t laugh easily. He nevertheless convinced us, and we welcomed him to Ballena Azul LTD as our Front-end Developer. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Jack\u2019s Interview\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/NOcAtr82yY8?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Jack\u2019s Interview<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/NOcAtr82yY8\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One thing leads to another, and in this line of work everyone needs someone they can trust. Jack had Lucas<strong> Theo, a seasoned Backend Developer<\/strong>. We interviewed him. He understood the role, showed genuine interest in the position, and even told us about his dog, Lul\u00fa, his honeymoon in Philippines and his love for hiking. We had no reason to distrust him. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, we welcomed him to the Ballena Azul family as well. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Lucas\u2019 Interview\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/9-LGFX0nLuw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Lucas\u2019 Interview<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/9-LGFX0nLuw\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With that, they had assembled the perfect crew for a master heist. We, on the other hand, had a stable full of Chollimas waiting to be broken in. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But you know, every good lie needs paperwork. A lot of paperwork. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter V: The Imposters<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It was time to sign the contracts and seal our alliance. But as an experienced CEO, I needed to run a quick background check on my new employees. Surely asking for an ID would be enough, right? I also requested their <strong>address<\/strong>, <strong>cryptocurrency wallets<\/strong>, and <strong>banking details<\/strong>. Standard onboarding paperwork. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jack sent a <strong>driver\u2019s license from Austin<\/strong>, <strong>Texas<\/strong>, where he supposedly lived, along with a valid SSN and a bank account at <strong>Lead Bank <\/strong>in <strong>Kansas City<\/strong>. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"648\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-1024x648.png\" alt=\"Lazarus Jack\u2019s Fake License\" class=\"wp-image-22485\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-1024x648.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-300x190.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-768x486.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-1536x971.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-2048x1295.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-370x234.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-270x171.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-fake-driver-license-740x468.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Jack\u2019s driving license<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Angelo was far more daring. He claimed to be living in <strong>Pasadena<\/strong>, <strong>Texas<\/strong>, yet sent us a <strong>California <\/strong>driver\u2019s license together with a <strong>Citibank <\/strong>account in <strong>New York<\/strong>. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"645\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-1024x645.png\" alt=\"Angelo\u2019s driving license\" class=\"wp-image-22508\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-1024x645.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-300x189.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-768x484.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-1536x968.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-370x233.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-270x170.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license-740x466.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-fake-license.png 1698w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Angelo\u2019s driving license<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The most interesting part was hidden in the <strong>metadata<\/strong>. Several EXIF entries revealed that the image had been processed with <strong>Google Gemini<\/strong>, and a <strong>SynthID <\/strong>watermark had been embedded as well. Between that and the obvious visual inconsistencies, the forgery was almost trivial to detect, unbeknownst to him. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"543\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-1024x543.png\" alt=\"Lazarus investigation: Angelo\u2019s License Metadata\" class=\"wp-image-22487\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-1024x543.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-300x159.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-768x408.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-1536x815.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-2048x1087.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-370x196.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-270x143.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelos-License-Metadata-740x393.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Angelo\u2019s License Metadata<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">If that seemed bold, Lucas<strong> <\/strong>managed to raise the stakes even further. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of sending documents under his own name, he shared a <strong>New York <\/strong>driver\u2019s license belonging to <strong>Pui Chin Teoh<\/strong>, together with a bankaccount from <strong>Wise<\/strong>. Unlike Angelo\u2019s document, the metadata showed it was an <strong>authentic photograph<\/strong> originally taken with an iPhone 15. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately for us, the GPS coordinates had been stripped. Our best guess was that Pui Chin is a real person who had photographed their own driver\u2019s license for a KYC process or similar, only for that image to later be leaked and eventually find its way into Lucas\u2019 hands. