When founders think about cybersecurity, they tend to think about software. They worry about vulnerable code, compromised credentials, ransomware, malicious links and unpatched infrastructure. Those risks are real, but they can create a dangerously narrow view of how an attacker gets inside a company. Sometimes the attacker does not need to find a vulnerability because the company gives them a laptop, an email address, source code access and a salary.
That is the uncomfortable lesson from a remarkable two-part investigation by threat intelligence researchers working with Any.Run. The researchers did not simply reverse-engineer malware after an incident. They entered the recruitment network used by suspected North Korean IT workers, created controlled work environments and later built a convincing fake DeFi company to observe how the operation worked from the inside.
For startup founders, the story is worth studying because it exposes a blind spot at the intersection of hiring, remote work and security. It shows how an organization can follow its normal processes and still invite a threat actor through the front door.
The employee who is not who they claim to be
In Part 1 of the investigation, researchers from BCA LTD and NorthScan, working with ANY.RUN, documented an alleged North Korean operation in which remote IT workers sought roles at companies in the financial and crypto sectors. The researchers attributed the activity to Famous Chollima, a division associated with the Lazarus Group.

The model is effective because it uses the language and infrastructure of legitimate remote work. Operators can use stolen or rented identities, facilitators, VPNs, remote desktop software, AI tools and real-time translation. Local intermediaries may receive company laptops or provide bank accounts, while the person performing the work is somewhere else.
The initial objective may be revenue generation, with salaries ultimately helping fund the North Korean regime. The risk to the employer can go much further. An operative with legitimate access may be able to steal intellectual property, gather intelligence, compromise systems or extort the company after being discovered or dismissed. The FBI has warned that North Korean IT workers have exfiltrated proprietary data and code, and it has advised companies to treat the issue as a continuing business threat.
This is not a theoretical edge case. In June 2025, the US Department of Justice announced enforcement actions across 16 states involving 29 financial accounts, 21 fraudulent websites and approximately 200 computers. A separate case involved a facilitator whose operation helped workers obtain positions at more than 300 US companies and generated more than $17 million in illicit revenue, according to the Justice Department.
What the honeypot company revealed
In Part 2, the researchers escalated the experiment by creating Ballena Azul LTD, a fictional DeFi startup with a website, branding, documentation, an online presence and a plausible product. Suspected North Korean IT workers were recruited into the company and given what appeared to be ordinary development machines.

Those machines were actually extended ANY.RUN sandbox environments. The researchers could monitor screen activity, files, network requests, remote connections and operational mistakes in real time. They observed the use of VPN infrastructure, AI assistants, remote access tools, translation software, cryptocurrency wallets and servers used as proxies. When activity became risky, they could interrupt the connection, simulate a crash or dispose of the virtual machine while keeping the broader operation contained.
The value of the operation was not that it uncovered a single ingenious hacking tool. It documented how ordinary tools, fabricated identities and weakly connected company processes can combine into a highly effective infiltration system. Recruitment establishes the identity, IT provisions access, Finance pays the worker and Security sees activity coming from an approved account. Each function may behave reasonably on its own while the company reaches the wrong conclusion as a whole. That is the part founders should pay attention to.
Hiring is part of your security perimeter
Fast-growing startups are particularly exposed because speed is part of their operating model. A promising engineer can move from first conversation to GitHub access in days. References may be informal, interviews may happen across time zones and contractors may be hired through layers of agencies or platforms. A founder may personally approve the candidate but never meet them in person.
None of this means remote hiring is inherently unsafe. It means identity, access and payment cannot be treated as separate administrative steps. They are one continuous security decision.
The traditional security perimeter was the office network. In a remote company, the perimeter includes the interview, the identity document, the shipping address, the device, the login pattern, the payroll destination and the relationship between all of them. A mismatch in any one field may have an innocent explanation. Several mismatches across the same employee should trigger a closer look.
What founders should do differently
Treat hiring as part of the security perimeter. Verify that candidates are who they claim to be, not only that they can perform the work, and build identity checks into recruitment and onboarding.
Connect warning signs across HR, IT, Finance and management. Inconsistent personal details, unusual VPN or remote desktop activity, mismatched payment accounts and changing locations may appear harmless separately but become significant when viewed together.
Confirm who receives and controls company devices, and give new hires only the access required for their role. Review permissions as trust develops, and monitor early login and device patterns for unexplained anomalies.
Finally, prepare for the possibility that a threat is already inside. Preserve evidence, restrict sensitive access and investigate which systems, credentials, code and data may have been exposed before taking further action.
Trust, but design it
Startups run on trust. Founders trust small teams with incomplete information, move quickly and give talented people meaningful responsibility. The answer to this threat is not to abandon that culture or make remote hiring impossible. The answer is to stop treating trust as a feeling.
Trust can be supported by identity checks, limited access, clear ownership and signals that travel across company functions. These controls do not have to become a bureaucratic burden. When designed well, they protect the speed and autonomy that make startups effective.
The ANY.RUN investigation is memorable because the researchers created a fake company to study fake employees. Its deeper lesson is more ordinary and more useful. A company can have strong software security and still be vulnerable if it does not know who is operating its systems.
For founders, cybersecurity now begins before the first login. It begins with the first conversation.
- Your next cyber threat may apply for a job - August 17, 2026
- AI Watermarks and the Trust Layer - August 16, 2026
- Weekly FIRGUN Newsletter – August 14 2026 - August 14, 2026

