North – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 12 Sep 2025 06:35:15 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 North – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Microsoft investigates Exchange Online outage in North America https://earlybirdsinvest.com/microsoft-investigates-exchange-online-outage-in-north-america/ https://earlybirdsinvest.com/microsoft-investigates-exchange-online-outage-in-north-america/#respond Fri, 12 Sep 2025 06:35:15 +0000 https://earlybirdsinvest.com/microsoft-investigates-exchange-online-outage-in-north-america/

Exchange Online

Microsoft is working to resolve an ongoing Exchange Online outage affecting customers throughout North America, blocking their access to emails.

“We’re investigating an issue affecting a portion of infrastructure in North America, where users may be unable to access their mailbox via any Exchange Online connection method,” the company explained earlier today.

According to user reports on DownDetector, the issue began impacting Microsoft’s customers more than six hours ago and is causing server connection problems, affecting users who attempt to log in to their accounts and access Teams, Outlook, and Hotmail.

While the root cause has yet to be determined and Microsoft hasn’t shared the number of customers affected by this outage, the company said that it’s currently investigating telemetry data and working to mitigate the impacted infrastructure.

“We’re continuing to evaluate service telemetry for potential system irregularities contributing to impact, and in parallel we’re applying some changes to optimize affected mailbox infrastructure,” Microsoft added in a recent update.

Earlier this week, Redmond resolved another issue that caused an anti-spam service to quarantine some emails and mistakenly block Exchange Online and Microsoft Teams users from opening URLs.

The company is also rolling out a fix to address an Exchange Online issue that triggers email access problems for Outlook mobile users who use Hybrid Modern Authentication (HMA).

The issue began impacting Android and iOS users on August 17, causing mailboxes to crash and preventing them from accessing their email and calendars.

Update September 11, 18:12 EDT: According to an admin center update, the outage also impacts customers in South America. Microsoft says it’s seeing signs of recovery after implementing a configuration change to some of the impacted infrastructure.

“We’ve seen some steady improvements in service quality as our manual database optimizations and configuration changes have reduced the impact of the high service utilization on the environment,” the compay notes.

“Additionally, we’re looking into a potential build versioning issue with a subset of machines supporting the service that may be contributing to impact.”

This is a developing story…

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/microsoft-investigates-exchange-online-outage-in-north-america/feed/ 0 58022
US Government Sanctions Network Aiding North Korea’s Crypto Heists https://earlybirdsinvest.com/us-government-sanctions-network-aiding-north-koreas-crypto-heists/ https://earlybirdsinvest.com/us-government-sanctions-network-aiding-north-koreas-crypto-heists/#respond Thu, 28 Aug 2025 16:19:19 +0000 https://earlybirdsinvest.com/us-government-sanctions-network-aiding-north-koreas-crypto-heists/

The US government has taken new action against a group accused of helping North Korea steal cryptocurrency from companies in the United States by pretending to be remote tech workers.

On August 27, the Treasury Department named several individuals and organizations from North Korea, Russia, and China who allegedly played a role in this scheme.

The goal of the operation was to place North Korean workers inside foreign businesses, gain access to their systems, and then steal cryptocurrency.

What is a Crypto Mining Rig? Is it Worth it? (EASILY Explained)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

This network reportedly named several key players in the latest action. Among them are a Russian citizen named Vitaliy Andreyev, a North Korean official operating out of Russia named Kim Ung Sun, a team of North Korean IT workers operating as a company, and a Chinese business that supported their activities.

Together, they helped funnel stolen digital funds out of companies and into North Korea.

According to US officials, these workers posed as freelance or remote tech employees. Once hired, they were able to gain access to sensitive systems. From there, they could take money in the form of cryptocurrency and pass it through a web of helpers.

This latest round of sanctions builds on past operations taken to stop North Korea’s misuse of crypto tools.

In 2023, US authorities imposed penalties on a North Korean group named Chinyong, which was also involved in placing fake IT workers inside foreign businesses. That same group is connected to this new case.

Recently, Interpol arrested more than 1,200 suspects in a major operation called Operation Serengeti 2.0. How did the operation go? Read the full story.