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"543\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-1024x543.png\" alt=\"Lazarus investigation Lucas license metadata\" class=\"wp-image-22498\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-1024x543.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-300x159.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-768x408.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-1536x815.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-2048x1087.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-370x196.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-270x143.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-Lucas-license-metadata-740x393.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Lucas\u2019s License Metadata<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">By now, we had <strong>fake identities<\/strong>, <strong>stolen SSNs<\/strong>, <strong>mule bank accounts<\/strong>, possible <strong>facilitator safe houses<\/strong>, and <strong>cryptocurrency wallets <\/strong>with transaction history. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, it was finally time to put my all-star team to work. We still didn\u2019t have laptops ready to ship, but that wasn\u2019t a problem. We told them our provider had set us up with virtual desktops so they could start right away. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That provider was <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN<\/strong><\/a>. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Reduce investigation risk without exposing systems.<\/span><br>\nGive your SOC visibility before impact spreads.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=lazarus-group-it-workers-investigation-part-two&#038;utm_term=100826&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nReduce Operational Risk<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter VI: The North Korean Job<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Capturing face-to-face footage is just as important as capturing everything happening inside the machine. Both provide different pieces of the same puzzle. <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN<\/strong><\/a><strong> <\/strong>was the perfect solution for this, allowing us to record <strong>every file opened<\/strong>, <strong>every network connection<\/strong>, and virtually <strong>every click <\/strong>made inside the system. Not a single byte could move without us noticing <strong>in real time<\/strong>. These instances were especially crafted for this operation, lasting for hours just like a real VDI would do. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We spun up three separate instances and handed each developer their own environment. It was time to watch them work. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the first day, Angelo and the team scouted their machines using almost the exact same playbook from Episode 1. They started with dxdiag(DirectX Diagnostic Tool), systeminfo, and wmic to get a detailed overview of the system, then checked where in the world they appeared to be by visiting legitimate IP lookup websites, in this case IP8. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Everything looked good, so Angelo felt safe enough to open his Google account, install Google Remote Desktop, just as we\u2019d seen in Episode 1, and sync his account with the machine. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, sync his account. Just like in Episode 1. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"612\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-1024x612.png\" alt=\"Lazarus investigation misclick\" class=\"wp-image-22489\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-1024x612.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-300x179.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-768x459.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-1536x918.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-2048x1224.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-370x221.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-270x161.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-wrong-click-740x442.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>A misclick worth millions<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">For those unfamiliar with how Google account synchronization works, it means that all the user\u2019s stored information becomes available on that device, including browsing history, search history, saved passwords, and installed extensions. All of his, from a single misplaced click. In Episode 1, this allowed us to identify the entire Famous Chollima toolset, including the AI tools they used throughout the job acquisition process. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, he didn\u2019t seem to notice and simply moved on to logging into his GitHub account. Business as usual. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"A hard day\u2019s work\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/fmGdsK9Tsfw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>A hard day\u2019s work<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/fmGdsK9Tsfw\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The team advanced on multiple fronts at a rapid pace, which isn\u2019t to say they were doing things the right way. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jack struggled to deliver a frontend that didn\u2019t look completely vibe-coded and identical to half the internet, while Angelo and Lucas wrestled with the backend and the smart contracts. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They <strong>googled the basics<\/strong>, like how to build upgradeable smart contracts, imported an existing MetaMask wallet, and then struggled to scrape together some crypto from testnet faucets. At one point, they even pasted the testnet URL into the wallet address field before eventually complaining to ChatGPT that \u201call of them require real money now.