Cybersecurity researchers created a fake DeFi startup called Ballena Azul LTD to trap operators from the North Korean group Famous Chollima, a subdivision of Lazarus. Three developers were recruited through an intermediary using the pseudonym Angelo Cruz, with their computers running in controlled environments monitored by the ANY.RUN sandbox. The fake developers provided falsified identity documents, including a permit edited with Google Gemini bearing a SynthID watermark, along with bank accounts in New York and Kansas. They used AstrillVPN and Google Remote Desktop to conceal their origin and synchronized their Google accounts, exposing passwords and browsing history. These infiltrations illustrate how thousands of North Korean IT workers could gain legitimate access to source code and intellectual property of Western companies for months.
Source: Read the original article

