Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
ID: 8b137b6e-d7f1-569d-a4c8-f1ab46b24eee
STIX ID: report--8b137b6e-d7f1-569d-a4c8-f1ab46b24eee
Feed Name: ANY.RUN's Cybersecurity Blog
Date Published: 2026-08-10
Date Updated: 2026-08-19
Author: Mauro Eldritch and Heiner García Pérez
Researchers created a fake DeFi startup to recruit suspected Lazarus (Famous Chollima) operatives, recording their recruitment, onboarding, remote-access workflows and toolset inside ANY.RUN sandbox VDIs; the investigation exposes long-term insider threat risks from DPRK IT worker placement, documents forged identities and mule accounts, lists observed tools (VPNs, remote desktop, AI image editing, ChatGPT, MetaMask) and provides IOCs including multiple IP addresses and Ethereum addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
