One of North Korea’s most persistent infiltration schemes—a network of remote IT workers connected to Lazarus Group’s renowned Chollima division—was discovered through a joint investigation headed by Mauro Eldritch, founder of BCA LTD, in collaboration with threat-intel initiative NorthScan and ANY.RUN, a solution for interactive malware analysis and threat intelligence.
Researchers were able to observe the operators in action for the first time, recording their work on what they thought were actual development computers. On the other hand, the machines were long-running, highly controlled sandbox environments built by ANY.RUN.
The operation began when NorthScan’s Heiner García impersonated a U.S. developer targeted by a Lazarus recruiter using the alias “Aaron” (also known as “Blaze”).
Posing as a job-placement “business,” Blaze attempted to hire the bogus developer as a spokesman; a known Chollima method used to smuggle North Korean IT workers into Western organizations read more about Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
