Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Bitcoin (BTC), ether (ETH) prices hold steady while XMR, HYPE outperform

14 minutes ago

‘DeFi Doesn’t Exist Anymore’ Just Onchain Finance: Andre Cronje

15 minutes ago

CEO of Crypto Lender Delio Gets 15 Years Over $49M Fraud

28 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Thursday, August 13
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Inside the Fake Crypto Startup That Fooled North Korean IT Workers
Cryptocurrency & Free Speech Finance

Inside the Fake Crypto Startup That Fooled North Korean IT Workers

News RoomBy News Room1 day agoNo Comments8 Mins Read2 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Inside the Fake Crypto Startup That Fooled North Korean IT Workers
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

It isn’t often that a reporter gets asked to pose as a venture capitalist to fool suspected North Korean IT workers.

But in June, I found myself joining a Zoom call as “Aelin Ashriver,” an investor from the fictitious Definitive Communications, to meet the development team of crypto startup Ballena Azul.

The IT workers on the call believed they were pitching for VC backing for their startup. In reality they had spent weeks working inside a fake crypto company set up purely to study their methods and infrastructure by Mauro Eldritch, founder of cybersecurity firm BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScane.

Cointelegraph tagged along for one stage of the investigation.

During the call, I played up the ruse by suggesting I might even be able to land Ballena Azul some coverage in Cointelegraph.

So at least someone was telling the truth.

Suspected DPRK IT workers pitch for venture capital backing from the fictitious Definitive Communications, played by Cointelegraph. Source: ANY.RUN

Building a company for suspected North Korean IT workers

Eldritch and García built the fictitious Ballena Azul with infrastructure provided by cybersecurity platform ANY.RUN. An existing UK registration for an unrelated company of the same name, which was dissolved in 2022, added legitimacy to the project.

Eldritch assumed the identity of co-founder “Leonardo Nelson,” while García took on the alias “Andy Jones” and posed as the company’s team lead.

Related: North Korean cyber spies are no longer just remote threats

One of the most valuable pieces of intel that the five-week ruse exposed were the external servers the workers used as intermediary points before connecting to Ballena Azul’s controlled virtual desktops.

Exposed servers were particularly valuable because such infrastructure is often recycled across operations and can remain active for long periods.

García tells Magazine the servers were associated with malware families linked to North Korean campaigns that steal credentials, crypto wallet data and other sensitive information.

“Some of the servers we found were tied back to distributing InvisibleFerret and BeaverTail/OtterCookie in prior years and were active to this day,” he says.

But some others were totally new and had zero intelligence about them, looking clean and keeping outside of mainstream block lists or threat feeds.”

He adds that the infrastructure could serve multiple purposes, with servers previously used for malware distribution also acting as command-and-control infrastructure, and as proxies for operators carrying out their day-to-day work.

The suspected workers do not need to deploy malware to pose a threat, according to the researchers. Once hired, they can gain legitimate access to a company’s internal systems, source code and other sensitive information. The longer they remain undetected, the longer they can continue drawing salaries that researchers say ultimately help fund the North Korean regime.

The operation also showed the group relied on artificial intelligence tools to help compensate for gaps in their technical knowledge. They used ChatGPT for writing and coding, including to answer basic questions and complete assignments they struggled with themselves. They preferred Google Gemini for image alteration and document forgery.

A suspected DPRK IT worker and ChatGPT team up in an attempt to obtain testnet crypto during the Ballena Azul operation. Source: ANY.RUN

Other tools employed included remote desktop software, crypto wallets and a service for sharing two-factor authentication codes.

North Korean IT workers have become a growing cybersecurity threat to the cryptocurrency industry. Consensys said in July that it had engaged a North Korea-linked developer through a third-party service provider before identifying the threat and cutting off access.

In another case, US prosecutors charged four North Korean nationals in 2025 with using false identities to obtain remote IT jobs and allegedly stealing more than $900,000 in cryptocurrency from two companies, including a US blockchain research and development firm.

The US Treasury said in March that North Korean IT worker schemes generated nearly $800 million in 2024 to help fund the Pyongyang regime’s weapons-of-mass-destruction programs.

Inside fake crypto company Ballena Azul

The ruse began when García connected with a recruiter via GitHub, who had been linked to Famous Chollima, a threat group associated with North Korean IT worker operations.

García said that Ballena Azul needed to hire software developers and the recruiter offered up “Jack Anderson,” “Angelo Espree” and “Lucas Theo.” At least two of them presented US identification.

The trio were given various programming assignments inside controlled virtual desktop environments, which allowed García and Eldritch to observe how they worked.

Angelo Espree was one of the developers onboarded through a recruiter associated with DPRK operations. Source: ANY.RUN

The researchers also deliberately introduced technical problems, including selective network outages and disappearing mouse cursors, to see how the suspected workers reacted and which tools they turned to when things went wrong.

“Honestly, the biggest surprise was how much of it ran on improvisation,” García says. “There was no rigid playbook, no polished corporate process behind them.”

During their many weeks working inside the controlled environments, the suspected North Koreans left behind a treasure trove for the researchers, including chat logs, AI conversations, crypto wallet information, VPN exit nodes and hours of live video footage. Their connections also exposed the servers that became one of the investigation’s most valuable findings.

