Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.
The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account.
The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit.
The second supplied a Texas license, a valid Social Security number, and a bank account in Kansas City. The third sent a New York license belonging to someone else, a genuine iPhone 15 photograph with the GPS coordinates stripped.
A successful placement gives the operative a real employee account and real access to source code and internal systems. The July 31 joint alert says North Korean IT workers seek contracts with the intent of remitting their salaries to parent North Korean agencies. It also names documents "forged or altered using image editing software" among the signals employers should watch for.
In April, the Justice Department sentenced two US facilitators over a separate scheme that placed workers at more than 100 US companies on at least 80 stolen identities and earned North Korea more than $5 million. Google's Gemini app can check an image for a SynthID watermark, but it only detects content created or edited by Google's AI models. A negative result does not rule out AI editing by other tools.
The operation was a sequel. A joint investigation by Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and ANY.RUN, a provider of interactive malware analysis and threat intelligence, spent late 2025 posing as a facilitator willing to rent out his identity. The Hacker News covered that operation in December.
This time they became the employer, building a fake DeFi protocol called Ballena Azul. A recruiter trawling GitHub for facilitators delivered the first developer. That developer vouched for a friend, who vouched for a third.
Nobody exploited anything.
Each operative came in through the hiring process, cleared an interview, signed a contract, and was given access to a work VM. The researchers write that these schemes are "not only a hiring risk" because once a placement holds, the worker's access is also authorized and expected.
Day one was reconnaissance. All three ran dxdiag, systeminfo, and wmic to profile their machines, then checked what country their connection appeared to originate from. One then installed Chrome Remote Desktop and synced his personal Google account to the sandbox, handing over his browsing history, saved passwords and installed extensions. He logged into GitHub on the same machine.
The tooling observed in this engagement differed from December. The researchers saw 2fa.cn used for passing two-factor codes between operators; the December operation had used authenticator.cc and otp.ee. Outlook.com appeared where only Gmail had before.
Their browsers carried AI job-application and interview-assistance extensions: AIApply, Final Round AI, Simplify Copilot and a saved-prompts tool for ChatGPT. The report places infrastructure on Vultr and Gorilla Servers and says AstrillVPN exit nodes ran throughout.
Silent Push has separately tracked Astrill as a fixture of North Korean operations.
The researchers advise periodic identity checks rather than one at hire, in-person verification for remote-first companies, recruiter training, and blocking AstrillVPN. The July 31 advisory further notes a single account reached from many addresses in a short window and profile text that reads like machine translation.
The report presents the Gemini-processing metadata and the SynthID watermark as separate findings but does not explain how the watermark itself was detected.
Attribution rests with the researchers, who presented the work at DEF CON 34 in Las Vegas this month. They describe the three as suspected Famous Chollima operatives. CrowdStrike uses that name for North Korea's IT worker operation, while the team places it under the wider Lazarus umbrella.
The eleven-government alert names no vendor actor cluster at all. As of August 11, no government source reviewed for this article had confirmed that identification. The real names behind the three personas are unknown, and the report gives no dates for how long the fake company ran.



