Researchers Set Up a Fake Crypto Company and Hired Three Suspected North Korean IT Workers
The sting recorded every keystroke on the laptops the fake employer issued, exposing the paper trail of a scheme US officials say funnels wages back to Pyongyang.

Key points
- Security researchers built a fake cryptocurrency startup, posted developer jobs, and hired three applicants they assess with medium confidence as North Korean operatives.
- Every virtual machine issued to the new hires was quietly recording, capturing the onboarding paperwork and payment details the workers submitted.
- One hire claimed to live in Pasadena, Texas but produced a California driver's license and a New York bank account, consistent with prior DPRK IT worker cases.
- US Treasury and FBI advisories tie this activity cluster, tracked by some vendors as Wagemole with infrastructure overlapping the Lazarus umbrella, to sanctions-evading revenue for the North Korean regime.
- The researchers say the goal was to collect defender-useful artefacts, and they're sharing hiring red flags with other employers.
A group of security researchers ran a sting on people they believe are North Korean IT workers. The trap was a company that never existed.
The setup: a fake cryptocurrency startup with real developer job postings. Three people accepted offers and received work laptops. None of it was what it appeared.
Each laptop was a virtual machine, a software-only computer running inside the researchers' own systems, recording throughout. The hires didn't know. The result, first reported by The Hacker News, is a rare inside look at how suspected DPRK (Democratic People's Republic of Korea) IT workers get through Western hiring pipelines.
Who are these workers, and why does anyone care?
They're people the US government says North Korea places abroad to take remote tech jobs under false identities, then send most of their pay back to the regime. The FBI and Treasury have warned employers about the scheme since 2022.
Security vendors track the activity under several names. CrowdStrike calls the cluster Famous Chollima. Others file it under Wagemole, with TTPs (tools, techniques and procedures) overlapping the wider Lazarus umbrella North Korea runs for cyber operations. We first reported on Famous Chollima in June, when North Korea-linked recruiters pivoted to code-review lures to drop malware on engineers' workstations. Attribution here is medium confidence: the behaviours fit, but any single hire could be a copycat or a fraudster with different motives.
Capability is one thing. Intent is another. Most of these workers appear to be doing the coding job they were hired for. The concern is the money trail, and the access a malicious insider could later abuse.
What did the researchers actually catch?
The onboarding paperwork. That's the part hiring teams can use tomorrow morning.
The first hire said he lived in Pasadena, Texas, then sent a California driver's license. His bank account was in New York. Three states, one person, no clean explanation.
| Claim | Document sent | Mismatch |
|---|---|---|
| Home in Pasadena, Texas | California driver's license | State does not match |
| California driver's license | New York bank account | Bank state does not match ID |
| Applied as US-based developer | Payment routing inconsistent with address | Three-way conflict |
The researchers logged similar patterns across the other two hires: reused stock photos on resumes, video calls with laggy or filtered backgrounds, requests to ship the laptop to an address that didn't match the ID on file. None of these signals are proof on their own. Stacked together, they're a pattern HR teams can be trained to spot.
Should ordinary job seekers or customers worry?
Not directly. This is a hiring-fraud and sanctions story, not a data breach. No customer data was taken because no real customers existed.
The practical advice sits with employers. If you hire remote engineers, the cheapest control is a careful look at whether the address, the ID and the bank account tell the same story. When they don't, ask why before you ship the laptop.



