
Black eats black? Fake DeFi actually snatched out North Korea's Lazarus real hacker
Source: Security Company ANY.RUN Compiled by: Daily Planet Daily Original title: Fishing Show of the Year, Fake DeFi Picks Out North Korea's Lazarus, Real Madrid Fans, Real Madrid Fans. With a mathematical background, they only use AI to write code. Core point of view: By setting up a fake DeFi company, the security agency successfully infiltrated the “Famous Chollima” hacker group under North Korea's Lazarus Group, revealed its complete process of using false identities, AI tools, and remote collaboration to infiltrate Western companies, and revealed its evolving toolset and infrastructure. Key element: The researchers disguised themselves as recruiters and recruited three North Korean agents within a few months to record their operation behavior, tool usage, and collaboration patterns in real time through the ANY.RUN sandbox environment. Agents used forged driver's licenses, stolen social security numbers, and mule accounts to complete the onboarding process. Some of these documents were processed by Google Gemini and had SynthID watermarks, revealing signs of forgery. Attackers rely on AI tools such as ChatGPT and Google Gemini to encode, translate, and modify files, and use AstrillVPN, remote desktop software, and dedicated servers to covertly access corporate environments. The three agents showed insufficient skills during development, frequently searched for basic issues, and exposed more proxy server and infrastructure information induced by selective network outages and captcha. The investigation found that Famous Chollima aims to lurk within the enterprise for a long time and legally obtain access to code, systems, and intellectual property rights, and is not limited to short-term attacks, and the threat persists significantly. Crypto friends who are often phished have probably heard of the North Korean hacker group Lazarus Group. Its well-known “campaigns” include, but are not limited to: Bybit ($1.5 billion) theft, Ronin Network/Axie Infinity Bridge attack ($6.2 billion), DMM Bitcoin/Ginco related attack ($308 million), Harmony Horizon Bridge attack ($100 million), and Atomic Wallet attacks ($100 million), etc. And the key to the success of these attacks is social engineering — hackers usually disguise themselves as normal job applicants, lurk at crypto companies for years, and wait for the right time. Recently, security agency ANY.RUN joined forces with BCA LTD (a company dedicated to threat intelligence and hunting) and NorthScan (a threat intelligence program to uncover the infiltration of North Korean IT workers) to effectively crack down on North Korean hacker agents. The researchers created a fake DeFi startup and successfully recruited “Famous Chollima” agents under North Korea's Lazarus Group who specialize in human infiltration, to gain an inside perspective on the actions of North Korea's IT workers. The ANY.RUN sandbox environment shows the agent's behavior patterns in real time, revealing their evolving toolsets, remote access workflows, AI tool usage, and supporting infrastructure. This survey went beyond the simple recruitment process and showed in depth how these agents collaborated, obtained, and used company resources after joining the company. The findings suggest that the North Korean IT worker program not only poses a recruitment risk; once agents sneak inside the organization, they can legally obtain access to code, systems, intellectual property, and critical business processes. The following is a report co-authored by the three parties, compiled by Daily Planet Daily. ——————Introduction In December of last year, we fully recorded the infiltration cycle of “Famous Chollima” for the first time. From recruiting collaborators to help them join Western companies, to falsifying documents, shipping laptops to intermediaries, and even using AI tools to assist and translate in real time during interviews, everything is under control. In that survey, we pretended to be a middleman willing to interview them and lend them a laptop in exchange for a percentage of their salary. The point is that those laptops are actually ANY.RUN sandbox environments that record every click and every step they take. This provided us with massive metrics, hours of computer operation videos, and face-to-face contact images, making an unprecedented survey and making headlines in many media. (“Famous Chollima...