\u201d <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"604\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-1024x604.png\" alt=\"Lazarus: Angelo using ChatGPT\" class=\"wp-image-22490\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-1024x604.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-300x177.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-768x453.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-1536x906.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-2048x1208.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-370x218.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-270x159.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Angelo-using-ChatGPT-740x437.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Angelo using ChatGPT<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">They then carried on working in their repository, now with entirely imaginary assets after failing to claim funds from any faucet. At this point, we were seriously questioning whether this had been the right business decision. Ballena Azul\u2019s next quarterly report was not looking promising. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Employee of the Month\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/2FDAlTeEeYk?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Employee of the Month<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/2FDAlTeEeYk\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Maybe it was just a bad day at work. Everyone has those. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But it never rains but pours. So, we decided to make it a little worse. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In Episode 1, we introduced artificial crashes and network outages to slow the operatives down, then immediately scolded them for \u201cbreaking\u201dthe laptops we\u2019d lent them. This time, we kept the selective network outages but also made the mouse cursor disappear randomly. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"604\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-1024x604.png\" alt=\"Lazarus research: Angelo debugging network outage\" class=\"wp-image-22499\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-1024x604.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-300x177.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-768x453.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-1536x906.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-2048x1208.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-370x218.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-270x159.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-research-Angelo-debugging-work-740x437.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Angelo debugging a selective network outage<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Whenever they complained, we told them that one of our provider\u2019s IT support agents would connect and fix the issue. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What followed was an unexpected reminiscence of something Aaron did with Andy in Episode 1, except this time between Angelo and one of our \u201cIT Support\u201d agents: chatting via Notepad. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Are you there?\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/lCy4BIbKNYI?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Are you there?<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/lCy4BIbKNYI\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Their vibecoding session continued, now wrestling with a faulty NPM installation and dealing with the occasional network outages while juggling ChatGPT results between <strong>Remix and Visual Studio<\/strong>, hoping for the best. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"604\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-1024x604.png\" alt=\"Lazarus: Debugging Node.js issues\" class=\"wp-image-22500\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-1024x604.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-300x177.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-768x453.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-1536x906.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-2048x1208.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-370x218.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-270x159.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Debugging-Node.js-issues-740x437.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Debugging Node.js issues with ChatGPT<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">They were busy, short-staffed, short-skilled, and had first-week deadlines looming over them, so this was the perfect time to summon an old villain from this series: <strong>Captcha Hell<\/strong>. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"604\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-1024x604.png\" alt=\"Lazarus: endless CAPTCHA loop\" class=\"wp-image-22501\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-1024x604.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-300x177.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-768x453.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-1536x906.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-2048x1208.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-370x218.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-270x159.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-CAPTCHA-loop-740x437.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Angelo stuck in an endless CAPTCHA loop<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">After dealing with CAPTCHAs for a couple of minutes, a network failure \u201cforced the VDI to be disposed of\u201d, wiping out all unsaved progress. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The days went by with the Chollimas prancing all over the stable, leaving behind not only faulty code but plenty of tracks: AstrillVPN exit nodes everywhere, chat logs, conversations with AI agents, wallets, and hours of live face footage. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"604\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-1024x604.png\" alt=\"Lazarus investigation: dream building\" class=\"wp-image-22502\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-1024x604.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-300x177.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-768x453.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-1536x906.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-2048x1208.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-370x218.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-270x159.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-investigation-dream-team-740x437.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Building the dream<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">But better than all of that, they exposed something far more interesting, caught in flagrante: <strong>operative servers<\/strong> used as proxies and vantage points to jump into the VDIs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This particular finding is highly valuable, as their servers tend to be long-lived, are often recycled, sometimes host multiple malware families reflecting the evolution of their campaigns over time, and by the end of their lifecycle accumulate tags across the entire threat intelligence landscape. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This was the case for one of them, but not for the other two, which had barely been seen and were tagged simply as \u201cscanner\u201d (\u201cthis host conducts port scans\u201d) and, oddly enough, \u201choneypot\u201d. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But as the days went by, not only did our intelligence collection grow, so did Ballena Azul LTD. It grew so much that it caught the attention of someone who wanted to meet the team behind the next crypto unicorn: a VC investor. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter VII: The Investor<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Mr. Aelin Ashriver worked for Definitive Communications (abbreviated as Def-Comm, which sounds remarkably similar to DEF CON, the conference where we presented this work) and was interested in funding our dream. We held multiple \u201cpractice\u201d sessions with the team, rehearsing our team salute: \u201cHello Def Comm, we\u2019re Ballena Azul LTD!\u201d When the big day finally arrived, everything went smoothly. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At one point during the meeting, Mr. Ashriver asked whether we\u2019d be interested in getting some media attention, mentioning that he could help with that and even claiming to be quite close to Cointelegraph. Of course he was. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mr. Ashriver was, in reality, Yohan Yun, a South Korean correspondent for Cointelegraph and was our partner in crime all the time. And you, dear reader, thought we were done with the plot twists. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Definitive Communications decided to fund Ballena Azul LTD, and you could almost see the dollar signs branded into their retinas. They could already taste the money pouring in. Securing one of the first spots at a startup often meant landing a trusted position, and they could practically feel those cold wallet private keys at the tip of their hooves. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We were climbing to the top. But everything that goes up\u2026 eventually comes down. And so, our downfall began. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Chapter VIII: The Lawyer<\/strong>  <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">I told you we had more plot twists. And believe me, this isn\u2019t the last one. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So far, Heiner (Andy) and I (Leonardo Nelson) had been working with Jack, Angelo and Lucas on a daily basis. But if you\u2019ve been paying attention, there\u2019s one missing name in this equation: Mr. Benito, my co-founder (played by our friend Alejo). He had been in Milan, busy with work and life, and trusted us to keep the house in order while he was away. When he returned, however, he found that we\u2019d turned the house into a stable, and he was not happy about it. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"The Many Lives of Mr Anderson\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/3HHdCePa9oM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>The Many Lives of Mr. Anderson<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/3HHdCePa9oM\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first to run away was Angelo, <strong>completely terrified<\/strong>. Jack took longer to understand what was happening (remember he relied on a rather unusual live translation tool). Benito took full advantage of that and landed one Matrix reference after another while we tried to keep a straight face (\u201c<em>I\u2019ll be as forthcoming as I can be, Mr. Anderson<\/em>\u201d, \u201c<em>Are you living two lives, Mr. Anderson?<\/em>\u201d). Once Jack finally understood the situation, he simply left. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the three of us were alone, we had a laugh to decompress and I could finally say that it was the last time using that costume, even if Benito thought the cap suited me well. But that wasn\u2019t the end of it. Our Telegram channel turned into a screaming match between me, the betrayed CEO, and Andy, the employee with a rather lax attitude towards employment law. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I accused him of bringing in \u201cillegal workers\u201d, still pretending not to fully understand what was really going on, and told him he was going to get me into trouble. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He fired back that he\u2019d been under enormous pressure to build a team quickly and that I wasn\u2019t paying him enough to do it. He\u2019d done the best he could with what he had. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The argument went on for a while until I decided to end not only our partnership, but our friendship as well, telling him that if he had anything else to say, he could channel it through my assistant or through Benito. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a gesture of humanity that I genuinely respect (and I mean it), Angelo reached out to Andy privately to ask whether he was alright and to say he was sorry about what had happened between us. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We never heard from the rest of the group again, who, to this day, still have no idea they were being reverse-spied on. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Reduce Tier 1-to-Tier 2 escalations by up to 30%.<\/span><br>\nGive your SOC clearer evidence for faster decisions.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nReduce SOC Workload<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Bonus Chapter I: Fool me thrice<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">What kind of second season would this be if we couldn\u2019t feature a returning character who mysteriously disappeared without a trace in the first one? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By the time we had assembled the team, we were already too deep to back out, so we did what anyone else would do in our situation: keep going and hire our fifth Beatle. But this one was an old acquaintance, both for you and for us. See for yourself, you probably recognize that voice. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"You\u2019re alive!\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/8Yq7G_hjeQ4?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>You\u2019re alive!<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/8Yq7G_hjeQ4\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Aaron Schulz (\u201cBlaze\u201d from Episode 1) made a <strong>heroic return<\/strong> and was willing to join Ballena Azul LTD, but in the end, we had certain irreconcilable artistic differences: he failed to provide a photo ID \u201cat least for a month, until we were able to pay the first salary.\u201d So, he ended up making a short cameo, but we\u2019re glad to know he\u2019s OK. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Still, there\u2019s one curious surprise left. What would you do if your live translation software suddenly acted up in the middle of the daily stand-up? <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Bonus Chapter II: Cough Syrup<\/strong>  <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This happened to Jack during one of our daily stand-ups. We noticed him panicking in his corner of the meeting as his turn to speak got closer, and we immediately understood that something was acting up on his side, most likely his live translation tool. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, he handled the situation like a man. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Cough syrup\" width=\"770\" height=\"433\" src=\"https:\/\/www.youtube.com\/embed\/KGxbobCqZTA?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\"><em>Cough syrup<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/youtu.be\/KGxbobCqZTA\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the video on YouTube<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He was ready to fake passing out if he had to, so we just let him get away with it this time. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, that was our last surprise, fun fact, or weird tape to show. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before closing this episode, let\u2019s backtrack for a moment and remember that, funny as these guys are, they still pose a threat to our companies and assets. Maybe not willingly, maybe not by choice, but they still do. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, let\u2019s analyze their latest toolset, updating what we\u2019ve seen and what has changed since our last engagement last December. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Famous Chollima New Toolset &amp; Infrastructure<\/strong>  <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This list includes only the<strong> tools we\u2019ve observed<\/strong> in this new episode, which may vary over time or across different operative clusters. <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AnyDesk, Google Remote Desktop: Remote desktop software. <\/li>\n\n\n\n<li>AstrillVPN: VPN service. <\/li>\n\n\n\n<li>Browser extensions: Saved Prompts for GPT, Simplify Copilot, AIApply, Final Round AI. <\/li>\n\n\n\n<li>ChatGPT: Writing and coding. They rely heavily on it to ask mundane questions about things they don\u2019t understand, even completing assignments instead of asking us. <\/li>\n\n\n\n<li>Google Gemini: Image alteration, especially document forgery. <\/li>\n\n\n\n<li>2fa.cn: Sharing 2FA codes across operatives. We noticed they are no longer using authenticator.cc or otp.ee, as in previous engagements. <\/li>\n\n\n\n<li>Cursor, Visual Studio Code and Remix: Coding. <\/li>\n\n\n\n<li>MetaMask, Bitget Wallet: Cryptocurrency wallets. <\/li>\n\n\n\n<li>ip8.com: Checking their exit IP address. <\/li>\n\n\n\n<li>Outlook.com: Previously, we had only observed them using Gmail during these engagements. <\/li>\n\n\n\n<li>System tools: dxdiag, systeminfo, wmic. <\/li>\n\n\n\n<li>VPS: Vultr, Gorilla Servers <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This concludes our engagement. Sadly, it\u2019s time to say goodbye! <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Until next time, Famous Chollima<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Last time we had to part ways, we closed Episode 1 with this very same title: half bad omen, half veiled threat. Whichever it was, it came true, and we\u2019rereusing it here because we still believe this won\u2019t be our last encounter. