Researchers Lure Suspected North Korean IT Workers Into Fake Crypto Startup
North Korea has been accused of dispatching IT workers under stolen or fabricated identities to secure remote jobs abroad, remit salaries to sanctioned state agencies and gain legitimate access to source code and internal systems. The scheme turns recruitment into an insider-security risk, particularly for crypto companies. In a separate case, the U.S. Justice Department said in April 2026 that two American facilitators helped place workers at more than 100 U.S. companies using at least 80 stolen identities, generating more than $5 million for North Korea.
Researchers Mauro Eldritch of BCA LTD, Heiner García of NorthScan and ANY.RUN built a fictitious DeFi startup, Ballena Azul, and hired three people they assessed as suspected Famous Chollima operatives. The findings were presented at DEF CON 34 in Las Vegas in August 2026 and reported on Aug. 11. On their first day, all three profiled assigned virtual machines and checked the apparent location of their connections; investigators also observed AstrillVPN, 2fa.cn and AI job-interview tools. The controlled systems exposed operational behavior and infrastructure without granting access to a real company.
All Coverage
1 original reportsThe Backstory
The history behind this eventNorth Korea Arrests Ex-Military Hackers Over Bank Theft, Crypto Laundering
North Korea’s central bank oversees currency issuance and state funds, while the Foreign Trade Bank handles foreign payments and currency transactions. The alleged ring included veterans of a military intelligence cyber-operations unit and IT specialists recruited from leading universities. Their suspected use of state-developed hacking expertise against two pillars of the country’s financial system marks an unusual insider breach and exposes vulnerabilities within an apparatus better known for conducting cyber theft abroad.
Daily NK reported on July 24 that North Korea’s security agency raided a Pyongyang safe house on the night of July 12, 2026, arresting alleged ringleaders and IT personnel. Investigators said the group diverted trade funds and foreign currency in small increments, sent them to overseas crypto wallets and used brokers in China to convert the assets into U.S. dollars and Chinese yuan. Authorities did not disclose the amount stolen or the number arrested, but reportedly seized computer equipment worth hundreds of thousands of dollars.
US Treasury Sanctions North Korean IT Fraud Network and Crypto-Laundering Channels
North Korea has long dispatched IT workers overseas to apply remotely for technology jobs using false identities, stolen data belonging to U.S. residents and “laptop farms,” then remit most of their salaries to Pyongyang. Such operations target blockchain and cryptocurrency companies and may also involve planting malware and stealing confidential information. The proceeds are alleged to fund North Korea’s nuclear weapons and ballistic missile programs.
On March 12, 2026, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned six individuals and two entities, saying the network generated nearly $800 million for North Korea in 2024. A Vietnam-based operator converted about $2.5 million in cryptocurrency between mid-2023 and mid-2025. On April 15, the U.S. Justice Department separately announced that two accomplices had been sentenced to 92 and 108 months in prison for helping infiltrate more than 100 companies and generate over $5 million in revenue.
North Korean IT Operatives Exposed Earning $1 Million a Month Through Crypto Scams
North Korea has long used overseas IT workers posing as job applicants to infiltrate crypto projects and gain salaries, system access and digital assets. The network uncovered by blockchain investigator ZachXBT involved about 140 people, indicating that the operation had developed into a sizable, sustainable source of foreign currency that could help North Korea evade international sanctions.
As of July 19, 2026, data released by ZachXBT showed that the team earned about $1 million a month from IT jobs and crypto scams. Members used simple passwords such as “123456” to manage payment and ranking platforms. Stolen crypto was converted into fiat currency and then transferred to Chinese bank accounts.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.