Swati KhandelwalAug 11, 2026Insider Threat / Cyber Espionage
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.
The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account.
The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit.
The second supplied a Texas license, a valid Social Security number, and a bank account in Kansas City. The third sent a New York license belonging to someone else, a genuine iPhone 15 photograph with the GPS coordinates stripped.
A successful placement gives the operative a real employee account and real access to source code and internal systems. The July 31 joint alert says North Korean IT workers seek contracts with the intent of remitting their salaries to parent North Korean agencies. It also names documents "forged or altered using image editing software" among the signals employers should watch for.
In April, the Justice Department sentenced two US facilitators over a separate scheme that placed workers at more than 100 US companies on at least 80 stolen identities and earned North Korea more than $5 million. Google's Gemini app can check an image for a SynthID watermark, but it only detects content created or edited by Google's AI models. A negative result does not rule out AI editing by other tools.
The operation was a sequel. Threat intelligence firm BCA LTD, the NorthScan research initiative, and sandbox provider ANY.RUN spent late 2025 posing as a facilitator willing to rent out his identity. The Hacker News covered that operation in December.
This time they became the employer, building a fake DeFi protocol called Ballena Azul. A recruiter trawling GitHub for facilitators delivered the first developer. That developer vouched for a friend, who vouched for a third.
Nobody exploited anything.
Each operative came in through the hiring process, cleared an interview, signed a contract, and was given access to a work VM. The researchers write that these schemes are "not only a hiring risk" because once a placement holds, the worker's access is also authorized and expected.