]]>
https://earlybirdsinvest.com/us-government-sanctions-network-aiding-north-koreas-crypto-heists/feed/ 0 55564
Leaked Device Reveals North Korea's Crypto Freelance Trick https://earlybirdsinvest.com/leaked-device-reveals-north-koreas-crypto-freelance-trick/ https://earlybirdsinvest.com/leaked-device-reveals-north-koreas-crypto-freelance-trick/#respond Sun, 17 Aug 2025 22:55:52 +0000 https://earlybirdsinvest.com/leaked-device-reveals-north-koreas-crypto-freelance-trick/

An August 13 report by blockchain investigator ZachXBT has revealed how a North Korean hacking group used fake identities and freelance job platforms to secure crypto-related roles.

The findings come from a hacked device belonging to one of the group’s members.

Screenshots from the compromised system exposed six individuals, believed to be connected to a $680,000 exploit in June, coordinated their operations using familiar tools and rented equipment.

What is Chainlink? LINK Explained Simply (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The group created and managed over 30 false identities, complete with forged documents and paid accounts on LinkedIn and UpWork. These profiles were then used to apply for remote jobs in the blockchain industry.

One member was found to have gone through an interview process for a developer role at Polygon
MATIC


$0.2487

Labs, while others submitted applications claiming to have worked at platforms like OpenSea and Chainlink
LINK


$25.42

.

Once hired, the team relied on remote access software such as AnyDesk and used VPNs to hide their actual locations. Their daily workflow was organized through Google’s ecosystem, including Drive, Chrome profiles, and calendar tools, often supported by Google Translate to assist with English communication.

Payments for their services typically flowed through Payoneer and were later converted into crypto. One wallet address, labeled “0x78e1a”, was directly linked to the June hack of the fan-token platform Favrr.

Other insights from the leaked device include simple technical searches, such as whether ERC-20 tokens can operate on Solana
SOL


$190.83

, and queries like identifying top artificial intelligence (AI) developers in Europe.

Recently, Meta deleted over 6.8 million WhatsApp accounts linked to scam groups running crypto fraud schemes. How do these scam groups operate? Read the full story.


]]>
https://earlybirdsinvest.com/leaked-device-reveals-north-koreas-crypto-freelance-trick/feed/ 0 53723
North Korean Kimsuky hackers exposed in alleged data breach https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/ https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/#respond Tue, 12 Aug 2025 09:30:51 +0000 https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/

North Korea

The North Korean state-sponsored hackers known as Kimsuky has reportedly suffered a data breach after two hackers, who describe themselves as the opposite of Kimsuky’s values, stole the group’s data and leaked it publicly online.

The two hackers, named ‘Saber’ and ‘cyb0rg,’ cited ethical reasons for their actions, saying Kimsuky is “hacking for all the wrong reasons,” claiming they’re driven by political agendas and follow regime orders instead of practicing the art of hacking independently.

“Kimsuky, you are not a hacker. You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda,” reads the hackers’ address to Kimsuky published in the latest issue of Phrack, which was distributed at the DEF CON 33 conference.

“You steal from others and favour your own. You value yourself above the others: You are morally perverted.”

The hackers dumped a portion of Kimsuky’s backend, exposing both their tooling and some of their stolen data that could provide insight into unknown campaigns and undocumented compromises.

The 8.9GB dump currently hosted on the ‘Distributed Denial of Secrets” website contains, among others:

  • Phishing logs with multiple dcc.mil.kr (Defense Counterintelligence Command) email accounts.
  • Other targeted domains: spo.go.kr, korea.kr, daum.net, kakao.com, naver.com.
  • .7z archive containing the complete source code of South Korea’s Ministry of Foreign Affairs email platform (“Kebi”), including webmail, admin, and archive modules.
  • References to South Korean citizen certificates and curated lists of university professors.
  • PHP “Generator” toolkit for building phishing sites with detection evasion and redirection tricks.
  • Live phishing kits.
  • Unknown binary archives (voS9AyMZ.tar.gz, Black.x64.tar.gz) and executables (payload.bin, payload_test.bin, s.x64.bin) not flagged in VirusTotal.
  • Cobalt Strike loaders, reverse shells, and Onnara proxy modules found in VMware drag-and-drop cache.
  • Chrome history and configs linking to suspicious GitHub accounts (wwh1004.github.io, etc.), VPN purchases (PureVPN, ZoogVPN) via Google Pay, and frequent use of hacking forums (freebuf.com, xaker.ru).
  • Google Translate use for Chinese error messages and visits to Taiwan government and military sites.
  • Bash history with SSH connections to internal systems.

