• bitcoinBitcoin (BTC) $ 106,315.00
  • ethereumEthereum (ETH) $ 2,534.35
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.28
  • bnbBNB (BNB) $ 655.63
  • solanaSolana (SOL) $ 154.22
  • usd-coinUSDC (USDC) $ 0.999781
  • dogecoinDogecoin (DOGE) $ 0.185959
  • tronTRON (TRX) $ 0.282346
  • cardanoCardano (ADA) $ 0.677444
  • staked-etherLido Staked Ether (STETH) $ 2,534.23
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,081.00
  • hyperliquidHyperliquid (HYPE) $ 35.92
  • suiSui (SUI) $ 3.28
  • wrapped-stethWrapped stETH (WSTETH) $ 3,053.88
  • chainlinkChainlink (LINK) $ 13.93
  • avalanche-2Avalanche (AVAX) $ 21.44
  • leo-tokenLEO Token (LEO) $ 9.18
  • stellarStellar (XLM) $ 0.269211
  • bitcoin-cashBitcoin Cash (BCH) $ 414.80
  • the-open-networkToncoin (TON) $ 3.18
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • hedera-hashgraphHedera (HBAR) $ 0.170643
  • usdsUSDS (USDS) $ 0.999521
  • wethWETH (WETH) $ 2,533.97
  • litecoinLitecoin (LTC) $ 87.97
  • wrapped-eethWrapped eETH (WEETH) $ 2,709.90
  • polkadotPolkadot (DOT) $ 4.06
  • moneroMonero (XMR) $ 329.38
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 4.66
  • pepePepe (PEPE) $ 0.000012
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 106,325.00
  • pi-networkPi Network (PI) $ 0.632253
  • whitebitWhiteBIT Coin (WBT) $ 31.35
  • aaveAave (AAVE) $ 256.60
  • uniswapUniswap (UNI) $ 6.42
  • daiDai (DAI) $ 0.999717
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • bittensorBittensor (TAO) $ 387.67
  • okbOKB (OKB) $ 51.59
  • internet-computerInternet Computer (ICP) $ 5.65
  • aptosAptos (APT) $ 4.74
  • nearNEAR Protocol (NEAR) $ 2.45
  • crypto-com-chainCronos (CRO) $ 0.097933
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 186.25
  • ondo-financeOndo (ONDO) $ 0.844010
  • ethereum-classicEthereum Classic (ETC) $ 17.12
  • susdssUSDS (SUSDS) $ 1.05
  • tokenize-xchangeTokenize Xchange (TKX) $ 31.04
  • kaspaKaspa (KAS) $ 0.087425
  • gatechain-tokenGate (GT) $ 18.32
  • mantleMantle (MNT) $ 0.650502
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • vechainVeChain (VET) $ 0.024451
  • official-trumpOfficial Trump (TRUMP) $ 10.50
  • render-tokenRender (RENDER) $ 3.91
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.762981
  • ethenaEthena (ENA) $ 0.320930
  • cosmosCosmos Hub (ATOM) $ 4.30
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.212225
  • fasttokenFasttoken (FTN) $ 4.41
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 105,660.00
  • worldcoin-wldWorldcoin (WLD) $ 1.13
  • quant-networkQuant (QNT) $ 118.93
  • filecoinFilecoin (FIL) $ 2.51
  • arbitrumArbitrum (ARB) $ 0.348055
  • algorandAlgorand (ALGO) $ 0.192568
  • skySky (SKY) $ 0.073760
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998371
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,533.46
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.45
  • usdtbUSDtb (USDTB) $ 0.999918
  • usdt0USDT0 (USDT0) $ 1.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.470312
  • kucoin-sharesKuCoin (KCS) $ 11.09
  • celestiaCelestia (TIA) $ 2.04
  • binance-staked-solBinance Staked SOL (BNSOL) $ 162.63
  • injective-protocolInjective (INJ) $ 13.40
  • bonkBonk (BONK) $ 0.000016
  • flare-networksFlare (FLR) $ 0.018476
  • nexoNEXO (NEXO) $ 1.24
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.87
  • sonic-3Sonic (S) $ 0.382524
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,883.50
  • spx6900SPX6900 (SPX) $ 1.28
  • story-2Story (IP) $ 4.07
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,652.33
  • optimismOptimism (OP) $ 0.620975
  • fartcoinFartcoin (FARTCOIN) $ 1.06
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • sei-networkSei (SEI) $ 0.191537
  • blockstackStacks (STX) $ 0.661133
  • paypal-usdPayPal USD (PYUSD) $ 0.999843
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999586
  • xdce-crowd-saleXDC Network (XDC) $ 0.060966
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 105,866.00
  • immutable-xImmutable (IMX) $ 0.525633
  • vaultaVaulta (A) $ 0.590213
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,703.37
  • dogwifcoindogwifhat (WIF) $ 0.919108
