Cybersecurity researchers created a fake startup and “hired” alleged remote workers linked to the Lazarus APT ecosystem as part of an undercover investigation aimed at observing their activities and uncovering the tools used during the operation.
The investigation captured several weeks of activity associated with the Famous Chollima IT scheme inside the controlled startup environment. A cybersecurity sandbox was used to observe the workers and document their activities during the operation.
Fake Startup Used as a Live Trap
The operation was designed as an undercover investigation in which alleged Lazarus APT remote workers were brought into a deliberately created startup environment.
The project was described as a “live trap” for the Famous Chollima IT scheme, allowing researchers to observe activity over several weeks rather than examining a single incident.
The investigation also uncovered a toolkit associated with the alleged remote workers, although the material available does not provide further technical details about the individual tools or explain how each was used.
Four Remote Worker Identities Featured
Material accompanying the investigation featured four individuals using the names “Angelo Espree”, “Lucas Theo”, “Angelo Cruz” and “Jack Anderson”.
The investigation focused on observing activity inside the fake startup and capturing information about the tools and methods associated with the alleged Famous Chollima operation.
Investigation Highlights Remote Worker Security Risk
The operation draws attention to the security risks organisations may face when suspected malicious actors seek remote employment as a way of gaining access to company environments.
By placing the alleged workers inside a controlled startup, researchers were able to capture weeks of activity and examine how the suspected operation functioned after the hiring process.
The information available does not provide additional details about organisations previously targeted, the precise technical methods used by the alleged workers or the specific capabilities of the toolkit uncovered during the investigation.
