{"id":36021,"date":"2025-07-09T17:31:32","date_gmt":"2025-07-09T17:31:32","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=36021"},"modified":"2025-07-09T17:31:32","modified_gmt":"2025-07-09T17:31:32","slug":"crypto-heist-crew-exposed-us-sanctions-north-koreas-shadow-coders","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=36021","title":{"rendered":"Crypto Heist Crew Exposed: US Sanctions North Korea\u2019s Shadow Coders"},"content":{"rendered":"<div>\n<p>US Treasury officials announced <a href=\"https:\/\/www.trmlabs.com\/resources\/blog\/us-treasury-sanctions-north-korean-cyber-facilitator-linked-to-it-worker-scheme\" target=\"_blank\" rel=\"noopener nofollow\">sanctions<\/a> this week aimed at shutting down a North Korea\u2011backed IT worker network that targeted crypto firms and other tech companies. Two individuals and four entities are now cut off from the US financial system.<\/p>\n<p>According to Treasury Deputy Secretary Michael Faulkender, these steps are meant to stop the misuse of stolen identities and <a href=\"https:\/\/www.coingecko.com\/\" target=\"_blank\" rel=\"noopener nofollow\">crypto<\/a> theft that funds North Korea\u2019s missile programs. It\u2019s a sharp pivot from giant hacks to undercover operations.<\/p>\n<h2>Stealth Operations Uncovered<\/h2>\n<p>Based on reports from the <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0190\" target=\"_blank\" rel=\"noopener nofollow\">Office of Foreign Assets Control<\/a> (OFAC), the sanctions hit Song Kum Hyok, a North Korea\u2011based operator accused of stealing US citizens\u2019 data to create fake identities.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Today, the Treasury\u2019s Office of Foreign Assets Control is taking action to stop individuals and entities that are enabling the Democratic People\u2019s Republic of Korea (DPRK) IT worker schemes.<\/p>\n<p>The DPRK generates significant revenue for its WMD and ballistic missile programs by\u2026<\/p>\n<p>\u2014 Treasury Department (@USTreasury) <a href=\"https:\/\/twitter.com\/USTreasury\/status\/1942645699491029372?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">July 8, 2025<\/a><\/p>\n<\/blockquote>\n<p>The operator then funneled those aliases to hired IT workers who applied to US firms. The other target is Gayk Asatryan, a Russian national who signed long\u2011term deals in 2024 with North Korean trading firms to employ dozens of <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-07-08\/us-sanctions-target-north-korean-fake-tech-worker-scheme\" target=\"_blank\" rel=\"noopener nofollow\">North Korean developers<\/a> in his companies.<\/p>\n<p>All US assets tied to them\u2014and to the four Russian entities named\u2014are now frozen. That means Americans can\u2019t make payments or open accounts linked to those sanctioned parties without risking civil or criminal penalties.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\"><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/15.1.0\/72x72\/1f6a8.png\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> This afternoon the <a href=\"https:\/\/twitter.com\/USTreasury?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">@USTreasury<\/a> sanctioned a key North Korean cyber actor for running an IT worker scheme using fake US IDs to funnel funds to the DPRK. For more check out our blogpost here: <a href=\"https:\/\/t.co\/MJ5a0jaoDL\" rel=\"nofollow\" target=\"_blank\">https:\/\/t.co\/MJ5a0jaoDL<\/a> <a href=\"https:\/\/t.co\/i7fbe9STp5\" rel=\"nofollow\" target=\"_blank\">pic.twitter.com\/i7fbe9STp5<\/a><\/p>\n<p>\u2014 TRM Labs (@trmlabs) <a href=\"https:\/\/twitter.com\/trmlabs\/status\/1942671975236710548?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">July 8, 2025<\/a><\/p>\n<\/blockquote>\n<h2>Hidden Workforce And Crypto Funding<\/h2>\n<p>North Korea\u2019s IT workforce now numbers in the thousands. Most are based in China and Russia, but they apply for jobs at firms in wealthier countries via mainstream and niche recruiting sites.<\/p>\n<p>According to OFAC, the aim is to raise cash for ballistic missile work by embedding skilled coders inside target firms. It\u2019s a model that spreads risk and makes detection harder than a single big attack.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full\" src=\"https:\/\/www.tradingview.com\/x\/BapZqwYs\/\" width=\"2048\" height=\"960\"><\/p>\n<p>North Korea\u2019s New Tactics<\/p>\n<p>A recent Google study found that this kind of scheme has gone global. While elaborate hacks still grab headlines, state\u2011aligned groups are increasingly banking on deception.<\/p>\n<p><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" class=\"aligncenter size-full wp-image-526669\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/07\/a_448283.png?resize=689%2C347\" alt=\"\" width=\"689\" height=\"347\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/07\/a_448283.png?w=689 689w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/07\/a_448283.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/07\/a_448283.png?w=360 360w\" sizes=\"auto, (max-width: 689px) 100vw, 689px\"><\/p>\n<p>That involves stealing data and posing as trusted workers rather than breaking into servers from the outside. It\u2019s quieter. It\u2019s often cheaper. And it can keep running for years before anyone notices.<\/p>\n<p>Rising Crypto Losses And Shifts In Strategy<\/p>\n<p>Blockchain\u2011intelligence firm TRM\u202fLabs reports that North Korea\u2011linked actors were behind about $1.6 billion of the $2.1 crypto stolen across 75 crypto hacks and exploits in the first half of 2025.<\/p>\n<p>It\u2019s a huge chunk. TRM Labs warns that while big exchange breaches still happen, a growing share of revenue now comes from these false\u2011identity worker schemes.<\/p>\n<p><em>Featured image from Getty Images, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>US Treasury officials announced sanctions this week aimed at shutting down a North Korea\u2011backed IT worker network that targeted crypto firms and other tech companies. Two individuals and four entities are now cut off from the US financial system. According to Treasury Deputy Secretary Michael Faulkender, these steps are meant to stop the misuse of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-36021","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/36021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36021"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/36021\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=36021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=36021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}