The hackers note that some of the above are already known or previously documented, at least partially.

However, the dump gives a new dimension to the data and provides interlinking between Kimsuky’s tools and activities, exposing and effectively “burning” the APT’s infrastructure and methods.

BleepingComputer has contacted various security researchers to confirm the veracity of the leaked documents and its value and will update the story if we receive a response.

While the breach will likely not have long-term impact on Kimsuky’s operations, it could lead to operational difficulties for Kimsuky and disruptions to ongoing campaigns.

The latest issue of Phrack (#72) is currently only available in a limited physical copy, but the online version should be ready for people to read for free in the following days from here.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/feed/ 0 52797
Investor Sues Pepe Meme Creator Over Role in North Korean NFT Hack https://earlybirdsinvest.com/investor-sues-pepe-meme-creator-over-role-in-north-korean-nft-hack/ https://earlybirdsinvest.com/investor-sues-pepe-meme-creator-over-role-in-north-korean-nft-hack/#respond Thu, 07 Aug 2025 18:44:37 +0000 https://earlybirdsinvest.com/investor-sues-pepe-meme-creator-over-role-in-north-korean-nft-hack/

An NFT investor is suing Matt Furie, the creator behind the Pepe meme, for his role in a hack that left his collection worthless. Jaggedsoft, who is also the creator of the Binance application programming interface (API), claims Furie and the NFT marketplace Chain/Saw enabled the hack by engaging in mismanagement, willful misconduct, and negligence of the project.

Furie created Pepe the Frog, and over the years, the meme has become prominent in both online and crypto communities. The artist did not join the Web3 space until recently, and his partnership with Chain/Saw led to the release of the NFT collection Replicandy. Pseudonymous crypto trader Path revealed that Jaggedsoft is the largest collector of Replicandy NFTs.

Within the third week of June, Furie’s NFT collection Replicandy was targeted by an IT worker who was hired as a developer for the project. The worker belongs to a North Korean hacker group, and these entities are known for their notoriety in infiltrating crypto projects.

On-chain sleuth ZachXBT explained that the IT worker first transferred ownership of Replicandy from Furie and Chain/Saw to his address. Then the attacker continuously minted NFTs and sold them in bids until their floor price plummeted to zero. Afterwards, they withdrew the mint proceeds from the contract, totaling at least $310,000, and transferred them to their addresses.

Since the hack happened, neither Furie nor Chain/Saw have said anything about reimbursing users or handling the incident. Their X handles, which were active prior to the event, have been mute since June 18. 

Jaggedsoft insists the project could have avoided hiring a North Korean hacker if they had done their due diligence on workers before employment. He insists that skipping basic checks, hiring the wrong people, letting a hack happen, and trying to hide it is not just unethical, but potentially criminal concealment.

The NFT investor also disclosed that Chain/Saw’s creator threatened to “fuck my life up” if he went ahead with the litigation. However, he said he had nothing to lose since his collectibles were already worthless. 

Meanwhile, the Binance API creator initially did not want to involve Furie in the lawsuit as he only created the art. However, Furie’s role in concealing the incident and other deceptive behaviors caused a change of heart; now he is mentioned in the lawsuit. Will litigation make Furie and Chain/Saw to reimburse users? Stay tuned for more updates.

]]>
https://earlybirdsinvest.com/investor-sues-pepe-meme-creator-over-role-in-north-korean-nft-hack/feed/ 0 52015
Arizona Freelancer Sentenced for Helping North Korean Workers Infiltrate US Jobs https://earlybirdsinvest.com/arizona-freelancer-sentenced-for-helping-north-korean-workers-infiltrate-us-jobs/ https://earlybirdsinvest.com/arizona-freelancer-sentenced-for-helping-north-korean-workers-infiltrate-us-jobs/#respond Sun, 27 Jul 2025 03:29:49 +0000 https://earlybirdsinvest.com/arizona-freelancer-sentenced-for-helping-north-korean-workers-infiltrate-us-jobs/

Christina Marie Chapman, a freelancer from Arizona with over 100,000 TikTok followers, has been sentenced to eight and a half years in prison after helping North Korean workers get hired by US companies using false identities.

