It isn’t often that a reporter gets asked to pose as a venture capitalist to fool suspected North Korean IT workers.
But in June, I found myself joining a Zoom call as “Aelin Ashriver,” an investor from the fictitious Definitive Communications, to meet the development team of crypto startup Ballena Azul.
The IT workers on the call believed they were pitching for VC backing for their startup. In reality they had spent weeks working inside a fake crypto company set up purely to study their methods and infrastructure by Mauro Eldritch, founder of cybersecurity firm BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScane.
Cointelegraph tagged along for one stage of the investigation.
During the call, I played up the ruse by suggesting I might even be able to land Ballena Azul some coverage in Cointelegraph.
So at least someone was telling the truth.

Suspected DPRK IT workers pitch for venture capital backing from the fictitious Definitive Communications, played by Cointelegraph. Source: ANY.RUN
Building a company for suspected North Korean IT workers
Eldritch and García built the fictitious Ballena Azul with infrastructure provided by cybersecurity platform ANY.RUN. An existing UK registration for an unrelated company of the same name, which was dissolved in 2022, added legitimacy to the project.
Eldritch assumed the identity of co-founder “Leonardo Nelson,” while García took on the alias “Andy Jones” and posed as the company’s team lead.
Related: North Korean cyber spies are no longer just remote threats
One of the most valuable pieces of intel that the five-week ruse exposed were the external servers the workers used as intermediary points before connecting to Ballena Azul’s controlled virtual desktops.
Exposed servers were particularly valuable because such infrastructure is often recycled across operations and can remain active for long periods.
García tells Magazine the servers were associated with malware families linked to North Korean campaigns that steal credentials, crypto wallet data and other sensitive information.
“Some of the servers we found were tied back to distributing InvisibleFerret and BeaverTail/OtterCookie in prior years and were active to this day,” he says.
But some others were totally new and had zero intelligence about them, looking clean and keeping outside of mainstream block lists or threat feeds.”
He adds that the infrastructure could serve multiple purposes, with servers previously used for malware distribution also acting as command-and-control infrastructure, and as proxies for operators carrying out their day-to-day work.
The suspected workers do not need to deploy malware to pose a threat, according to the researchers. Once hired, they can gain legitimate access to a company’s internal systems, source code and other sensitive information. The longer they remain undetected, the longer they can continue drawing salaries that researchers say ultimately help fund the North Korean regime.
The operation also showed the group relied on artificial intelligence tools to help compensate for gaps in their technical knowledge. They used ChatGPT for writing and coding, including to answer basic questions and complete assignments they struggled with themselves. They preferred Google Gemini for image alteration and document forgery.

A suspected DPRK IT worker and ChatGPT team up in an attempt to obtain testnet crypto during the Ballena Azul operation. Source: ANY.RUN
Other tools employed included remote desktop software, crypto wallets and a service for sharing two-factor authentication codes.
North Korean IT workers have become a growing cybersecurity threat to the cryptocurrency industry. Consensys said in July that it had engaged a North Korea-linked developer through a third-party service provider before identifying the threat and cutting off access.
In another case, US prosecutors charged four North Korean nationals in 2025 with using false identities to obtain remote IT jobs and allegedly stealing more than $900,000 in cryptocurrency from two companies, including a US blockchain research and development firm.
The US Treasury said in March that North Korean IT worker schemes generated nearly $800 million in 2024 to help fund the Pyongyang regime’s weapons-of-mass-destruction programs.
Inside fake crypto company Ballena Azul
The ruse began when García connected with a recruiter via GitHub, who had been linked to Famous Chollima, a threat group associated with North Korean IT worker operations.
García said that Ballena Azul needed to hire software developers and the recruiter offered up “Jack Anderson,” “Angelo Espree” and “Lucas Theo.” At least two of them presented US identification.
The trio were given various programming assignments inside controlled virtual desktop environments, which allowed García and Eldritch to observe how they worked.

Angelo Espree was one of the developers onboarded through a…
cointelegraph.com