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And it probably won\u2019t be yours either. At the end of the day, there\u2019s no silver bullet, but the classic playbook still applies: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do your background checks and KYC. If you\u2019re a remote-first company, make them periodic and include in-person verification. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Train your recruiters to spot the red flags. They\u2019re the first line of defence protecting your company. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Block AstrillVPN immediately, along with every service that refuses to cooperate with takedowns or law enforcement requests. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you spot a Famous Chollima, make them really famous by recording their face and sharing it with the intelligence community. You\u2019ll help spread awareness and might prevent an unsuspecting company from hiring a spy or even facing sanctions. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Always doubt. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-1024x1024.png\" alt=\"Lazarus investigation IT workers\" class=\"wp-image-22503\" style=\"width:644px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-1024x1024.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-300x300.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-150x150.png 150w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-768x768.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-70x70.png 70w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-370x370.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-270x270.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2-740x740.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-nvestigation-part-2.png 1254w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Always Doubt<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Trust no one. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-1024x1024.png\" alt=\"Lazarus investigation IT worker scheme\" class=\"wp-image-22504\" style=\"width:650px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-1024x1024.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-300x300.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-150x150.png 150w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-768x768.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-70x70.png 70w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-370x370.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-270x270.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught-740x740.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Lazarus-IT-workers-caught.png 1254w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Trust No One<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">And don\u2019t forget to smile, you\u2019re on camera! \ud83d\ude42<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How ANY.RUN Supports Investigations Like This<\/strong> <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This investigation produced several layers of evidence, from live activity inside the virtual desktops to accounts, wallets, VPN infrastructure, browser data, and network connections linked to the operatives. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> provided the controlled environment needed to capture that activity as it unfolded, preserve the evidence, and examine each action without exposing real corporate systems. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For researchers and security teams, this kind of visibility makes it easier to understand how identities, infrastructure, tools, and behavior come together within an operation. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Trusted by 74% of Fortune 100 companies.<\/span><br>\nScale investigations without adding operational friction.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nStrengthen Security Operations<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\"><strong>About ANY.RUN<\/strong>  <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOCs, MSSPs, and enterprise security teams investigate threats faster and make response decisions based on clear behavioral evidence. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> allows teams to analyze malware, phishing pages, suspicious files, and URLs in a controlled environment while observing the full attack chain in real time. <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a> built on investigations from more than 15,000 organizations and 600,000 security professionals helps teams enrich alerts, uncover related activity, and bring current threat context into detection, hunting, and response workflows. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN is <a href=\"https:\/\/any.run\/compliance\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktocompliance\" target=\"_blank\" rel=\"noreferrer noopener\">SOC 2 Type II attested<\/a>, reflecting its commitment to strong security controls and customer data protection. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>IOCs<\/strong> <\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IPv4: 62[.]33[.]223[.]165 \/\/ INVESTSTROY-NET (InvestStroyTrest)<\/li>\n\n\n\n<li>IPv4: 89[.]187[.]185[.]11 \/\/ DPRK-operated VPS<\/li>\n\n\n\n<li>IPv4: 45[.]77[.]71[.]42 \/\/ DPRK-operated VPS<\/li>\n\n\n\n<li>IPv4: 185[.]152[.]67[.]39 \/\/ DPRK-operated VPS<\/li>\n\n\n\n<li>IPv4: 104[.]250[.]148[.]58 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4: 192[.]200[.]115[.]226 \/\/ AstrillVPN exitnode<\/li>\n\n\n\n<li>IPv4: 107[.]150[.]38[.]250 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4: 206[.]217[.]134[.]34 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>IPv4:199[.]168[.]112[.]175 \/\/ AstrillVPN exit node<\/li>\n\n\n\n<li>0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd<\/li>\n\n\n\n<li>0xA3D6938f152C47A411263573Bb3AF324C25A8eba<\/li>\n\n\n\n<li>0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Further Reading<\/strong>  <\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ANY.RUN Blog: Smile, You\u2019re on Camera! Episode 1 <\/li>\n\n\n\n<li>InsomniHack Switzerland: Smile, You\u2019re on