HomeMalware & ThreatsNorth Korean IT Workers Behind Scams Supporting Ukrainian Invasion

North Korean IT Workers Behind Scams Supporting Ukrainian Invasion

Published on

spot_img

Cryptocurrency Fraud,
Cybercrime,
Fraud Management & Cybercrime

Leaked Payment Server Data Lets Researchers Trace Money Flows

North Korean IT Workers Behind Scams Supporting Ukrainian Invasion
The North Korean flag hanging in front of the Vladivostok, Russia, railway station before an April 2019 visit from North Korean leader Kim Jong Un. (Image: Shutterstock)

Recent research based on leaked payment server data has shed light on the alarming financial pathways through which salaries paid to North Korean IT workers are allegedly funneled into ammunition used against Ukraine. This has become a focal point of concern for international security analysts.

For years, North Korea has reportedly engaged in illicit activities to smuggle remote and contract IT workers onto the payrolls of Western companies. This strategy aims to boost the flow of hard currency into a regime described as impoverished and totalitarian. The ramifications of such actions are profound, particularly concerning infrastructure contributions to military efforts.

Earlier reports published in April by researcher ZachXBT provided crucial insights into the financial transactions related to North Korean IT workers. His findings unveiled a myriad of intermediaries adept at funneling fraudulent payments back to Pyongyang. In a subsequent report released by the insider security firm DTEX, researchers were able to corroborate many of these findings, having examined over 390 accounts of IT workers, along with associated chat logs and payment routing data.

One cryptocurrency wallet, identified by the administrator account PC-1234, reportedly processed an astounding $1.97 million in payments from North Korean IT workers between December 2025 and February 2026. This particular wallet is linked to the Ryongbong General Corporation, a North Korean defense conglomerate that is currently under U.S. sanctions.

It is critical to note that the revenue generated from the salaries of these IT workers is not merely funding technological advancements but is also significantly contributing to developing weapons of mass destruction. Lead investigator Michael “Barni” Barnhart emphasized that the financing for North Korea’s weapons programs is intricately linked to revenue-generating operations, which include not only the global networks of IT workers but also ongoing cryptocurrency theft operations.

Additionally, the information presented by DTEX reveals that the flow of funds from these IT worker salaries supports a broader framework that underpins various sanctioned entities, meeting domestic state needs, and even facilitating warfare efforts. North Korea’s involvement with Russia, particularly its deployment of 14,000 to 15,000 troops to the front lines supporting Moscow’s invasion of Ukraine, underscores the dire implications of these financial maneuvers.

In its report, DTEX articulated a clear message for skeptics asking, “So what?” or “Is it really that bad?”—pointing them to follow the money to understand the severity of the situation. The leaked financial data shows that most of the funds are moving to finance management Unit 1020, a previously unreported financial management unit linked to Command 710.

Barnhart’s research also highlights a concerning trend: an increasing crossover between North Korean IT workers and hackers. He noted that this overlap is now significantly more pervasive than previously understood, indicating evolving strategies employed by the regime to exploit various avenues for financial gain.

In conclusion, the combination of leaked server data and thorough investigative work brings to the forefront the intricate mechanisms through which North Korean IT workers contribute to military facades and support ongoing conflicts. This evolving landscape calls for heightened scrutiny and coordinated action from global communities concerned about the implications of financial operations orchestrated by a rogue regime.

Source link

Latest articles

German Law Enforcement Claims to Have Dismantled Mega Phishing-as-a-Service Group Kratos

In a significant move against cybercrime, cybersecurity experts have recently commented on a particularly...

Google Launches CodeMender as Managed AI Security Agent

Google's Gemini Enterprise Agent Platform has recently welcomed an innovative addition aimed at reinforcing...

OpenClaw Security Best Practices for CISOs

OpenClaw: Revolutionizing Productivity and Posing New Security Challenges OpenClaw has swiftly emerged as one of...

More like this

German Law Enforcement Claims to Have Dismantled Mega Phishing-as-a-Service Group Kratos

In a significant move against cybercrime, cybersecurity experts have recently commented on a particularly...

Google Launches CodeMender as Managed AI Security Agent

Google's Gemini Enterprise Agent Platform has recently welcomed an innovative addition aimed at reinforcing...

OpenClaw Security Best Practices for CISOs

OpenClaw: Revolutionizing Productivity and Posing New Security Challenges OpenClaw has swiftly emerged as one of...