A joint investigation by Mauro Eldritch , founder of BCA LTD , and NorthScan and ANY.RUN , has uncovered one of North Korea’s most dangerous threats: a network of remote IT workers affiliated with the notorious Chollima division of the Lazarus group . For the first time, researchers were able to track the operators in real time, recording their activity on what they believed were actual developer laptops. However, these machines were fully controlled sandbox environments created by ANY.RUN.

The operation began when NorthScan’s Heiner García posed as an American programmer and was approached by a Lazarus recruiter with the alias “ Aaron ” (also known as “Blaze”). Posing as a job-placement “business ,” Blaze attempted to hire the fake programmer as a front, a well-known tactic Chollima uses to infiltrate Western companies, primarily in the finance, cryptocurrency, healthcare , and engineering sectors.
See also: Korea: Arrests for trafficking private videos through hacked IP cameras
The plan followed a familiar pattern:
identity theft or borrowing,
interviews with artificial intelligence tools and sharing answers,
working remotely via the victim's laptop,
funneling salary back to the DRC.
Once Blaze requested full access, including SSN, ID, LinkedIn, Gmail, and 24/7 laptop availability, the team moved on to the next phase.

The Trap: How were the Lazarus hackers caught red-handed?
Instead of using an actual laptop, Mauro Eldritch deployed ANY.RUN Sandbox virtual machines, each configured to resemble a fully functional personal workstation with usage history, developer tools , and routing through a US residential proxy.
The group could also cause crashes, limit connectivity, and record every movement without notifying operators.
See also: University of Pennsylvania: New data breach via Oracle EBS
What did they find in Chollima's toolkit?
Sandbox sessions revealed a simple but effective set of tools designed for identity theft and remote access rather than malware development. Once their Chrome profile was synced, the operators loaded:
– AI-powered task automation tools (Simplify Copilot, AiApply, Final Round AI) for automatically filling out applications and generating interview responses.
– Browser-based OTP generators (OTP.ee / Authenticator.cc) for managing victims' 2FA , after collecting identity documents.
– Google Remote Desktop, configured via PowerShell with a fixed PIN, for continuous control of the host computer.
– Routine system reconnaissance (dxdiag, systeminfo, whoami) to validate hardware and environment.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– Connections consistently routed through Astrill VPN, a pattern linked to previous Lazarus infrastructure.
In one session, the operator even left a message on Notepad asking the “programmer” to upload his ID, SSN, and banking information, confirming the goal of the operation: complete identity theft and workstation takeover without deploying malware.
See also: Hackers distribute ValleyRat via Telegram, WinSCP, Chrome and Teams

Remote recruitment has become a quiet but reliable entry point for identity-based threats. Attackers often reach organizations by targeting individual employees with seemingly legitimate interview requests. Once inside, the risk extends to the entire targeted organization.
The attacker can gain access to internal dashboards, sensitive business data, and administrator-level accounts that have significant business impact. Raising awareness within the company and providing a safe space for teams to report anything suspicious can be the difference between stopping an approach early and dealing with a full-blown internal breach later.
Source: thehackernews.com
