Cybersecurity

🎭 Ghost Workers Unmasked: Lazarus Group’s Fake IT Employee Scheme Caught Live On Camera

December 14, 2025•3 min read

A covert hiring scheme run by North Korea’s infamous Lazarus Group just got exposed in one of the most surreal cyber-ops ever caught on camera.
And the reveal is equal parts shocking, sloppy, and dangerously effective.

What researchers uncovered isn’t malware, ransomware, or zero-days.
It’s a human supply chain attack — a full-scale infiltration operation designed to sneak North Korean operatives into Western companies by posing as remote IT workers.

And for the first time ever, investigators recorded the entire operation from inside the attackers’ own workflow.


🎯 The Playbook: Hire a Real Person. Use Their Identity. Take Over Their Job.

The Lazarus sub-group known as Famous Chollima has been running a massive identity-fraud pipeline hidden in plain sight.

Here’s how it works:

1️⃣ Recruiters using names like “Aaron” and “Blaze” message developers on GitHub and job boards.

2️⃣ They promise “easy side income” for letting someone work under the applicant’s identity.

3️⃣ They ask for:

  • Social Security numbers

  • Bank account info

  • Full device access
    4️
    ⃣ The victim earns 10–35% of a salary while the real work is done by a North Korean “ghost developer” controlling their machine remotely.

This isn’t just fraud — it’s nation-state outsourcing with stolen identities.


🕵️‍♂️ The Sting Operation That Turned the Tables

Threat researchers from BCA LTD, NorthScan, and ANY.RUN decided to infiltrate the infiltrators.

They built a fake developer persona and let a Lazarus recruiter reel them in.
But instead of handing over a real laptop, the team deployed a sandbox rig disguised as a legitimate workstation.

From there, the camera rolled — capturing every step of the operation.

The footage exposed:

  • AnyDesk and Google Remote Desktop for remote control

  • Automated Chrome extensions used to mass-apply for jobs

  • Final Round AI generating answers during interviews

  • OTP.ee producing fake one-time passwords

  • Astrill VPN servers masking North Korean traffic

This wasn’t advanced hacking.
This was weaponized social engineering, duct tape, and bad operational security.


💀 North Korean Ops, Meet CAPTCHA

For all their notoriety, the operatives showed surprising incompetence:

  • Constantly trapped in CAPTCHA loops

  • Repeatedly asking the researchers for help troubleshooting

  • Googling their own IP reputation

  • Running Windows diagnostics like confused interns

Weeks into the sting, after intentionally crashing the VM and simulating network outages, the attackers became suspicious.

One confronted the “employee” over Telegram.
Moments later, he vanished.


💸 Why This Matters: Millions in Fraud, Espionage & Sanctions Evasion

Lazarus Group’s fake worker program isn’t just about income.
It’s allegedly funneling millions into North Korea’s weapons programs.

Targeted industries include:

  • Finance

  • Cryptocurrency

  • Healthcare

  • Civil engineering

  • High-security infrastructure

A compromised “remote employee” inside these environments is the perfect foothold for:

  • Long-term espionage

  • Credential theft

  • Lateral movement

  • Supply chain compromise

This is not hypothetical.
This is happening right now — at scale.


🛡 What Employers Must Watch For

Red flags include:

✔ Candidates reluctant to turn on their camera
✔ Strange typing or behavior during interviews
✔ Requests to use their own device (or avoid corporate monitoring)
✔ VPN connections from unexpected regions
✔ Interview answers that feel AI-generated
✔ Recruiters contacting employees with “side work opportunities”

Background checks and identity verification are no longer optional — they’re mission critical.


⚠ Advice for Job Seekers

If someone promises:

✨ “Easy money”
✨ “Side income”
✨ “Just let someone remote into your laptop”

Run.
Do not pass go.
Do not hand over your identity.

Never allow unknown recruiters to:

  • Access your device

  • Perform interviews using your hardware

  • Request personal documents outside official HR channels

When in doubt, verify directly with the actual employer.


Elliptic Systems’ Take

This investigation marks the first captured, end-to-end look at Lazarus Group’s ghost-developer operation from the inside.
And it confirms what we’ve warned organizations about for years:

The next supply chain attack won’t come from code — it will come from people.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog