Live Footage Exposes Lazarus Group’s Covert IT-Worker Pipeline Targeting U.S. Finance and Crypto Firms in a State-Backed Espionage and Funding Scheme

Live Footage Exposes Lazarus Group’s Covert IT-Worker Pipeline Targeting U.S. Finance and Crypto Firms in a State-Backed Espionage and Funding Scheme
any.run
Revision history

3 recorded changes

Want your article here?

Promote with Leviathan News

TL;DR: Researchers infiltrated a North Korean scheme where Lazarus Group’s Famous Chollima division hires or impersonates remote IT workers to infiltrate Western companies—especially in crypto, finance, healthcare, and engineering. The operatives use stolen identities, heavy social engineering, and remote-access tools (AnyDesk, Google Remote Desktop) rather than advanced malware. Investigators posed as recruits and lured the attackers into controlled ANY.RUN sandbox “laptops,” capturing every action, tool, message, and network request. The team documented the recruits’ attempts to gather full identity details, SSNs, bank access, and 24/7 device control. Despite poor operational security, Lazarus operators rely on persistence and convincing storytelling. The investigation gives a rare real-time inside look at how these DPRK IT-worker infiltration operations function.

Top comment by @Danicjade

More coverage

More on Lazarus

Comments