Reporter Poses as VC to Expose Suspected North Korean Crypto Operatives
- The investigation used a controlled fake workplace to observe suspected operatives’ identities, tools, working habits and online infrastructure.
- Researchers uncovered questionable identity documents, location-masking technology, AI-assisted work and servers associated with malware families linked to North Korean campaigns.
- A reporter’s simulated investor role formed part of the deception, which eventually ended when researchers challenged workers over their documents.
Cybersecurity researchers used a fake cryptocurrency company to investigate three developers they believe were North Korean operatives, with a reporter joining the deception by posing as a venture capital investor. The fabricated business, Ballena Azul, was presented as a decentralised finance startup, while its systems were designed to monitor the developers’ activity.
Mauro Eldritch and Heiner García recruited the suspected workers through a GitHub-linked intermediary and gave them access to virtual machines that recorded their actions. The developers claimed to live in the United States and provided identification and banking information that researchers said raised questions about their identities. Among the findings were a New York licence belonging to another person and an image that researchers said had been processed using Google Gemini.
During one stage of the investigation, a Cointelegraph reporter joined a Zoom call while impersonating Aelin Ashriver, an investor working for the fictional Definitive Communications. The reporter acted as though Ballena Azul was seeking investment and even suggested the company might receive media coverage.
Related: Australia Eyes Crypto Tax Shake-Up as CGT Discount Changes Loom
Following the Workers’ Digital Trail
The researchers observed the workers using AstrillVPN to obscure their apparent locations, alongside remote-access software, cryptocurrency wallets and tools for transferring two-factor authentication codes. They also found extensive use of artificial intelligence, with ChatGPT helping with coding and basic technical problems and Gemini used for image alteration and document forgery.
The operation also exposed servers that researchers associated with infrastructure previously linked to malware campaigns. When the deception ended, researchers confronted two workers over their documents, prompting them to leave the video meeting. The reporting noted that the workers’ nationality and affiliation could not be independently confirmed and had not been publicly identified by a government agency.
Related: AUSTRAC Shuts Down Cryptolink’s 96 Crypto ATMs Over Compliance Failures