
đ Ghost Workers Unmasked: Lazarus Groupâs Fake IT Employee Scheme Caught Live On Camera
A covert hiring scheme run by North Koreaâs infamous Lazarus Group just got exposed in one of the most surreal cyber-ops ever caught on camera.
And the reveal is equal parts shocking, sloppy, and dangerously effective.
What researchers uncovered isnât malware, ransomware, or zero-days.
Itâs a human supply chain attack â a full-scale infiltration operation designed to sneak North Korean operatives into Western companies by posing as remote IT workers.
And for the first time ever, investigators recorded the entire operation from inside the attackersâ own workflow.
đŻ The Playbook: Hire a Real Person. Use Their Identity. Take Over Their Job.
The Lazarus sub-group known as Famous Chollima has been running a massive identity-fraud pipeline hidden in plain sight.
Hereâs how it works:
1ď¸âŁ Recruiters using names like âAaronâ and âBlazeâ message developers on GitHub and job boards.
2ď¸âŁ They promise âeasy side incomeâ for letting someone work under the applicantâs identity.
3ď¸âŁ They ask for:
Social Security numbers
Bank account info
Full device access
4ď¸âŁ The victim earns 10â35% of a salary while the real work is done by a North Korean âghost developerâ controlling their machine remotely.
This isnât just fraud â itâs nation-state outsourcing with stolen identities.
đľď¸ââď¸ The Sting Operation That Turned the Tables
Threat researchers from BCA LTD, NorthScan, and ANY.RUN decided to infiltrate the infiltrators.
They built a fake developer persona and let a Lazarus recruiter reel them in.
But instead of handing over a real laptop, the team deployed a sandbox rig disguised as a legitimate workstation.
From there, the camera rolled â capturing every step of the operation.
The footage exposed:
AnyDesk and Google Remote Desktop for remote control
Automated Chrome extensions used to mass-apply for jobs
Final Round AI generating answers during interviews
OTP.ee producing fake one-time passwords
Astrill VPN servers masking North Korean traffic
This wasnât advanced hacking.
This was weaponized social engineering, duct tape, and bad operational security.
đ North Korean Ops, Meet CAPTCHA
For all their notoriety, the operatives showed surprising incompetence:
Constantly trapped in CAPTCHA loops
Repeatedly asking the researchers for help troubleshooting
Googling their own IP reputation
Running Windows diagnostics like confused interns
Weeks into the sting, after intentionally crashing the VM and simulating network outages, the attackers became suspicious.
One confronted the âemployeeâ over Telegram.
Moments later, he vanished.
đ¸ Why This Matters: Millions in Fraud, Espionage & Sanctions Evasion
Lazarus Groupâs fake worker program isnât just about income.
Itâs allegedly funneling millions into North Koreaâs weapons programs.
Targeted industries include:
Finance
Cryptocurrency
Healthcare
Civil engineering
High-security infrastructure
A compromised âremote employeeâ inside these environments is the perfect foothold for:
Long-term espionage
Credential theft
Lateral movement
Supply chain compromise
This is not hypothetical.
This is happening right now â at scale.
đĄ What Employers Must Watch For
Red flags include:
â Candidates reluctant to turn on their camera
â Strange typing or behavior during interviews
â Requests to use their own device (or avoid corporate monitoring)
â VPN connections from unexpected regions
â Interview answers that feel AI-generated
â Recruiters contacting employees with âside work opportunitiesâ
Background checks and identity verification are no longer optional â theyâre mission critical.
â Advice for Job Seekers
If someone promises:
⨠âEasy moneyâ
⨠âSide incomeâ
⨠âJust let someone remote into your laptopâ
Run.
Do not pass go.
Do not hand over your identity.
Never allow unknown recruiters to:
Access your device
Perform interviews using your hardware
Request personal documents outside official HR channels
When in doubt, verify directly with the actual employer.
Elliptic Systemsâ Take
This investigation marks the first captured, end-to-end look at Lazarus Groupâs ghost-developer operation from the inside.
And it confirms what weâve warned organizations about for years:
The next supply chain attack wonât come from code â it will come from people.
