How Cybersecurity Researchers Created a Phony Cryptocurrency Company to Expose North Korean Operatives
Suspected IT operatives from North Korea became employees at a fraudulent cryptocurrency company — unaware that investigators were monitoring and documenting their every action to gather critical intelligence.

Journalists rarely receive invitations to impersonate venture capital investors as part of an elaborate scheme to deceive suspected North Korean IT operatives.
Yet in June, I participated in a Zoom meeting under the pseudonym "Aelin Ashriver," representing the non-existent investment firm Definitive Communications, while meeting with the technical team behind cryptocurrency venture Ballena Azul.
The IT operatives participating in the video conference were convinced they were seeking venture capital investment for their fledgling company. What they didn't realize was that they had been toiling for multiple weeks within a fraudulent cryptocurrency enterprise established exclusively to analyze their techniques and technological infrastructure by Mauro Eldritch, who founded cybersecurity company BCA LTD, alongside Heiner García, a cyber threat intelligence specialist at Telefónica Tech and creator of NorthScane.
Cointelegraph participated in a specific phase of this investigation.
Throughout the video conference, I enhanced the deception by hinting that I could potentially secure media coverage for Ballena Azul in Cointelegraph.
At least that part contained some honesty.
Building a company for suspected North Korean IT workers
Eldritch and García constructed the fictional Ballena Azul utilizing infrastructure supplied by cybersecurity platform ANY.RUN. A pre-existing UK business registration for an unconnected company sharing the identical name, which had been dissolved in 2022, provided additional credibility to the operation.
Eldritch adopted the persona of co-founder "Leonardo Nelson," whereas García assumed the identity "Andy Jones" and portrayed himself as the organization's team lead.
Among the most critical intelligence discoveries that the five-week deception revealed were the external servers the operatives utilized as intermediary connection points prior to accessing Ballena Azul's monitored virtual desktop systems.
The discovered servers proved exceptionally valuable due to the fact that such infrastructure frequently gets reused throughout multiple operations and can stay operational for extended timeframes.
García informs Magazine that the servers showed associations with malware families connected to North Korean operations that exfiltrate credentials, cryptocurrency wallet information and additional confidential data.
"Some of the servers we found were tied back to distributing InvisibleFerret and BeaverTail/OtterCookie in prior years and were active to this day," he says.
But some others were totally new and had zero intelligence about them, looking clean and keeping outside of mainstream block lists or threat feeds.
He notes that the infrastructure could fulfill various functions, with servers that had previously been employed for malware dissemination also functioning as command-and-control infrastructure, along with serving as proxies for operators conducting their routine activities.
The suspected operatives don't require malware deployment to represent a danger, based on what the researchers found. After being employed, they can obtain authorized access to an organization's internal networks, proprietary code and additional confidential materials. The more time they stay undetected, the longer they can keep receiving paychecks that researchers indicate ultimately contribute funding to the North Korean government.
The operation additionally demonstrated the group's dependence on artificial intelligence technologies to help bridge deficiencies in their technical expertise. They utilized ChatGPT for composition and programming, including answering fundamental questions and finishing assignments they found challenging to complete independently. They favored Google Gemini for modifying images and creating counterfeit documents.
Additional tools utilized included remote desktop applications, cryptocurrency wallets and a platform for distributing two-factor authentication codes.
North Korean IT operatives have emerged as an escalating cybersecurity danger to the cryptocurrency sector. Consensys announced in July that it had hired a North Korea-associated developer via a third-party service vendor before recognizing the threat and terminating access.
In another case, US prosecutors charged four North Korean nationals in 2025 with using false identities to obtain remote IT jobs and allegedly stealing more than $900,000 in cryptocurrency from two companies, including a US blockchain research and development firm.
The US Treasury said in March that North Korean IT worker schemes generated nearly $800 million in 2024 to help fund the Pyongyang regime's weapons-of-mass-destruction programs.
