Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageidentity-impersonation-fraudinitial-access-methodai-enabled-threat-activity

North Korean Lazarus Group's Remote IT Worker Identity Rental Scheme

Updated 3mo agoFirst seen Dec 2, 20254 sources

Security researchers have uncovered and documented a sophisticated scheme by North Korea's Lazarus Group, specifically its Famous Chollima division, to infiltrate Western companies by recruiting remote IT workers under false pretenses. The operation involves North Korean agents posing as recruiters who target engineers and developers, convincing them to rent out their identities and computers. These compromised individuals act as figureheads, allowing Lazarus operatives to pass interviews, gain employment, and use the victims' devices as proxies to conceal their true location and activities. Researchers, including Mauro Eldritch of BCA LTD and the NorthScan initiative, managed to capture the scheme live by deploying controlled sandbox environments that mimicked real developer laptops, enabling them to observe the attackers' tactics in real time.

The scheme leverages social engineering, AI-driven interview techniques, and deepfake technology to bypass security checks and secure positions at high-profile companies, particularly in finance, crypto, healthcare, and engineering sectors. Victims are offered a share of the salary, typically 20-35%, in exchange for their cooperation, but they bear all legal and reputational risks if the operation is discovered. The investigation also revealed that Lazarus operatives spammed GitHub repositories with recruitment messages to attract more candidates. This exposure provides critical insight into North Korea's ongoing efforts to generate revenue and conduct espionage through remote access to Western corporate networks.

Share:
North Korean Lazarus Group's Remote IT Worker Identity Rental Scheme
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 2, 20257mo ago

Joint research publicly links the scheme to Lazarus/Famous Chollima

BCA LTD, NorthScan, and ANY.RUN publicly reported that the observed fake IT worker operation was tied to North Korea’s Famous Chollima cluster, associated with the Lazarus Group. The report warned that remote hiring workflows can be exploited to gain access to internal systems and sensitive data at Western organizations.

Investigators observe live Famous Chollima remote-worker tradecraft

Inside the honeypot, researchers recorded operators using Astrill VPN, host reconnaissance commands, AI browser extensions, OTP and authentication tooling, and Google Remote Desktop configured through PowerShell for persistent remote access. The activity showed an emphasis on account takeover and remote control rather than traditional malware deployment.

Researchers deploy ANY.RUN laptop-farm honeypot to monitor operators

After the recruiter demanded sensitive identity and access artifacts, the researchers shifted to a controlled laptop-farm honeypot built with long-running ANY.RUN interactive sandbox systems disguised as developer laptops. This allowed them to safely observe the full workflow without exposing real endpoints.

Recruiter solicits identity data and frontman access for fake employment

During the engagement, the recruiter requested extensive personal information and 24/7 remote access to a laptop via tools such as AnyDesk, and offered 20% to 35% of salary for help acting as a frontman in interviews. The scheme relied on identity rental, anti-camera or deepfake interview tactics, and AI-assisted job application support.

Researchers engage DPRK recruiter posing as a U.S. developer

Researchers from BCA LTD and NorthScan contacted a recruiter persona known as “Aaron” or “Blaze” after encountering GitHub spam posts, while impersonating a U.S.-based developer. The recruiter sought to place North Korean IT workers into Western companies using rented, stolen, or borrowed identities.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

27 LINKEDOpen in app
Affected products
3 linked
AnydeskGmailWindows Notepad
Organizations
21 linked
Any.RunNorthScanBCA LTDGoogleLazarus GroupAstrillAuthenticator.ccBleepingComputerFamous ChollimaAnyDesk Software GmbHFinal Round AISimplifyAIApplyOTP.eeAstrill VPNSecurity AffairsThe Hacker NewsGitHubSlack TechnologiesBitsoNorthScan threat intelligence initiative
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

North Korean Lazarus Group's Remote IT Worker Identity Rental Scheme | Mallory