Fake Startup Used to Track Alleged Lazarus APT Remote Worker Activity

The420.in Staff
2 Min Read

Cybersecurity researchers created a fake startup and “hired” alleged remote workers linked to the Lazarus APT ecosystem as part of an undercover investigation aimed at observing their activities and uncovering the tools used during the operation.

The investigation captured several weeks of activity associated with the Famous Chollima IT scheme inside the controlled startup environment. A cybersecurity sandbox was used to observe the workers and document their activities during the operation.

FCRF Launches Certified AI-Powered SOC Analyst Program to Train the Next Generation of Cyber Defence Professionals

Fake Startup Used as a Live Trap

The operation was designed as an undercover investigation in which alleged Lazarus APT remote workers were brought into a deliberately created startup environment.

The project was described as a “live trap” for the Famous Chollima IT scheme, allowing researchers to observe activity over several weeks rather than examining a single incident.

The investigation also uncovered a toolkit associated with the alleged remote workers, although the material available does not provide further technical details about the individual tools or explain how each was used.

Material accompanying the investigation featured four individuals using the names “Angelo Espree”, “Lucas Theo”, “Angelo Cruz” and “Jack Anderson”.

The investigation focused on observing activity inside the fake startup and capturing information about the tools and methods associated with the alleged Famous Chollima operation.

Investigation Highlights Remote Worker Security Risk

The operation draws attention to the security risks organisations may face when suspected malicious actors seek remote employment as a way of gaining access to company environments.

By placing the alleged workers inside a controlled startup, researchers were able to capture weeks of activity and examine how the suspected operation functioned after the hiring process.

The information available does not provide additional details about organisations previously targeted, the precise technical methods used by the alleged workers or the specific capabilities of the toolkit uncovered during the investigation.

Stay Connected