Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

U.S. Sanctions North Korean IT Worker Network Supporting WMD Programs

The Hacker News by The Hacker News
January 17, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 17, 2025Ravie LakshmananInsider Threat / Cryptocurrency

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and four entities for their alleged involvement in illicit revenue generation schemes for the Democratic People’s Republic of Korea (DPRK) by dispatching IT workers around the world to obtain employment and draw a steady source of income for the regime in violation of international sanctions.

“These IT workers obfuscate their identities and locations to fraudulently obtain freelance employment contracts from clients around the world for IT projects, such as software and mobile application development,” the Treasury Department said.

“The DPRK government withholds up to 90% of the wages earned by these overseas workers, thereby generating annual revenues of hundreds of millions of dollars for the Kim regime’s weapons programs to include weapons of mass destruction (WMD) and ballistic missile programs.”

Cybersecurity

The action represents the latest salvo in the U.S. government’s ongoing efforts to crack down on the various financially motivated streams that aim to further Pyongyang’s strategic objectives. The individuals and companies that have been sanctioned by OFAC are listed below –

  • Department 53 of The Ministry of the People’s Armed Forces, which is said to generate revenue using front companies related to IT and software development
  • Korea Osong Shipping Co, a Department 53 front company that maintained DPRK IT workers in Laos since at least 2022
  • Chonsurim Trading Corporation, a Department 53 front company that has maintained another group of DPRK IT workers in Laos
  • Liaoning China Trade Industry Co., Ltd, a China-based company that has shipped Department 53 equipment, viz. notebook and desktop computers, graphics cards, HDMI cables, and network equipment, to facilitate IT worker activity abroad
  • Jong In Chol, the president of Chonsurim’s DPRK IT worker delegation in Laos
  • Son Kyong Sik, a China-based chief representative of Korea Osong Shipping Co

Both the front companies are alleged to have used false identities and aliases to communicate with clients and undertake software development work for companies across the world.

The fraudulent IT worker scheme attracted mainstream attention in 2023, although it’s believed that such operations have been ongoing since at least 2018, when the Treasury sanctioned two companies Yanbian Silverstar and Volasys Silver Star for the “exportation of workers from North Korea, including exportation to generate revenue for the Government of North Korea or the Workers’ Party of Korea.”

The activity cluster is tracked by the cybersecurity community under the monikers Famous Chollima, Nickel Tapestry, UNC5267, and Wagemole.

Recent analyses have found that North Korean IT workers have been increasingly infiltrating cryptocurrency and Web3 companies and “compromising their networks, operations, and integrity.” The insider threat operation has also identified people in the U.S. who are willing to support their schemes by running laptop farms in exchange for a monthly fee.

Cybersecurity

Heightened public disclosures about these campaigns have further led to a surge in extortion attempts by stealing intellectual property from the companies they work for and demanding “more cryptocurrency than they ever have before” for not releasing it publicly or giving it away to rivals, Google-owned Mandiant told The Record.

That having said, the IT worker operation is just one of the many methods North Korea employs to illegally generate revenue. DPRK state-sponsored hacking groups have a long history of targeting developers with job-themed lures to deliver various kinds of malware that are capable of facilitating data and cryptocurrency theft.

“The DPRK continues to rely on its thousands of overseas IT workers to generate revenue for the regime, to finance its illegal weapons programs, and to enable its support of Russia’s war in Ukraine,” said Acting Under Secretary of the Treasury for Terrorism and Financial Intelligence Bradley T. Smith.

“The United States remains resolved to disrupt these networks, wherever they operate, that facilitate the regime’s destabilizing activities.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Researchers say AI fails to describe complexities of Holocaust | Computer Weekly

Researchers say AI fails to describe complexities of Holocaust | Computer Weekly

Recommended.

200+ Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers

200+ Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers

June 20, 2025
Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks

Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks

July 29, 2025

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio