Close Menu
Computing.net
    Facebook X (Twitter) Instagram
    Computing.netComputing.net
    • News
      1. AI
      2. Crypto
      3. Gaming
      4. Hardware
      5. Security
      6. Software
      7. View All

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      AI Trading Bot Loses $441K in Crypto After Decimal Point Mistake

      February 23, 2026

      Tesla (TSLA) Stock: Goodbye Sedans, Hello Robots in Dramatic Production Shift

      January 29, 2026

      Palantir Technologies (PLTR) Stock: Why Bears May Be Wrong About Valuation Concerns

      January 29, 2026

      SUI Token Rallies 40% Following Major Staking Event and CME Futures Announcement

      May 12, 2026

      Chainlink (LINK) Surges to $10.40 as Network Activity Hits Eight-Month Peak

      May 12, 2026

      Dogecoin Whales Ramp Up Accumulation as DOGE Eyes Critical Breakout Levels

      May 12, 2026

      Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

      May 12, 2026

      Hamster Kombat: Unraveling TON’s Gaming Phenomenon

      August 7, 2024

      W-Coin: Exploring the Latest Telegram Tap-to-Earn Phenomenon

      August 7, 2024

      Hamster Kombat: 300 Million Players & Counting, HMSTR Token Airdrop Soon!

      July 31, 2024

      Hamster Kombat Developers Work with TON Team on Airdrop Solution

      July 30, 2024

      Nothing Expands Product Line with New AI Feature & Phone Update

      July 31, 2024

      Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

      August 6, 2024

      SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

      July 30, 2024

      OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

      July 30, 2024

      Hamster Kombat Players Face Growing Cybersecurity Threats

      July 25, 2024

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      Cookie Crumble: Google Halts Plans to Eliminate Third-Party Cookies in Chrome

      July 23, 2024

      Big Brother is Watching: Apple’s Creepy New Ad Urges iPhone Users to Ditch Chrome

      July 23, 2024

      Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

      May 12, 2026

      Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

      May 12, 2026

      GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

      May 12, 2026

      SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

      May 12, 2026
    • How To

      Batch Files: Tokens and Delimiters (FOR Loops)

      July 31, 2024

      Types of Ethernet Cabling & Electrical Low Voltage Wiring

      July 9, 2024

      What You Should Know About .JSON File Extension

      January 10, 2023

      Bkup File Extension

      November 19, 2022

      HEIC File Extension

      November 19, 2022
    • Office
      1. Excel
      2. Google Sheets
      3. View All

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024

      How to Remove Characters from Right in Excel

      July 30, 2023

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      Bullet Points in Google Sheets

      January 20, 2022

      Sort by Date in Google Sheets

      January 18, 2022

      Google Sheets Timestamp

      January 17, 2022

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024
    • Answers
    • About
    • Contact
    Facebook X (Twitter)
    Computing.net
    News

    Blockchain Sleuth Uncovers $3.5M Crypto Scheme Run by North Korean IT Workers

    Oliver DaleBy Oliver DaleApril 9, 2026
    Twitter LinkedIn Email Telegram
    Twitter LinkedIn Email Telegram

    Contents:

    Toggle
    • Key Findings
    • Payment Coordination Infrastructure
    • Malicious Activity Planning and Educational Resources

    Key Findings

    • ZachXBT uncovered a coordinated network of 140 North Korean IT workers generating approximately $1M monthly in cryptocurrency
    • The operation accumulated more than $3.5M starting from late November 2024 through fraudulent identity schemes targeting remote developer positions
    • A payment coordination website called “luckyguys.site” relied on the easily guessable password “123456”
    • Cryptocurrency earnings were laundered through Chinese banking channels and services including Payoneer
    • Multiple wallet addresses associated with this network traced back to OFAC-sanctioned organizations and faced blacklisting by Tether

    A blockchain investigator known as ZachXBT released internal documentation this week obtained from a compromised device used by a North Korean IT worker, uncovering an organized cryptocurrency fraud scheme that accumulated more than $3.5 million within several months.

    An anonymous hacker who penetrated one worker’s device provided the information. ZachXBT shared the discovery on X, explaining how approximately 140 workers operating under a leader called “Jerry” were generating roughly $1 million monthly in cryptocurrency beginning in late November 2024.

    1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.

    I spent long hours going through all of it, none of which has ever been publicly released.

    It revealed an intricate… pic.twitter.com/aTybOrwMHq

    — ZachXBT (@zachxbt) April 8, 2026

    The network relied on fabricated credentials to secure remote technology positions through platforms such as Indeed. Documentation revealed Jerry submitting applications for full-stack developer and software engineer openings while utilizing an Astrill VPN to conceal geographic location.

