CoinDesk
2025-07-08 18:55:12

U.S. Sanctions North Korean IT Workers Over 'Cyber Espionage,' Crypto Thefts

The U.S. Treasury Department's sanctions watchdog added North Korean national Song Kum Hyok to its "Specially Designated Nationals" list, alleging he is "a malicious cyber actor" tied to a North Korean hacking group. The Office of Foreign Assets Control moved to block Song from the global financial system on Tuesday, arguing he worked to place other North Korean officials in various companies as IT workers. These IT workers would then send funds back to North Korea and, in some cases, find ways of exploiting the companies they worked for to generate additional revenue. The crypto industry has been hard-hit by these types of schemes, with numerous major thefts taking place as a result of efforts by North Korean hackers. "The DPRK generates significant revenue through the deployment of IT workers who fraudulently gain employment with companies around the world, including in the technology and virtual currency industries," Tuesday's release said. Late last month, crypto investigator and analyst ZachXBT said "multiple projects ... were exploited," likely due to hiring North Korean IT workers as developers. Though Tuesday's Treasury Department release mentioned past hacks of crypto projects, it did not name any specific ones or include any crypto wallets in its sanctions list. It did note that the department had previously sanctioned the Lazarus Group, which investigators have tied to various crypto hacks across the past several years, including the $625 million theft from Axie Infinity and this year's massive $1.5 billion hack of Bybit. "DPRK IT workers often take on projects that involve virtual currency, and they use virtual currency exchanges and trading platforms to manage funds they receive for contract work as well as to launder and remit these funds to the DPRK," the U.S. Treasury Department said Tuesday. 'Illicit Revenue Generation' Ari Redbord, the global head of policy and government affairs at TRM Labs, said the embedded IT workers "have served as on-ramps to both illicit revenue generation and eventual intrusion activity, particularly in the crypto space." "One notable aspect of today’s designation is the explicit reference to North Korean IT workers operating out of China and Russia," he said, adding that this shows a "growing alignment" between the DPRK and certain jurisdictions. "This action also fits into a broader pattern. In just the last month, Treasury has taken multiple steps targeting North Korea’s use of IT workers to funnel illicit proceeds back to Pyongyang often laundered through crypto exchanges and anonymized platforms," he said. "Song represents the operational layer behind those schemes: not the hacker, but the enabler. And that makes him just as important to disrupt. Building out networks has been a huge focus for Treasury over the last few months and this is another example of going after facilitators," Redbord added Read more: How North Korea Infiltrated the Crypto Industry

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.