A court in Washington, DC found her guilty of conspiracy to commit wire fraud, identity theft, and money laundering.

Along with the prison time, she will spend three more years under supervision, forfeit over $284,000, and repay $176,850.

What is a Crypto Mining Rig? Is it Worth it? (EASILY Explained)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

FBI Counterintelligence Assistant Director Roman Rozhavsky said in a July 24 press release that she played a key part in a plan that brought in around $17 million to fund North Korea’s weapons development. He added:

Even an adversary as sophisticated as the North Korean government can’t succeed without the assistance of willing US citizens like Christina Chapman.

Starting in 2020, Chapman worked with North Korean agents to set up US-based remote jobs for overseas IT workers.

To make it seem like those workers were physically located in the US, she ran a “laptop farm” from her home. She connected dozens of company-issued computers to the internet so that remote users could log in without raising suspicion.

Officials later recovered more than 90 computers from her home. Chapman also sent 49 devices to addresses overseas, including several in a city near North Korea’s border.

Chapman moved the money through her own accounts. She also helped file tax documents and Social Security forms under the names of the people whose identities were being used.

On July 16, Paul Chowles, a former officer from the UK’s National Crime Agency, got 5.5 years for stealing 50 Bitcoin
BTC


$117,214.79

in a Silk Road 2.0 probe. How did the case unfold? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/arizona-freelancer-sentenced-for-helping-north-korean-workers-infiltrate-us-jobs/feed/ 0 49885
TikTok Influencer Sentenced to 8.5 Years for Aiding North Korean IT Sanctions Evasion Scheme https://earlybirdsinvest.com/tiktok-influencer-sentenced-to-8-5-years-for-aiding-north-korean-it-sanctions-evasion-scheme/ https://earlybirdsinvest.com/tiktok-influencer-sentenced-to-8-5-years-for-aiding-north-korean-it-sanctions-evasion-scheme/#respond Fri, 25 Jul 2025 12:25:01 +0000 https://earlybirdsinvest.com/tiktok-influencer-sentenced-to-8-5-years-for-aiding-north-korean-it-sanctions-evasion-scheme/

Crypto Journalist

Amin Ayan

Crypto Journalist

Amin Ayan

About Author

Amin Ayan is a crypto journalist with over four years of experience in the industry. He has contributed to leading publications such as Cryptonews, Investing.com, 99Bitcoins, and 24/7 Wall St. He has…

Last updated: 


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

An Arizona-based TikTok influencer has been sentenced to eight and a half years in prison for her role in a North Korean plot to infiltrate the U.S. tech workforce and fund the regime’s weapons program.

Key Takeaways:

  • Christina Chapman was sentenced to 8.5 years for helping North Korean IT workers infiltrate US tech jobs.
  • She ran a “laptop farm” and laundered wages, aiding over 300 job placements.
  • The scheme is part of a broader effort by North Korea to fund its weapons program.

Christina Marie Chapman, who gained popularity online for her freelance lifestyle content, was convicted in Washington, D.C. on charges of wire fraud conspiracy, aggravated identity theft, and money laundering.

In addition to prison time, Chapman was ordered to forfeit over $284,000 and pay restitution of $176,850. She will also serve three years of supervised release.

TikToker Ran ‘Laptop Farm’ to Help North Korean IT Workers Pose as US Employees

According to prosecutors, Chapman operated a “laptop farm” from her home, allowing North Korean IT workers to remotely access U.S.-based networks while appearing to be physically located inside the country.

Between 2020 and her arrest, she helped operatives obtain remote roles at more than 300 American companies, including Fortune 500 firms, a major television network, and a leading aerospace manufacturer.

“Even an adversary as sophisticated as the North Korean government can’t succeed without the assistance of willing U.S. citizens like Christina Chapman,” said Roman Rozhavsky, Assistant Director of the FBI’s Counterintelligence Division.

US authorities say North Korea has built a global network of IT operatives who use fake identities and proxy networks to secure jobs and channel funds to the regime.

Chapman’s activities helped facilitate these efforts by setting up U.S.-based internet access, laundering wages through personal bank accounts, and shipping laptops overseas, including multiple devices sent to a Chinese city near North Korea.

Investigators seized more than 90 laptops from her residence and discovered she had sent 49 more abroad.

