Researchers conducted honeypot operation posing as DeFi startup to monitor and profile Lazarus Group IT workers.
Security & Exploits ·
Researchers created a fake DeFi startup and recruited workers from the Lazarus Group for employment, then monitored their activities within a controlled sandbox environment. During this operation, the team recorded their tooling, workflows, and faces from inside the honeypot setup.
The research was presented as part of a DEFCON talk, offering an unusual window into the operational practices and tools used by Lazarus IT personnel. By simulating a legitimate startup hiring process, the researchers were able to observe the group's standard procedures and infrastructure choices in a contained setting rather than through indirect analysis.
The full presentation details remain accessible in the recorded talk, though the specific findings about Lazarus tooling, operational workflows, and other technical indicators have not been separately summarized in available reports. What operational security measures or attribution techniques Lazarus may employ to detect such honeypots remains unclear.