AI

The Fake Crypto Startup That Lured North Korea's Remote IT Army

Fake crypto startups aren't just scams for retail investors — they're now the trap line for catching the very hackers who've been bleeding the industry dry…

· 6 min read · Blackhat Empire

🚀 Quick Take

Fake crypto startups aren't just scams for retail investors — they're now the trap line for catching the very hackers who've been bleeding the industry dry. A five-week sting operation exposed how suspected North Korean IT workers operate, lean on AI to fill skill gaps, and recycle infrastructure that's been stealing credentials and crypto wallet data for years. For anyone trading onchain, this isn't just a spy story — it's a map of exactly the kind of threats lurking behind the tokens and jobs flowing through this industry, and a reminder that the same AI tools your favorite devs use are now in the hands of adversaries.

The full breakdown comes via Cointelegraph AI.

🛠 What It Is

Security researchers Mauro Eldritch of BCA LTD and Heiner García of Telefónica Tech pulled off something rare: they built a fake crypto startup called Ballena Azul, staffed it with fictitious founders, and watched suspected North Korean IT workers walk straight into it.

The workers thought they were pitching a venture capitalist for funding. In reality, every move they made was inside controlled virtual desktops, monitored to extract intelligence on how they work, what tools they use, and which servers they connect through.

Here's what made it work: Eldritch and García added legitimacy by registering the company under the UK registration of a dissolved firm with the same name. On the call, a Cointelegraph reporter posed as "Aelin Ashriver," a VC from the fictitious Definitive Communications — even offering to land the startup coverage as part of the ruse.

Five weeks later, the take was massive: chat logs, AI conversations, crypto wallet info, VPN exit nodes — and most importantly, the external servers the workers used as intermediary points before touching the controlled environment. Those servers are gold because this kind of infrastructure gets recycled across operations and stays active for long stretches.

The connections were damning. García said some servers were tied to distributing InvisibleFerret and BeaverTail/OtterCookie malware in prior years — families linked to campaigns that steal credentials and crypto wallet data — and were "active to this day."

The workers didn't need to deploy malware to be a threat. Once hired, they could gain legitimate access to internal systems, source code, and sensitive info. And they were paid salaries that researchers say ultimately fund the North Korean regime.

The numbers are staggering: the US Treasury said North Korean IT worker schemes generated nearly $800 million in 2024. In one case, US prosecutors charged four North Korean nationals in 2025 with using fake identities to steal more than $900,000 in crypto from two companies. This isn't a distant geopolitical footnote — it's live threat activity in the same ecosystems you trade on every day.

🧠 Why Traders Should Care

This story matters for you because it tells you exactly how sophisticated the bad actors are that you're trading against.

First, infrastructure recycling. The same servers used for malware distribution pull double duty as command-and-control hubs and proxies for daily operations. That means the wallet-stealing infrastructure from years ago is still live, still catching new victims.

Second, the AI factor. Here's the uncomfortable twist: the suspected workers used ChatGPT for coding and writing, outsourcing assignments they struggled with. They preferred Google Gemini for image alteration and document forgery. AI is leveling the playing field — for good and bad. A team with gaps in technical knowledge can now produce polished work, convincing documents, and sharper phishing attempts.

The takeaway for traders is straightforward: if you're interacting with a "verified" project or developer onchain, don't assume the identity checks mean anything. North Korean operatives use fake US IDs, recruit through GitHub, and present polished front-ends. The threat isn't just hacks — it's social engineering that gets you to trust the wrong person, then quietly access your systems or drain what they can.

Third, the improvisation angle. What stood out to García was how ad hoc these operations were. There's no rigid playbook behind them — which makes them both harder to predict and, ironically, easier to catch if you're paying attention to red flags.

⚡ Trade Smarter With It

You don't need to be a cyber-intelligence analyst to protect yourself from the threats this story exposes. You just need the right free tools — starting with @gmgnalerts.

Every alert in that free multi-chain Telegram network goes through a layered security gate before it reaches you: GoPlus, RugCheck, GMGN entrapment/bundler/holder analysis, LP lock-burn checks. And here's the key — risks are printed ON the alert as warnings. You see the red flags before you ever click.

Before you touch a token, you already know if it's bundled, if holders are concentrated, if liquidity is locked. The intel this sting extracted — the server-hopping, the recycled infrastructure, the AI-assisted forgeries — is exactly what you want to be screening for when you surface suspicious activity onchain.

The rest of the toolkit — the XTRACK milestone tracker, the multibuy scanner, the web terminal, and the GMGN execution hub — is all detailed in the footer below.

🎯 Bottom Line

North Korea's IT army doesn't just hack — it infiltrates, impersonates, and improvises, with AI doing the heavy lifting. The same story playing out in this sting is happening in tokens, jobs, and community channels across crypto every day.

Your edge isn't out-muscling them. It's out-seeing them — with real-time alerts, layered security checks visible before you trade, and a network built to surface red flags instead of hiding them. The attackers have AI on their side. Now you've got the tools to match them.


Blackhat Empire — Free multi-chain crypto alerts: @gmgnalerts (450+ groups, SOL / BSC / ROBINHOOD + more). Security-gated buy/sell alerts with visible warnings. XTRACK @xtrack1bot tracks multiplier milestones; @VBMBbot multibuy scanner. Web terminal: blackhat.finance. Trade via GMGN: gmgn.ai.

DYOR. Not financial advice. Crypto is volatile; never risk more than you can afford to lose.


🏴 Blackhat Empire — Free Alert Network

🚪 Telegram Portal: @gmgnalerts 📲 Trade on GMGN: gmgn.ai 📍 Live plays & full DYOR: blackhat.finance 🏴 Add all 7 MAIN groups: t.me/addlist 💬 Community Chat: @gmgnx_chat 🤖 Power tools: @VBMBbot · @xtrack1bot