    An unsent email draft showed Jerry pursuing a WordPress and SEO specialist opportunity at a Texas-based t-shirt business, requesting compensation of $30 hourly for 15 to 20 weekly hours.

    A second worker identified as “Rascal” employed a fabricated identity paired with a Hong Kong address on payment documentation. The leaked materials also contained an image of an Irish passport associated with Rascal, though its actual usage remains unconfirmed.

    Payment Coordination Infrastructure

    The team managed financial transactions via a website known as “luckyguys.site.” Numerous platform accounts operated using the basic password “123456,” revealing significant security vulnerabilities.

    This website served dual purposes as a communication channel and reporting system. Team members logged their earnings and awaited further directions through the platform. An administrative account designated PC-1234 validated payments and shared login credentials for cryptocurrency exchanges and financial technology services.

    Three organizations mentioned in the documentation — Sobaeksu, Saenal, and Songkwang — currently face sanctions from the US Office of Foreign Assets Control.

    Cryptocurrency proceeds underwent conversion to traditional currency through Chinese banking institutions and platforms like Payoneer. Tether froze one Tron wallet associated with the operation in December 2024.

    Malicious Activity Planning and Educational Resources

    The compromised data revealed several workers developing strategies for theft operations. One conversation mentioned plans to target Arcano on GalaChain using a Nigerian intermediary, though evidence confirming execution of this attack remains absent.

    An administrator circulated 43 educational modules addressing reverse engineering software including Hex-Rays and IDA Pro, with emphasis on disassembly techniques, debugging processes, and malware examination.

    The information trove contained 390 user accounts, conversation records, and browsing activity. Documentation showed 33 workers exchanging messages via IPMsg while connected to an identical network.

    ZachXBT observed this collective demonstrated lower technical capabilities compared to other North Korean teams such as AppleJeus and TraderTraitor.

    State-affiliated actors from North Korea have extracted more than $7 billion altogether since 2009. This particular network also maintained connections to the $280 million breach of Drift Protocol occurring on April 1, 2025.

    Share. Twitter LinkedIn Email Telegram
    Oliver Dale
    • Website
    • X (Twitter)
    • LinkedIn

    Editor-in-Chief of Computing.net and founder of Kooc Media, A UK-Based Online Media Company. Believer in Open-Source Software, Blockchain Technology & a Free and Fair Internet for all. His writing has been quoted by Nasdaq, Dow Jones, Investopedia, The New Yorker, Forbes, Techcrunch & More. Contact Oliver@blockonomi.com

    Related Posts

    Senate Releases Complete Clarity Act Text: Crypto Regulation Bill Faces Critical Vote

    May 12, 2026

    Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

    May 12, 2026

    Binance AI Systems Thwart $10.5 Billion in Cryptocurrency Fraud Attempts Over 15 Months

    May 12, 2026

    Galaxy Digital Partners with Sharplink on $125M Ethereum DeFi Yield Strategy

    May 12, 2026

    Kiyosaki’s 2026 Economic Forecast: His Investment Strategy for Silver, Bitcoin and Ethereum

    May 12, 2026

    Brent Crude Surges Past $100 Following Trump’s Dismissal of Iran Proposal

    May 11, 2026
    Add A Comment

    Comments are closed.

    Latest

    Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

    May 12, 2026

    Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

    May 12, 2026

    GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

    May 12, 2026

    SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

    May 12, 2026

    Trump Dismisses Iran Peace Proposal — Oil Markets React as Hormuz Remains Restricted

    May 12, 2026
    • Facebook
    • Twitter

    Latest Reviews

    Meta Platforms Shares Tumble 8% Despite Strong Q1 Performance Amid AI Investment Surge

    April 30, 2026

    Flush.com Review: Casino & Sportsbook With 275% Welcome Bonus

    March 7, 2026

    Katsubet Review: Crypto Casino With 300% Welcome Bonus & Free Spins

    March 7, 2026

    7Bit Review: Crypto Casino With 325% Bonus & 250 FS

    March 7, 2026

    Mega Dice Review: Crypto Casino With 200% Bonus & 50 Free Spins, Legit?

    March 7, 2026


    Home / Privacy Policy / Terms & Conditions

    Computing.net © 1996 - 2026 Kooc Media Ltd. All rights reserved. Registered Company No.05695741

    Type above and press Enter to search. Press Esc to cancel.