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,654.84
  • wbnbWrapped BNB (WBNB) $ 655.82
  • curve-dao-tokenCurve DAO (CRV) $ 0.654401
  • the-graphThe Graph (GRT) $ 0.093022
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 106,112.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,662.39
  • flokiFLOKI (FLOKI) $ 0.000085
  • clbtcclBTC (CLBTC) $ 106,193.00
  • tether-goldTether Gold (XAUT) $ 3,321.69
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 171.83
  • pax-goldPAX Gold (PAXG) $ 3,339.06
  • zcashZcash (ZEC) $ 49.24
  • theta-tokenTheta Network (THETA) $ 0.769206
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.32
  • galaGALA (GALA) $ 0.016602
  • msolMarinade Staked SOL (MSOL) $ 200.32
  • lido-daoLido DAO (LDO) $ 0.820605
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.10
  • ethereum-name-serviceEthereum Name Service (ENS) $ 21.02
  • iotaIOTA (IOTA) $ 0.182561
  • ousgOUSG (OUSG) $ 111.34
  • jasmycoinJasmyCoin (JASMY) $ 0.014275
  • pyth-networkPyth Network (PYTH) $ 0.119500
  • the-sandboxThe Sandbox (SAND) $ 0.280944
  • bittorrentBitTorrent (BTT) $ 0.00000069
  • walrus-2Walrus (WAL) $ 0.499353
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.999768
  • raydiumRaydium (RAY) $ 2.31
  • pendlePendle (PENDLE) $ 4.10
  • bitcoin-svBitcoin SV (BSV) $ 33.22
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010171
  • keetaKeeta (KTA) $ 1.59
  • jito-governance-tokenJito (JTO) $ 1.88
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 105,095.00
  • usual-usdUsual USD (USD0) $ 0.997446
  • kaiaKaia (KAIA) $ 0.107295
  • coredaoorgCore (CORE) $ 0.623940
  • polyhedra-networkPolyhedra Network (ZKJ) $ 2.01
  • tezosTezos (XTZ) $ 0.578871
  • ketKet (KET) $ 0.588916
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • flowFlow (FLOW) $ 0.367702
  • thorchainTHORChain (RUNE) $ 1.65
  • dexeDeXe (DEXE) $ 10.06
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,533.12
  • falcon-financeFalcon USD (USDF) $ 0.999532
  • apecoinApeCoin (APE) $ 0.709766
  • super-oethSuper OETH (SUPEROETH) $ 2,532.58
  • grassGrass (GRASS) $ 1.95
  • saros-financeSaros (SAROS) $ 0.212793
  • heliumHelium (HNT) $ 2.97
  • decentralandDecentraland (MANA) $ 0.282071
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,642.14
  • wrapped-hypeWrapped HYPE (WHYPE) $ 35.94
  • based-brettBrett (BRETT) $ 0.052877
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 2,707.32
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 106,221.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,533.83
  • tbtctBTC (TBTC) $ 105,775.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,737.91
  • true-usdTrueUSD (TUSD) $ 0.998857
  • chain-2Onyxcoin (XCN) $ 0.014492
  • kavaKava (KAVA) $ 0.450874
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.185778
  • beldexBeldex (BDX) $ 0.065423
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999697
  • starknetStarknet (STRK) $ 0.133194
  • dog-go-to-the-moon-runeDog (Bitcoin) (DOG) $ 0.004465
  • syrupMaple Finance (SYRUP) $ 0.411066
  • aethirAethir (ATH) $ 0.048600
  • usddUSDD (USDD) $ 1.00
  • elrond-erd-2MultiversX (EGLD) $ 15.29
  • eigenlayerEigenlayer (EIGEN) $ 1.41
  • ecasheCash (XEC) $ 0.000022
  • eosEOS (EOS) $ 0.588676
  • neoNEO (NEO) $ 6.04
  • aerodrome-financeAerodrome Finance (AERO) $ 0.512004
  • dydx-chaindYdX (DYDX) $ 0.539191
  • compound-governance-tokenCompound (COMP) $ 46.46
  • pumpbtcpumpBTC (PUMPBTC) $ 103,053.00
  • arweaveArweave (AR) $ 6.43
  • conflux-tokenConflux (CFX) $ 0.082392
  • apenftAPENFT (NFT) $ 0.00000042
  • hashnote-usycCircle USYC (USYC) $ 1.09
  • kaitoKAITO (KAITO) $ 1.68
  • usdbUSDB (USDB) $ 0.998077
  • mimblewimblecoinMimbleWimbleCoin (MWC) $ 36.86
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,532.43
  • axie-infinityAxie Infinity (AXS) $ 2.45
  • staked-hypeStaked HYPE (STHYPE) $ 35.94
  • morphoMorpho (MORPHO) $ 1.40
  • reserve-rights-tokenReserve Rights (RSR) $ 0.006827
  • aioz-networkAIOZ Network (AIOZ) $ 0.336262
  • ether-fiEther.fi (ETHFI) $ 1.17
  • ripple-usdRipple USD (RLUSD) $ 0.999784
  • telcoinTelcoin (TEL) $ 0.004146
  • stader-ethxStader ETHx (ETHX) $ 2,688.96

