Articles
Inside ANY.RUN’s Live Infiltration of a North Korean IT-Worker Ring
Endorsed
David Head3 min readDEC 4, 2025

Inside ANY.RUN’s Live Infiltration of a North Korean IT-Worker Ring


Visit Social Post
View on LinkedInRead the social post and join the conversation.

One of North Korea's most persistent IT-worker operations was observed from the inside.

Heiner García of NorthScan, Mauro Eldritch of BCA LTD, and ANY.RUN built a controlled environment, engaged a suspected Famous Chollima recruiter, and let the operators believe they had gained access to a real U.S.-based laptop.

The result is an unusually concrete view of how a modern candidate-fraud operation recruits frontmen, establishes a laptop farm, and applies to jobs at scale.

Recruiting a frontman

The recruiter offered two arrangements. A participant could lend out an identity and laptop while the operators handled interviews, or take a larger cut by also appearing in interviews and meetings.

The requested package was comprehensive: access to email and LinkedIn, identity and background-check information, financial accounts, and a computer that could remain available through remote-access software.

This matters because the real person can defeat several controls at once. They can pass identity verification, receive company hardware, appear on camera, and provide a clean location for the device while a different person performs the work.

Turning a sandbox into a laptop farm

The researchers did not provide a real personal computer. ANY.RUN supplied extended virtual environments designed to look like established developer machines.

Once the operators connected, the researchers could observe their screen, files, network activity, and tool choices in real time. They also retained control of the environment and deliberately interrupted it before the operators could harm a real third party.

The operator inspected the supposed hardware, installed or used remote-access and browser tools, logged into shared accounts, and prepared the machine to support the job-search workflow.

Applying at scale with ordinary tools

The investigation also showed that the application workflow was not dependent on a single exotic piece of malware.

The operators used familiar tools: remote desktop, browsers, email, LinkedIn, and AI-assisted job-search products. The same software that helps a legitimate candidate tailor a resume or practice an interview can help a fraud ring apply across many employers.

That makes the operation harder to catch with a simple software blacklist. The important question is whether the identity, application, interviewer, device, and eventual worker remain consistent.

What recruiters should learn

  • Social engineering is central. Fraud rings recruit ordinary people to supply clean identities and physical infrastructure.
  • A U.S. device or IP address does not prove the operator is in the United States.
  • Identity verification can validate the frontman without identifying the person doing the work.
  • High-volume applications may be generated with mainstream automation and AI tools.
  • Hiring evidence should remain available after the start date so security teams can investigate continuity.

The researchers' original report includes the full chronology and controlled recordings. It is worth reading because it replaces abstract warnings with an observable workflow—and shows exactly where layered hiring controls can interrupt it.