A five-week cybersecurity investigation has exposed how suspected North Korean IT workers were recruited into a completely fabricated crypto startup, unknowingly entering a controlled environment designed to monitor their behavior, tools, infrastructure and connections.
The operation was created by Mauro Eldritch, founder of cybersecurity firm BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScane. The pair built a fictional cryptocurrency company called Ballena Azul specifically to study how suspected North Korean IT workers operate once they gain access to a legitimate-looking organization.
The investigation even involved a reporter posing as a venture capitalist during a Zoom meeting with the suspected workers.
The individuals believed they were interviewing for development positions at a promising crypto startup seeking investment. In reality, almost every aspect of the company had been constructed as part of the investigation.
A Fake Startup Built to Observe the Workers
Eldritch and García created Ballena Azul using infrastructure supplied by cybersecurity platform ANY.RUN.
To make the company appear legitimate, the researchers relied on an existing UK company registration belonging to an unrelated business that had previously operated under the same name before being dissolved in 2022.
The researchers also created fictional identities.
Eldritch presented himself as Ballena Azul co-founder Leonardo Nelson, while García adopted the identity Andy Jones and posed as the company’s team lead.
The suspected workers were then given software development assignments inside controlled virtual desktop environments.
This allowed the researchers to observe their activity while maintaining control over the systems they were using.
A reporter participating in the investigation also joined one of the calls under the fictional identity Aelin Ashriver, supposedly an investor from a fake venture capital firm called Definitive Communications.
During the call, the reporter even suggested that the startup might receive coverage from Cointelegraph, reinforcing the appearance that Ballena Azul was a legitimate company preparing for outside investment.
Researchers Uncover Valuable Network Infrastructure
One of the most significant discoveries came from examining the external servers the workers used before connecting to Ballena Azul’s controlled environments.
These intermediary servers can be particularly valuable to cybersecurity investigators because infrastructure used by threat actors may be reused across multiple operations and remain active for extended periods.
According to García, some of the servers identified during the investigation had previously been associated with malware families connected to North Korean cyber campaigns, including InvisibleFerret and BeaverTail/OtterCookie.
Those malware families have been linked to attempts to steal credentials, cryptocurrency wallet information and other sensitive data.
Some of the servers identified by the researchers were already known through existing threat intelligence databases. Others, however, appeared to be previously undocumented infrastructure.
The researchers said these systems could potentially serve several purposes, including malware distribution, command-and-control operations and proxy infrastructure used by remote workers attempting to conceal their true locations.
The findings are significant because the workers did not necessarily have to deploy malware themselves to create a security risk.
Once hired by a company, a fraudulent employee can receive legitimate access to internal systems, source code, credentials, corporate communications and other sensitive information.
The longer such access remains undetected, the greater the potential exposure.
AI Became a Tool for the Suspected Workers
The investigation also provided insight into how artificial intelligence tools were being used by the suspected workers.
Researchers observed them relying heavily on AI systems to compensate for gaps in their technical knowledge.
ChatGPT was reportedly used for coding, writing, answering basic technical questions and completing assignments that the workers struggled to solve independently.
Google Gemini was reportedly preferred for tasks involving image manipulation and document alteration.
Other tools observed during the operation included remote desktop software, cryptocurrency wallets and services designed to share two-factor authentication codes.
The researchers said the heavy reliance on AI suggested that some of the workers were capable of completing assignments by using external tools even when they lacked the underlying technical expertise themselves.
However, the researchers emphasized that the use of AI was not necessarily the most important finding. The broader concern was how legitimate employment could provide suspected North Korean operators with access to corporate infrastructure and sensitive information.
North Korean IT Workers Are a Growing Crypto Security Threat
The investigation comes amid increasing warnings about North Korean IT workers infiltrating technology and cryptocurrency companies by using false identities.
In July, Consensys disclosed that it had unknowingly engaged a developer linked to North Korea through a third-party service provider. The company subsequently identified the threat and terminated the individual’s access.
In another case, U.S. prosecutors charged four North Korean nationals in 2025 with allegedly using false identities to obtain remote IT jobs and stealing more than $900,000 in cryptocurrency from two companies, including a U.S. blockchain research and development firm.
The U.S. Treasury has also warned about the financial scale of North Korean IT worker operations.
According to Treasury estimates, these schemes generated nearly $800 million in 2024, with the proceeds helping support the North Korean regime and its weapons programs.