DOJ Seeks $7.7 Million Forfeiture in Crypto From North Korean Hackers Masquerading as IT Workers

0 2

DOJ Seeks $7.7 Million Forfeiture in Crypto From North Korean Hackers Masquerading as IT Workers

The U.S. Department of Justice last week filed a civil forfeiture claim for $7.74 million in crypto laundered by North Korean IT workers who fraudulently gained employment with companies in the U.S. and abroad.

The U.S. government seized the funds as part of an operation against a North Korean scheme to evade sanctions, with authorities indicting a North Korean Foreign Trade Bank representative, Sim Hyon Sop, in connection with the scheme in April 2023.

According to the DOJ, North Korean IT workers gained employment at U.S. crypto companies using fake or fraudulently obtained identities, before laundering their income through Sim for the benefit of the regime in Pyongyang.

The forfeiture complaint also details that the IT workers had been deployed in various locations around the world, including in China, Russia and Laos.

By hiding their true identities and locations, the workers were able to secure employment with blockchain firms, who generally paid them in stablecoins—USDC or Tether.

“For years, North Korea has exploited global remote IT contracting and cryptocurrency ecosystems to evade U.S. sanctions and bankroll its weapons programs,” said Sue J. Bai, the head of the DOJ’s National Security Division.

The Department of Justice also reports that the IT workers used several methods to launder their fraudulent income, including setting up exchange accounts with fictitious IDs, making multiple small transfers, converting from one token to another, buying NFTs, and mixing their funds.

Once ostensibly laundered, the funds were then sent to the North Korean government via Sim Hyon Sop and Kim Sang Man, the CEO of a company operating under North Korea’s Ministry of Defense.

The DOJ indicted Sim Hyon Sop on two separate charges in April 2023, including conspiring with North Korean workers to earn income via fraudulent employment and, secondly, conspiring with OTC crypto traders to use the fraudulently generated income to purchase goods for North Korea.

The FBI Chicago Field Office and FBI’s Virtual Assets Unit are investigating the cases related to the forfeiture complaint, which the DoJ filed with the U.S. District Court for the District of Columbia.

“The FBI’s investigation has revealed a massive campaign by North Korean IT workers to defraud U.S. businesses by obtaining employment using the stolen identities of American citizens, all so the North Korean government can evade U.S. sanctions and generate revenue for its authoritarian regime,” said Roman Rozhavsky, the Assistant Director of the FBI’s Counterintelligence Division.

While the precise extent of fraudulent North Korean IT work is not fully established, most experts agree that the problem is becoming more significant.

A growing threat in North Korea

“The threat posed by North Korean IT workers posing as legitimate remote employees is growing significantly – and fast,” explains Chainalysis Head of National Security Intelligence Andrew Fierman, speaking to Decrypt.

As evidence of just how “industrialized and sophisticated” the threat has become, Fierman cites the example of the DoJ’s December indictment of 14 North Korean nationals, who had allegedly also operated under false IDs and earned $88 million through a six-year scheme.

“While it’s difficult to pin an exact percentage of North Korea’s illicit cyber revenue to fraudulent IT work, it’s clear from government assessments and cybersecurity research that this method has evolved into a reliable stream of income for the regime – especially when paired with espionage goals and follow-on exploits,” he says.

Other security specialists concur that the threat of illicit North Korean IT employees is becoming more prevalent, with Michael Barnhart – Principal i3 Insider Investigator at DTEX Systems – telling Decrypt that their tactics are becoming more sophisticated.

“These operatives aren’t just a potential threat, they have actively embedded themselves within organizations already, with critical infrastructure and global supply chains already compromised,” he says.

Barnhart also reports that North Korean threat actors have even begun establishing “front companies posing as trusted third parties”, or embedding themselves into legitimate third parties that may not utilize the same rigorous safeguards as other, larger organizations.

Interestingly, Barnhart estimates that North Korea may be generating hundreds of millions in revenue each year from fraudulent IT work, and that any recorded figures or sums are likely to be underestimated.

“The saying of ‘you don’t know what you don’t know’ comes into play, as each day a new scheme to earn money is discovered,” he explains. “Additionally, much of the revenue is obfuscated to look like elements of cyber criminal gangs or completely legitimate seeming efforts, which muddle the overall attribution.”

And while Thursday’s forfeiture claim indicates that the U.S. Government is managing to get more of a handle on North Korea’s operations, the increasing sophistication of the latter suggests that American and international authorities may continue playing catchup for a while yet.

As Andrew Fierman says, “What’s especially concerning is how seamlessly these workers are able to blend in: leveraging generative AI for fake personas, deepfake tools for interviews, and even support systems to pass technical screenings.”

In April, Google’s Threat Intelligence Group revealed that North Korean actors had expanded beyond the U.S. to infiltrate themselves in cryptocurrency projects in the UK, Germany, Portugal and Serbia.

This included projects developing blockchain marketplaces, AI web apps and Solana smart contracts, with accomplices in the UK and U.S. helping operatives to bypass ID checks and receive payments via TransferWise and Payoneer.

Edited by Stacy Elliott.

Source

Leave A Reply

Your email address will not be published.