# The Job Offer Was a Trap. Three Suspected North Korean Operatives Walked Right In.


Security researchers built a fake DeFi startup, posted jobs, ran interviews, and watched what happened next. All three hires spent their first day profiling the machines they'd just been given.


---


## Building the Decoy


Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and threat intelligence platform ANY.RUN spent the tail end of 2025 playing a different game: posing as a facilitator willing to rent out an identity to North Korean IT worker rings. That operation, covered by The Hacker News in December, gave them a ground-level view of how the ecosystem works.


This time they flipped the script entirely. They became the employer.


The team constructed a fictional DeFi protocol called Ballena Azul — complete enough to attract real applicants and credible enough to clear a basic due-diligence check. Every virtual machine issued to new hires was logging everything. Recruiter channels on GitHub pointed them toward a first developer. That developer vouched for a second. The second vouched for a third. Classic referral hiring, except the referral network was an ongoing covert operation.


What followed was a masterclass in watching the watchers watch back.


---


## What the Documents Said (And What the Metadata Gave Away)


The researchers' report is most useful as a hiring manager's field guide. Each of the three hires submitted identification and banking paperwork, and each package contained contradictions that individual document checks might have missed entirely but that pattern-matching caught immediately.


The first developer claimed residence in Pasadena, Texas, then submitted a California driver's license and a New York bank account. Image metadata from the submitted documents showed processing by Google Gemini. The team also detected a SynthID watermark — the invisible marker Google embeds in content its AI tools create or edit. That's a specific, actionable signal.


The second applicant submitted a Texas license with a valid Social Security number paired to a Kansas City bank account. On paper, each piece might pass individually. Together, the geography tells a story that doesn't add up.


The third went the identity theft route: a New York license belonging to an actual person, combined with a genuine iPhone 15 photograph — with GPS coordinates stripped.


None of these are sophisticated forgeries by spy-thriller standards. They're adequate forgeries designed to pass cursory verification at scale. The operation banks on hiring teams checking boxes rather than connecting dots across documents. It works because most teams do exactly that.


A note on SynthID: the Google Gemini app can scan images for the watermark, but it only detects content touched by Google's own AI tools. A clean result doesn't mean the document is clean — it means Google's AI wasn't the tool used. Any employer building a detection checklist around SynthID alone is building a sieve.


---


## Day One Was Reconnaissance, Not Onboarding


This is the section that should make every remote-first company uncomfortable.


Within hours of receiving access to their work VMs, all three operatives ran the same diagnostic sweep: dxdiag, systeminfo, and wmic. These are Windows system information tools. They were profiling the machines — hardware specs, OS version, installed software, network configuration. They also checked what country their connection appeared to originate from, presumably to confirm their VPN cover was holding.


One went further. He installed Chrome Remote Desktop and synced his personal Google account to the sandbox. That single action handed the researchers — and would have handed a real employer's adversary — his complete browsing history, saved passwords, and installed browser extensions. He then logged into GitHub on the same machine, linking his personal identity to the work environment he'd been handed.


The researchers note this behavior pattern is documented, consistent, and begins on day one of every successful placement. Which means the threat model for North Korean IT worker infiltration isn't a long-game patience play where the operative slowly earns trust before doing damage. The damage starts immediately. The authorized access that comes with legitimate employment *is* the capability.


Tooling in this engagement differed slightly from the December operation — 2fa.cn replaced authenticator.cc and otp.ee for passing two-factor codes between operators, and Outlook.com appeared alongside Gmail. The underlying infrastructure ran on Vultr and Gorilla Servers, with AstrillVPN exit nodes throughout. Silent Push has tracked Astrill across multiple confirmed North Korean operations; its presence here is consistent with that pattern.


The browser extension inventory is worth noting: AIApply, Final Round AI, Simplify Copilot, and a saved-prompts tool for ChatGPT. These workers use AI interview assistance to clear screening rounds. The AI-assisted hiring process is creating AI-assisted infiltration.


---


## What Defenders Actually Need


The July 31 joint government advisory following this and related incidents lists the signals worth watching: accounts accessed from many different IP addresses in short windows, profile text that reads like machine translation, forged documents. The researchers add AstrillVPN blocking to that list.


But the more durable recommendation is structural. Document checks at hire are necessary but not sufficient. The researchers explicitly call for periodic identity re-verification — not a one-time box at onboarding. For remote-first companies, in-person verification at some point in the relationship is no longer paranoid; it's baseline due diligence.


Recruiter training matters too. The first operative in this sting came through a GitHub recruiter channel specifically known for facilitating these placements. That's not bad luck — that's a pipeline the threat actors deliberately cultivated.


In April, the Justice Department sentenced two US-based facilitators involved in a parallel scheme that placed workers at more than 100 American companies using 80 stolen identities and funneled over $5 million back to North Korean parent agencies. The scale isn't hypothetical. The conviction record isn't hypothetical. The question for any remote-first company that has hired aggressively in crypto, fintech, or DeFi over the last two years is whether they've asked the right questions yet.


---


## HackWire Analysis


What this sting operation reveals goes beyond the mechanics of North Korean IT worker infiltration — it exposes a fundamental mismatch between how modern companies hire and how adversarial actors exploit hiring pipelines.


The crypto and DeFi sectors are disproportionately exposed here for reasons that aren't accidental. Remote-first culture, high tolerance for pseudonymous contributors, rapid hiring cycles, and a developer talent shortage that creates pressure to move candidates quickly through the funnel — all of it creates exactly the conditions these operations require. The researchers' choice of a fake DeFi protocol as cover wasn't arbitrary. It was chosen because that's where the access is easiest to acquire.


The referral network angle deserves more attention than it's getting in other coverage. Hiring managers trust internal referrals. That's a documented bias, and it's being weaponized: one operative vouches for the next, converting social trust into a force multiplier. A single successful placement doesn't just yield one insider — it yields credibility for the next applicant. Companies that rely heavily on employee referrals without independent verification of referred candidates are running a structurally exploitable process.


The SynthID finding is technically interesting but shouldn't become a crutch. The useful frame here is layered verification — geography inconsistencies across documents, account access patterns post-hire, VPN usage on work machines, and behavioral anomalies in the first days of employment. No single signal catches everything. The operatives are adaptive; the playbook is already shifting between engagements. Defenders need to watch for the pattern, not the specific technique.


For security and HR teams reading this: the December operation and this sequel together constitute the most detailed public documentation of these schemes in operation. The researchers published their methodology. Read it before you post your next remote developer role.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)