For cryptocurrency companies, the threat extends beyond traditional hacking.
A fraudulent employee can potentially obtain privileged access while appearing to be a legitimate member of the organization, creating a security risk that may remain invisible for months.
How Ballena Azul Recruited the Suspected Workers
The investigation began after García established contact with a recruiter through GitHub who had been associated with Famous Chollima, a group linked to North Korean IT worker operations.
The recruiter presented several candidates for positions at the fictional Ballena Azul startup.
Among them were individuals using the names Jack Anderson, Angelo Espree and Lucas Theo. At least two reportedly provided identification documents claiming to show U.S. identities.
The candidates were given programming assignments through controlled virtual desktops.
The researchers deliberately introduced technical problems during the work, including selective network outages and disappearing mouse cursors.
The purpose was to observe how the workers responded when normal development conditions broke down.
The researchers reportedly found that much of their behavior was improvised rather than following a rigid operational playbook.
Over several weeks, the controlled environment accumulated a substantial amount of intelligence, including chat messages, AI conversations, cryptocurrency wallet information, VPN exit nodes and hours of video footage.
The workers’ network connections also exposed the external infrastructure they relied upon, which became one of the most valuable discoveries of the investigation.
The North Korean IT Worker Playbook Is Evolving
The Ballena Azul investigation is part of a broader effort to understand how suspected North Korean operatives infiltrate Western technology companies.
García had previously investigated a suspected operative who claimed to be Japanese during a job interview in 2025. The individual became suspiciously hostile after being asked to introduce himself in his supposed native language.
The investigation later uncovered another tactic: suspected operatives asking freelancers to purchase computers that could then be remotely accessed.
This allows workers operating from outside the United States to perform their jobs through computers physically located inside the country.
The technique can make them appear to employers and freelance platforms as legitimate U.S.-based contractors.
Investigators have also documented so-called “laptop farms,” in which individuals in the United States host computers that remote workers can access.
In May, two U.S. individuals who operated such arrangements were sentenced to 18 months in prison after helping North Korean IT workers pose as U.S.-based employees. The schemes reportedly generated more than $1.2 million and affected nearly 70 companies.
The expanding use of AI adds another layer to the threat.
While the Ballena Azul workers reportedly used AI primarily as an assistant for coding and technical work, other North Korean cyber groups are reportedly using AI more aggressively for offensive operations, including automating attacks, analyzing stolen information and creating more convincing phishing campaigns.
The Researchers Eventually Shut Down Ballena Azul
After collecting intelligence for several weeks, the researchers decided to end the operation.
They introduced another fictional executive, Benito Camella, who supposedly returned from business activities in Milan and confronted the workers over inconsistencies in their identities and documentation.
The confrontation quickly caused the group to fragment.
One worker left the video call first, while another remained online longer before realizing that the situation was collapsing.
The researchers continued the deception after the call ended.
Inside Ballena Azul’s Telegram channel, the fictional CEO accused “Andy Jones” of hiring illegal workers and exposing the company to serious risks.
Jones responded that he had been pressured to build a team quickly and claimed that he had not been adequately compensated for the work.
The staged dispute ultimately ended with the fictional CEO terminating both the professional relationship and the supposed friendship.
The researchers maintained the appearance that Ballena Azul had collapsed because of a disastrous hiring decision.
The Workers Never Learned They Were Being Investigated
One of the suspected North Korean workers later contacted García privately to apologize for what had happened and ask whether he was safe.
According to the researchers, the others never contacted them again.
The most striking aspect of the operation is that the suspected workers reportedly remained unaware that the company they had spent weeks working for did not actually exist.
Instead, they believed they had joined an emerging crypto startup, completed development assignments and interacted with company executives and potential investors.
In reality, the entire environment had been constructed to study their behavior and uncover the infrastructure behind their operations.
The investigation demonstrates why North Korean IT worker schemes represent a different kind of cybersecurity challenge from conventional external attacks. Rather than breaking through a company’s defenses from the outside, fraudulent workers can potentially enter through the front door, receive legitimate credentials and operate inside trusted corporate environments.
For crypto companies, where employees may have access to source code, wallets, private keys, financial systems and sensitive infrastructure, that threat can be particularly serious.
The Ballena Azul operation ultimately turned that strategy against the suspected operatives, transforming a fake crypto startup into a controlled intelligence-gathering environment without the workers realizing they were being monitored.

