How We Caught Lazarus's IT Workers Scheme Live on Camera
2025-12-04 • Any Run •
https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/
ANY.RUN, BCA LTD, and NorthScan documented a Famous Chollima operation attributed to Lazarus that sought to place North Korean remote IT workers into American financial and crypto/Web3 companies. The operators relied on social engineering rather than advanced malware, using stolen or rented identities, fake job-seeking setups, GitHub spam, Telegram outreach, and pressure on recruited engineers to attend interviews or provide laptop access. The investigation used controlled sandboxed laptop-farm environments to observe the operators in real time while preventing malicious activity. The observed toolkit included AnyDesk, Google Remote Desktop, AI interview helpers, OTP extensions, and shared infrastructure, giving defenders concrete behaviors for detecting DPRK IT-worker infiltration and identity-rental schemes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | calendly.com | 2024-10-29 | 2026-03-02 |
| IPv4 | 194.33.45.162 | 2025-02-25 | 2026-01-21 |
| URL | https://us.bold.pro/my/jaron-ga… | 2025-12-04 | 2025-12-04 |
| URL | https://jackson-portfolio.verce… | 2025-12-04 | 2025-12-04 |
| DOMAIN | us.bold.pro | 2025-11-07 | 2025-12-04 |
| URL | https://calendly.com/7codewizar… | 2025-06-24 | 2025-12-04 |