🎭 Lazarus Didn't Hack the Company. It Got Hired.
ANY.RUN built a fake startup to watch North Korean operatives from the inside. The obvious corporate reaction to what they found would turn every remote worker into a suspect.
The part that stuck with me is not that suspected North Korean operatives used ChatGPT/Claude to write code, because half the industry does that and some of them write worse code than the operatives. What got me is that nobody had to break in. They applied, sat through interviews, signed contracts and received their access the same way everyone else in the company did.
Researchers from ANY.RUN, BCA LTD and NorthScan built a fake DeFi startup called Ballena Azul. The whole point was to get hired by the wrong people, specifically the ones connected to Famous Chollima, the branch of Lazarus that plants remote IT workers inside Western companies. The full report is here: https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/
It worked.
The people who got the job received virtual desktops that recorded basically everything, down to the clicks, and the researchers also collected hours of video calls with faces on camera. What shows up in that material is not a hacking crew. It looks like a staffing agency that happens to be criminal, with the forged résumés and the stolen Social Security numbers and the mule bank accounts and the usual VPN plus remote desktop stack, plus someone on standby to quietly take over when a candidate started drowning in an interview.
AI made every layer of this cheaper. ChatGPT for code and for writing decent English, live tools for translation and interview support, and Gemini apparently used to alter an identity document. That last one got caught partly because Gemini’s own SynthID watermark was still sitting in the image (LOL). Funny for about five seconds.
Because another document in the same operation appears to be a real photograph of a real person, probably leaked after a legitimate KYC process. Someone did everything right. Uploaded the selfie, held the ID next to their face, waited for the green checkmark. And then their face went to work in a country they have never visited.
That is the privacy story hiding inside the cybersecurity story, no? A fake employee gets assembled out of real victims. The name belongs to somebody, the tax number to somebody else, the bank account to a third person who probably answered a job ad on Telegram. And the victim is the one who inherits the tax records, the compliance alerts, the call from an investigator about work they never performed. Try explaining that to your bank manager.
The U.S. Department of Justice says one of these networks landed jobs at more than 100 American companies. A separate laptop farm case involved over 300 companies and more than $17 million. So no, this is not a demo built for a conference stage.
The identity problem is bleeding into the technical side too. There is a June 2026 paper called “Synthetic APTs: the Collapse of TTP-Based Attribution” where AI agents were configured to imitate five threat groups, Lazarus among them, and they reproduced a significant portion of the documented behavior of each one. Read that twice. Behaving like Lazarus is about to stop proving that you are Lazarus.
I keep coming back to this one and I do not love where it lands. I am not sure digital evidence means what we all quietly assume it means anymore. Not worthless, obviously, but the confidence level attached to it feels off by a wide margin.
The ANY.RUN investigation is the human version of the same collapse. A face on camera, a résumé that checks out, a consistent time zone, a personal coding style, an interview that goes well. None of that adds up to one real person behind the screen.
And here is where I expect most companies to get it wrong, because they will read this case and immediately buy more webcam checks, more facial recognition, deeper background screening and permanent monitoring of anyone working from home. I understand the reflex, and identity verification really does need to become a serious security control, especially for people touching source code, money or personal data. But verifying someone at a moment that actually matters is not the same thing as watching them forever, and the second one is just surveillance wearing a compliance badge.
ANY.RUN recommends recording the faces of suspected operatives and sharing them with the intelligence community. Inside a controlled counterintelligence operation backed by months of evidence, fine, I get the reasoning. As standing corporate policy it should make you deeply uncomfortable. Your HR department is not an intelligence agency. A facial image processed for identification is biometric data, whatever the vendor calls it in the contract. Suspicion is wrong a lot. And an informal internal watchlist has no expiry date and no appeal process, and in three years nobody at that company will remember why the name is on it.
The better answer is boring, which is probably why nobody sells it at conferences. Verify identity when someone’s level of trust actually changes, instead of once at onboarding and never again. Look at where a document came from and not only at whether it looks right. Confirm the address where you shipped the corporate laptop. Block the remote access tools you never approved, keep privileges small, keep development away from production, and make a second human sign off on sensitive code and financial actions. Periodic re-verification for privileged roles is reasonable if it stays narrow and everyone knows it is happening.