To be sure, the heavy AI reliance isn’t unique to the workers hoodwinked in Ballena Azul’s operation. 

Ballena Azul workers generally used AI as a crutch for coding and technical tasks they struggled with. Reuters reported Monday that another North Korean hacking group, Kimsuky, was using AI for a more offensive purpose. The group was reportedly running AI tools locally to help automate cyberattacks, analyze stolen data and produce more convincing phishing campaigns.

Evolving playbook of remote DPRK IT workers

This was not the first time Cointelegraph has played a minor role in exposing suspected North Korean workers.

In February 2025, García and Cointelegraph conducted a job interview for a suspected operative calling himself “Motoki.” The developer claimed to be Japanese but ragequit the interview after being asked to introduce himself in his mother tongue.

Still, García kept communicating with him. Motoki eventually offered to send García money to buy a computer that he could access remotely, allowing him to work through a local machine instead of connecting through a VPN to bypass restrictions used by employers and freelance platforms.

Related: From Sony to Bybit: How Lazarus Group became crypto’s supervillain

García later documented suspected North Korean operatives recruiting freelancers to provide verified accounts, identities and remote access to their computers. In one version of the scheme, operatives could work through machines physically located in the US, making them appear to employers and freelance platforms as US-based contractors.

In May, two US “laptop farmers” — people who hosted a cluster of computers that North Koreans could remotely access — were sentenced to 18 months in prison for helping DPRK IT workers pose as US-based employees in schemes that generated more than $1.2 million and affected nearly 70 companies.

Taking Ballena Azul down

All fake things must come to an end, so the researchers introduced “Benito Camella,” Ballena Azul’s co-founder, who had supposedly been focused on other business in Milan while the company expanded.

When he returned, Camella confronted the workers over discrepancies in their identities and documents. The confrontation quickly began to clear the chat room. Espree left the video call first, while Anderson stayed longer before realizing the scheme was unraveling.

“Are you living two lives, Mr. Anderson?” Camella asks Jack Anderson during the confrontation. Source: ANY.RUN

But the researchers kept the deception going even after the meeting ended. In the company’s Telegram channel, the “CEO” accused “Andy Jones” of bringing in “illegal workers” and putting the company at risk. “Jones” responded that he had been under pressure to build a team quickly and was not being paid enough to do it. He maintained that he had done the best he could with what he had.

The staged argument ended with the fake CEO terminating both their working relationship and friendship, keeping up the appearance that Ballena Azul had collapsed because of a disastrous hiring decision.

One of the suspected North Koreans later contacted García privately to apologize for what had happened and ask whether he was all right.

According to the researchers, they never heard from the rest of the group again.

To this day, they say, the suspected workers do not know they wasted weeks working inside an environment built to extract intelligence from them.

Magazine: Do the Coldcard attacks mean all hardware wallets are now insecure?

Editor’s note: Cointelegraph could not independently confirm the nationality or affiliation of the suspected DPRK IT workers, and no government agency has publicly identified them.

Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Some articles contain affiliate links, from which Cointelegraph may earn a commission. These relationships do not influence which products we review or our editorial conclusions. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Bitcoin (BTC), ether (ETH) prices hold steady while XMR, HYPE outperform

14 minutes ago
Cryptocurrency & Free Speech Finance

‘DeFi Doesn’t Exist Anymore’ Just Onchain Finance: Andre Cronje

15 minutes ago
Cryptocurrency & Free Speech Finance

CEO of Crypto Lender Delio Gets 15 Years Over $49M Fraud

28 minutes ago
Cryptocurrency & Free Speech Finance

Brazil’s largest BTC digital asset treasury firm plans ETF with 95% STRC allocation

1 hour ago
Cryptocurrency & Free Speech Finance

Binance bStocks passes xStocks as second-largest tokenized stock issuer

1 hour ago
Cryptocurrency & Free Speech Finance

Bitcoin treasury company Metaplanet (3350) unveils BitBonds with $1.3 million private debt sale

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

‘DeFi Doesn’t Exist Anymore’ Just Onchain Finance: Andre Cronje

15 minutes ago

CEO of Crypto Lender Delio Gets 15 Years Over $49M Fraud

28 minutes ago

Why Do Americans Support the Death Penalty, Despite Wrongful Convictions?

60 minutes ago

Brazil’s largest BTC digital asset treasury firm plans ETF with 95% STRC allocation

1 hour ago
Latest Posts

Binance bStocks passes xStocks as second-largest tokenized stock issuer

1 hour ago

Libel Lawsuit Over Highly Publicized L.A. Landlord-Tenant Dispute Thrown Out

2 hours ago

Bitcoin treasury company Metaplanet (3350) unveils BitBonds with $1.3 million private debt sale

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Bitcoin (BTC), ether (ETH) prices hold steady while XMR, HYPE outperform

14 minutes ago

‘DeFi Doesn’t Exist Anymore’ Just Onchain Finance: Andre Cronje

15 minutes ago

CEO of Crypto Lender Delio Gets 15 Years Over $49M Fraud

28 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.