Suspected North Koreans IT workers joined a fake crypto startup — without realizing their every move was being tracked to extract valuable intel.
It isn’t often that a reporter gets asked to pose as a venture capitalist to fool suspected North Korean IT workers.
But in June, I found myself joining a Zoom call as “Aelin Ashriver,” an investor from the fictitious Definitive Communications, to meet the development team of crypto startup Ballena Azul.
The IT workers on the call believed they were pitching for VC backing for their startup. In reality they had spent weeks working inside a fake crypto company set up purely to study their methods and infrastructure by Mauro Eldritch, founder of cybersecurity firm BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScane.
Cointelegraph tagged along for one stage of the investigation.
During the call, I played up the ruse by suggesting I might even be able to land Ballena Azul some coverage in Cointelegraph.
So at least someone was telling the truth.
Suspected DPRK IT workers pitch for venture capital backing from the fictitious Definitive Communications, played by Cointelegraph. Source: ANY.RUN
Eldritch and García built the fictitious Ballena Azul with infrastructure provided by cybersecurity platform ANY.RUN. An existing UK registration for an unrelated company of the same name, which was dissolved in 2022, added legitimacy to the project.
Eldritch assumed the identity of co-founder “Leonardo Nelson,” while García took on the alias “Andy Jones” and posed as the company’s team lead.
Related: North Korean cyber spies are no longer just remote threats
One of the most valuable pieces of intel that the five-week ruse exposed were the external servers the workers used as intermediary points before connecting to Ballena Azul’s controlled virtual desktops.
Source
This article is syndicated for educational reading. For the latest updates, visit the original publisher.
Read on cointelegraph.com