Researchers Built a Fake Crypto Startup to Catch North Korean IT Workers

·
Listen to this article~5 min
Researchers Built a Fake Crypto Startup to Catch North Korean IT Workers

Security researchers created a fake crypto startup, hired three suspected North Korean IT workers, and recorded everything. Here's what they found and how to spot the red flags.

Here's a story that sounds like it came straight out of a spy thriller, but it actually happened in the world of cybersecurity. A team of researchers decided to play a long game against a growing threat: North Korean operatives sneaking into Western companies as remote IT workers. Their plan? Create a completely fake cryptocurrency startup, post real-looking job ads for developers, and then watch what happens when the applications roll in. They ended up hiring three people they strongly suspect were North Korean operatives. But here's the kicker: every single virtual machine the company issued to these new hires was secretly recording everything. Every keystroke, every click, every attempt to move money or exfiltrate data—it was all captured on tape. ### Why This Matters for Hiring Teams The researchers' findings aren't just a cool story for a security conference. They're a goldmine of practical intelligence for anyone who hires remote developers, especially in the crypto, fintech, or software sectors. The way these operatives operate is surprisingly sloppy in some ways, but also deeply deceptive in others. The onboarding paperwork alone is a masterclass in spotting red flags. The first hire they brought on claimed to live in Pasadena, Texas. That sounds normal enough, right? But then they submitted a California driver's license as their ID. And the bank account they provided for payroll? That was based in New York. Three different states, none of them matching up. It's the kind of inconsistency that a quick background check might miss if you're not paying close attention. ### The Classic Red Flags to Watch For If you're running a hiring process for remote roles, here are some patterns the researchers noticed that should make you pause: - **Geographic mismatches**: The address, the ID, and the bank account never align to the same location. This is a huge tell. - **Rushed onboarding**: Operatives tend to push for quick hires and minimal verification steps. They want to get in the door before anyone asks too many questions. - **Generic or overly polished resumes**: They often have spotless work histories that look too perfect, with no gaps and no references that actually pick up the phone. - **Reluctance to turn on cameras**: Even for video calls, they'll often claim technical issues or use poor lighting as an excuse to stay off-screen. ### What the Recording Revealed The virtual machines were set up to log everything, and what they captured was chilling. The new hires didn't just start coding. They immediately began probing the network, looking for ways to pivot into other systems, and attempting to install tools that would let them maintain access. In one case, they tried to set up a cryptocurrency wallet that would route funds to a known North Korean address. This isn't just about one fake company. It's a warning shot for every business that relies on remote talent. The researchers showed that even a small, fake operation could attract these actors within days. Imagine what they'd do to a real company with actual secrets and real money. ### How to Protect Your Own Company You don't need to build a fake startup to protect yourself, but you should take a few lessons from this experiment. First, verify identity documents against each other. If someone's address, license, and bank account don't line up, ask questions. Second, use device fingerprinting and monitoring tools on any hardware you ship to remote workers. You have every right to know what's happening on your own machines. Finally, trust your gut. If a candidate seems too eager, too perfect, or too evasive, slow the process down. The cost of a rigorous background check is nothing compared to the cost of a data breach. The researchers pulled off a brilliant sting, but you don't have to be a spy to protect your business. You just have to be careful.