Inside fake crypto company Ballena Azul
The deception commenced when García established contact with a recruiter through GitHub, who had been associated with Famous Chollima, a threat organization connected to North Korean IT worker schemes.
García explained that Ballena Azul required software developers for hire and the recruiter presented "Jack Anderson," "Angelo Espree" and "Lucas Theo." A minimum of two individuals supplied US identification documents.
The three developers received numerous programming tasks within monitored virtual desktop environments, which enabled García and Eldritch to watch how they operated.
The researchers additionally intentionally created technical difficulties, including targeted network interruptions and vanishing mouse pointers, to observe how the suspected operatives responded and which resources they employed when encountering problems.
"Honestly, the biggest surprise was how much of it ran on improvisation," García says. "There was no rigid playbook, no polished corporate process behind them."
Throughout their numerous weeks operating within the controlled systems, the suspected North Koreans deposited a wealth of information for the researchers, including chat records, AI dialogues, cryptocurrency wallet details, VPN exit nodes and extensive live video documentation. Their network connections additionally revealed the servers that emerged as one of the investigation's most significant discoveries.
To be sure, the heavy AI reliance isn't unique to the workers hoodwinked in Ballena Azul's operation.
Ballena Azul workers generally used AI as a crutch for coding and technical tasks they struggled with. Reuters reported Monday that another North Korean hacking group, Kimsuky, was using AI for a more offensive purpose. The group was reportedly running AI tools locally to help automate cyberattacks, analyze stolen data and produce more convincing phishing campaigns.
Evolving playbook of remote DPRK IT workers
This was not the first time Cointelegraph has played a minor role in exposing suspected North Korean workers.
In February 2025, García and Cointelegraph conducted a job interview for a suspected operative calling himself "Motoki." The developer claimed to be Japanese but ragequit the interview after being asked to introduce himself in his mother tongue.
Still, García kept communicating with him. Motoki eventually offered to send García money to buy a computer that he could access remotely, allowing him to work through a local machine instead of connecting through a VPN to bypass restrictions used by employers and freelance platforms.
García subsequently recorded suspected North Korean operatives enlisting freelancers to supply verified accounts, personal identities and remote access to their computing devices. In one variation of the operation, operatives could perform work through machines physically situated in the US, creating the appearance to employers and freelance platforms that they were US-based contractors.
In May, two US "laptop farmers" — people who hosted a cluster of computers that North Koreans could remotely access — were sentenced to 18 months in prison for helping DPRK IT workers pose as US-based employees in schemes that generated more than $1.2 million and affected nearly 70 companies.
Taking Ballena Azul down
All fake things must come to an end, so the researchers introduced "Benito Camella," Ballena Azul's co-founder, who had supposedly been focused on other business in Milan while the company expanded.
When he returned, Camella confronted the workers over discrepancies in their identities and documents. The confrontation quickly began to clear the chat room. Espree left the video call first, while Anderson stayed longer before realizing the scheme was unraveling.
Yet the researchers maintained the deception continuing even following the meeting's conclusion. In the company's Telegram channel, the "CEO" blamed "Andy Jones" for recruiting "illegal workers" and endangering the organization. "Jones" countered that he had been experiencing pressure to assemble a team rapidly and wasn't receiving adequate compensation to accomplish it. He insisted that he had performed the best he could given the circumstances.
The orchestrated dispute concluded with the fictitious CEO ending both their professional arrangement and personal friendship, sustaining the impression that Ballena Azul had imploded due to a catastrophic recruitment error.
One of the suspected North Koreans later contacted García privately to apologize for what had happened and ask whether he was all right.
According to the researchers, they never heard from the rest of the group again.
To this day, they say, the suspected workers do not know they wasted weeks working inside an environment built to extract intelligence from them.
Editor's note: Cointelegraph could not independently confirm the nationality or affiliation of the suspected DPRK IT workers, and no government agency has publicly identified them.