< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

8 clusters · 32 sources · 60 days · First seen · Last updated

North Korean crypto hacking and software supply-chain ops

Overview

By August 2026, North Korean state-sponsored actors had targeted over 1,640 organizations across 57 countries. Intelligence from Proofpoint identified the ‘UNK_DeadDrop’ cluster, which targets developers via phishing campaigns using malicious Visual Studio Code extensions (VSIX) and GitHub repositories to deploy cross-platform malware. This technical exploitation is paired with a social engineering strategy where operatives use identity theft, fraudulent banking, and artificial intelligence to impersonate foreign nationals in remote work roles.

These fraudulent schemes are expanding beyond IT into healthcare, sales, and marketing. In February 2026, three North Korean workers impersonating Chinese nationals were identified at an Australian healthcare company after investigators detected suspicious VPN usage and passport anomalies. The FBI is currently investigating a North Korean national who secured remote employment with a U.S. federal agency. Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, noted that operatives use stolen identities, fraudulent documents, and VPNs to mask their locations, sometimes utilizing US-based facilitators to receive hardware.

Financial investigations by the Royal United Services Institute (RUSI) estimate North Korea stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025 to fund weapons programs. To manage these assets, Pyongyang increasingly outsources laundering to Asian criminal networks, such as ‘pig butchering’ syndicates, or sells stolen coins at a discount to third parties. This process involves mixing stolen funds with criminal proceeds and utilizing money mules in China, the Philippines, and Indonesia, alongside entities like Cambodia’s Huione Group to convert digital assets into fiat currency.

Entities

North Korea · FBI · Todd Hemmen · Huntress · Elliptic

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 16 days ago

    [TECHNOLOGY] 3 sources
    North Korea expands fraudulent job schemes into healthcare and sales

    North Korean actors are expanding fraudulent remote employment schemes into healthcare and sales to fund weapons programs, using forged identities and VPNs to bypass corporate security.

  2. about 1 month ago

    [TECHNOLOGY] 3 sources
    FBI investigates North Korean IT worker at US federal agency

    The FBI is investigating a North Korean IT worker who infiltrated a US federal agency using false identities, highlighting growing risks of remote-work espionage and AI-enhanced recruitment fraud.

  3. about 1 month ago

    [INTERNATIONAL] 2 sources
    North Korea uses criminal networks to launder $2.8 billion in stolen crypto

    North Korea stole $2.8 billion in crypto between Jan 2024 and Sept 2025, increasingly using Asian criminal networks to launder the funds to finance its weapons program.

  4. about 1 month ago

    [TECHNOLOGY] 4 sources
    North Korean actors target developers and infiltrate agencies via remote work

    North Korean actors are using sophisticated phishing, AI, and identity theft to secure remote jobs and fund weapons programs, including a suspected infiltration of a U.S. federal agency.

  5. about 2 months ago

    [TECHNOLOGY] 10 sources
    North Korean Hackers Target macOS Users and Open‑Source npm Packages

    North Korean hackers used a fake macOS update with blockchain C2 to steal crypto and deployed a malicious Chrome extension, while also compromising npm packages (typo‑crypto, debug, chalk, axios) to inject code

  6. about 2 months ago

    [CRIME] 5 sources
    North Korea arrests former military hackers accused of stealing state bank funds via cryptocurrency

    North Korea arrested former military hackers on July 12, accusing them of breaching state banks and laundering stolen funds via cryptocurrency, though the claims are unverified.

  7. about 2 months ago

    [TECHNOLOGY] 6 sources
    North Korean Crypto Threats Spur Security Reveal and Arrests

    Fireblocks revealed “BitForge” crypto wallet flaws that could aid nation‑state attackers like North Korea’s Lazarus group, while North Korean officials reportedly arrested a team accused of hacking state banks

  8. 3 months ago

    [CRIME] 2 sources
    North Korea-linked hackers seize $643 million in crypto, 66% of H1 global loss

    North Korean-linked hackers stole about $643 million in crypto in H1 2024, representing 66 % of the $972 million global crypto‑hacking loss, mainly from two DeFi platform breaches.

Sources

abmedia.io · b2b-cyber-security.de · brasilemfolhas.com.br · clubic.com · cointelegraph.com · countryrebel.com · crypto-news-flash.com · cryptobriefing.com · cryptopolitan.com · cybernoz.com · cyberscoop.com · cybersecuritynews.com · decrypt.co · dev.to · editorials.voa.gov · en.coin-turk.com · flagthis.com · ibtimes.co.uk · it-boltwise.de · journalducoin.com · livecoins.com.br · news-krypto.de · news.donga.com · opensourceforu.com · police.cz · securityaffairs.co · sf-encyclopedia.com · spacemoney.com.br · stv.seoul.co.kr · thehackernews.com · theregister.com · tokenpost.com

This summary has been updated 7 times: see revision history