The wages earned by the North Korean agents were misreported to the US tax and social security agencies under stolen or borrowed American identities.

The crypto sector remains a key target in this operation. According to Chainalysis, North Korean-linked hackers stole $1.34 billion in cryptocurrency in 2024 alone, up 21% from the previous year.

Cybersecurity experts say North Korean job seekers are increasingly sophisticated, often hiring European actors to front video interviews while using VPNs and proxy IPs to conceal their locations.

North Korea Linked to Major Crypto Hacks

North Korea has also been linked to several other major crypto heists, including those targeting Bybit, the Ronin Bridge, Harmony, and various DeFi platforms.

Global law enforcement is responding. The U.S. Department of Justice recently moved to seize over $7.7 million in digital assets tied to North Korean IT workers embedded in blockchain firms.

Meanwhile, the U.S. and South Korea signed a bilateral agreement in 2023 to enhance their technical capabilities in detecting and countering DPRK cyber operations.

North Korean cyber strategies continue to evolve. In April, Lazarus-linked operatives reportedly set up US-based shell companies to distribute malware to crypto developers.

Kraken recently thwarted an infiltration attempt by a suspected North Korean posing as a job candidate.


]]>
https://earlybirdsinvest.com/tiktok-influencer-sentenced-to-8-5-years-for-aiding-north-korean-it-sanctions-evasion-scheme/feed/ 0 49587
Tornado Cash Trial: Roman Storm Faces Claims of Aiding North Korea Hackers https://earlybirdsinvest.com/tornado-cash-trial-roman-storm-faces-claims-of-aiding-north-korea-hackers/ https://earlybirdsinvest.com/tornado-cash-trial-roman-storm-faces-claims-of-aiding-north-korea-hackers/#respond Wed, 16 Jul 2025 10:35:28 +0000 https://earlybirdsinvest.com/tornado-cash-trial-roman-storm-faces-claims-of-aiding-north-korea-hackers/

Tornado Cash has become a tool for North Korea’s Lazarus Group after the hackers stole $600 million from the Ronin Bridge in 2022, US prosecutors told jurors on July 15 as the trial of Roman Storm began in Manhattan.

Storm, one of the developers behind the crypto privacy software, is accused of allowing the sanctioned group to use his service to hide stolen funds, despite being aware of its intended use.

In opening statements, Assistant US Attorney Kevin Mosley stated that Tornado Cash is a “giant washing machine for dirty money” and argued Storm chose to keep the platform running even after learning criminals were abusing it.

What is Olympus DAO? (OHM Crypto Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

However, Storm’s legal team argued that he did nothing illegal. His lawyer, Keri Axel, told the jury that Tornado Cash was a public privacy tool anyone could use, and Storm could not control what others did with it. She said:

The world is full of products that have legitimate uses and are misused. Signal, or even a hammer that can be used to break in and steal stuff. The government can’t show a criminal agreement for a criminal purpose.

Prosecutors objected twice during Axel’s statement when she raised examples about users’ safety, but the judge allowed her to finish.

According to Storm, the trial could take up to a month, with a verdict expected before mid‑August. On July 14, he requested urgent financial assistance to fund his legal defense. What did he say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/tornado-cash-trial-roman-storm-faces-claims-of-aiding-north-korea-hackers/feed/ 0 47934
US sanctions North Korean tech worker crew over crypto thefts https://earlybirdsinvest.com/us-sanctions-north-korean-tech-worker-crew-over-crypto-thefts/ https://earlybirdsinvest.com/us-sanctions-north-korean-tech-worker-crew-over-crypto-thefts/#respond Wed, 09 Jul 2025 02:51:36 +0000 https://earlybirdsinvest.com/us-sanctions-north-korean-tech-worker-crew-over-crypto-thefts/

The US Treasury has sanctioned two people and four entities involved in what it says was a North Korea-run IT worker ring that would infiltrate crypto companies, aiming to exploit them.

The Treasury’s Office of Foreign Assets Control (OFAC) said on Tuesday that it sanctioned the North Korea-based Song Kum Hyok for allegedly stealing US citizens’ information to use as aliases and giving it to hired foreign IT workers who would seek employment at US companies.

OFAC also sanctioned the Russian national Gayk Asatryan for allegedly using his companies to employ dozens of North Korean IT workers under long-term agreements he signed with North Korean trading firms starting in 2024.

Source: Treasury Department 

A growing number of fraudulent tech workers with ties to North Korea, officially the Democratic People’s Republic of Korea (DPRK), have been expanding their infiltration operations, with an April report from Google finding that the infrastructure for the schemes has spread worldwide.

“Treasury remains committed to using all available tools to disrupt the Kim regime’s efforts to circumvent sanctions through its digital asset theft, attempted impersonation of Americans, and malicious cyber-attacks,” said Treasury Deputy Secretary Michael Faulkender.

Thousands of IT workers target wealthier countries to fund missile program

OFAC said North Korea aims to generate revenue for its ballistic missile programs by deploying a thousands-strong workforce of highly skilled IT workers all over the world, the bulk of which are located in China and Russia.

The workforce mainly targets employers located in wealthier countries and uses various mainstream and industry-specific networking platforms, OFAC said.

The sanctions mean all US assets connected to Asatryan, Song, and the four Russian entities also named are frozen. It’s also now illegal for people in the US to conduct any financial transactions or have business dealings with them under the threat of civil and criminal penalties.

North Korea shifting away from hacks

North Korea has been notorious for its high-profile hacks through teams such as the Lazarus Group, and is responsible for some of the largest crypto hacks ever recorded, such as the $1.5 billion Bybit exploit in February.

However, blockchain intelligence firm TRM Labs said on Tuesday that they are starting to shift tactics. 

“While exchange breaches remain significant, DPRK-linked operations are increasingly shifting toward deception-based revenue generation, including IT worker infiltration,” the firm said.

Source: TRM Labs 

TRM Labs estimates North Korea-aligned bad actors are responsible for $1.6 billion of the $2.1 billion stolen across 75 crypto hacks and exploits in the first half of 2025.

US cracks down on North Korean IT workers

US authorities have been increasingly cracking down on fraudulent North Korean IT worker schemes this year.

Related: North Korea targets crypto workers with new info-stealing malware

On June 30, four North Korean nationals were charged with wire fraud and money laundering after posing as remote workers at US and Serbian blockchain companies.

Meanwhile, on June 5, the US Department of Justice said it was trying to seize $7.74 million in frozen crypto allegedly earned by North Korean IT workers using fake identities and working at blockchain firms as remote contractors.  

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express

]]> https://earlybirdsinvest.com/us-sanctions-north-korean-tech-worker-crew-over-crypto-thefts/feed/ 0 46570 Remote Work Scam: North Koreans Stole $1 Million in Crypto, DOJ Says https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/ https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/#respond Wed, 02 Jul 2025 06:27:08 +0000 https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/

US prosecutors have charged four North Korean citizens with wire fraud and money laundering after they allegedly pretended to be remote IT workers to steal nearly $1 million in crypto.

The charges were filed in the state of Georgia and involve two blockchain companies based in the US and Serbia.

The US Department of Justice (DOJ) identified the suspects as Kim Kwang Jin, Kang Tae Bok, Jong Pong Ju, and Chang Nam Il. The group reportedly used fake and stolen IDs to hide that they were North Korean citizens.

What is Terra Luna? History & Crash Explained (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

They started operating from the United Arab Emirates in 2019 before later getting jobs at a blockchain startup in Atlanta and a crypto firm in Serbia between December 2020 and May 2021.

Kim and Jong are accused of using fake documents, including false identification, to secure employment. US Attorney Theodore S. Hertzberg said this method poses a risk for companies that rely on remote workers, as it can be difficult to confirm someone’s true identity.

After getting access to internal systems, the suspects carried out two separate thefts. In February 2022, Jong allegedly stole around $175,000 in cryptocurrency. A month later, Kim exploited smart contract code to take another $740,000.

The stolen money was then moved through mixing services and sent to exchange accounts controlled by Kang and Chang. These accounts were set up using fake Malaysian IDs, investigators said.

According to John A. Eisenberg, the assistant attorney general for national security, the stolen funds were meant to help North Korea avoid sanctions and support its banned weapons programs.

Recently, Dwayne Golden, a 57-year-old man from the US, was sentenced to nearly eight years in prison. What happened? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/remote-work-scam-north-koreans-stole-1-million-in-crypto-doj-says/feed/ 0 45292