Camera! <\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Editor\u2019s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner Garc\u00eda from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN, the leading company in malware analysis and threat intelligence. The article was written by Mauro and Heiner. Key [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":22519,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[8],"tags":[57,10,34],"class_list":["post-22466","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-analysis","tag-anyrun","tag-cybersecurity","tag-malware-analysis"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Smile, You\u2019re on Camera! Part 2: Lazarus IT Workers Exposed<\/title>\n<meta name=\"description\" content=\"See what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mauro Eldritch&nbsp;and&nbsp;Heiner Garc\u00eda P\u00e9rez\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"24 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/\"},\"author\":{\"name\":\"Mauro Eldritch&nbsp;and&nbsp;Heiner Garc\u00eda P\u00e9rez\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup\",\"datePublished\":\"2026-08-10T12:41:39+00:00\",\"dateModified\":\"2026-08-10T12:41:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/\"},\"wordCount\":4645,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hiring-Lazarus-APT-Remote-Workers-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"malware analysis\"],\"articleSection\":[\"Malware Analysis\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/\",\"name\":\"Smile, You\u2019re on Camera! Part 2: Lazarus IT Workers Exposed\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hiring-Lazarus-APT-Remote-Workers-scaled.png\",\"datePublished\":\"2026-08-10T12:41:39+00:00\",\"dateModified\":\"2026-08-10T12:41:40+00:00\",\"description\":\"See what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hiring-Lazarus-APT-Remote-Workers-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hiring-Lazarus-APT-Remote-Workers-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"Lazarus investigation: part 2\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/lazarus-group-it-workers-investigation-part-two\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware Analysis\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/malware-analysis\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},[{\"@type\":[\"Person\"],\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"Mauro Eldritch\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/Mauro-copy.jpeg\",\"inLanguage\":\"en_US\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/Mauro-copy-150x150.jpeg\",\"caption\":\"Mauro Eldritch\"}},{\"@type\":[\"Person\"],\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"Heiner Garc\u00eda P\u00e9rez\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/Mauro-copy.jpeg\",\"inLanguage\":\"en_US\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/1666601720229-150x150.jpeg\",\"caption\":\"Heiner Garc\u00eda P\u00e9rez\"}}]]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Smile, You\u2019re on Camera! Part 2: Lazarus IT Workers Exposed","description":"See what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/","twitter_misc":{"Written by":"Mauro Eldritch&nbsp;and&nbsp;Heiner Garc\u00eda P\u00e9rez","Est. reading time":"24 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/"},"author":{"name":"Mauro Eldritch&nbsp;and&nbsp;Heiner Garc\u00eda P\u00e9rez","@id":"https:\/\/any.run\/"},"headline":"Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup","datePublished":"2026-08-10T12:41:39+00:00","dateModified":"2026-08-10T12:41:40+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/"},"wordCount":4645,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Hiring-Lazarus-APT-Remote-Workers-scaled.png","keywords":["ANYRUN","cybersecurity","malware analysis"],"articleSection":["Malware Analysis"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/","url":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/","name":"Smile, You\u2019re on Camera! Part 2: Lazarus IT Workers Exposed","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Hiring-Lazarus-APT-Remote-Workers-scaled.png","datePublished":"2026-08-10T12:41:39+00:00","dateModified":"2026-08-10T12:41:40+00:00","description":"See what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Hiring-Lazarus-APT-Remote-Workers-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Hiring-Lazarus-APT-Remote-Workers-scaled.png","width":2560,"height":1243,"caption":"Lazarus investigation: part 2"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation-part-two\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Malware Analysis","item":"https:\/\/any.run\/cybersecurity-blog\/category\/malware-analysis\/"},{"@type":"ListItem","position":3,"name":"Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},[{"@type":["Person"],"@id":"https:\/\/any.run\/","name":"Mauro Eldritch","image":{"@type":"ImageObject","@id":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/Mauro-copy.jpeg","inLanguage":"en_US","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/Mauro-copy-150x150.jpeg","caption":"Mauro Eldritch"}},{"@type":["Person"],"@id":"https:\/\/any.run\/","name":"Heiner Garc\u00eda P\u00e9rez","image":{"@type":"ImageObject","@id":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/01\/Mauro-copy.jpeg","inLanguage":"en_US","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2025\/12\/1666601720229-150x150.jpeg","caption":"Heiner Garc\u00eda P\u00e9rez"}}]]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=22466"}],"version-history":[{"count":33,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22466\/revisions"}],"predecessor-version":[{"id":22524,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22466\/revisions\/22524"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/22519"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=22466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=22466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=22466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}