[REVISION HISTORY]
North Korean crypto hacking and software supply-chain ops
Updated 7 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-17 12:13 UTC → 2026-08-31 23:58 UTC ·
added
removed
By August 2026, reports indicated North Korean state-sponsored actors had targeted over 1,640 organizations across 57 countries. New intelligence Intelligence from Proofpoint identified a cluster dubbed ‘UNK_DeadDrop,’ the ‘UNK_DeadDrop’ cluster, which targets developers via phishing campaigns using malicious Visual Studio Code extensions (VSIX) and GitHub repositories to deploy cross-platform malware. This technical exploitation is paired with a social engineering strategy where operatives use identity theft and theft, fraudulent banking banking, and artificial intelligence to impersonate foreign nationals in remote work roles. A joint statement from the United States These fraudulent schemes are expanding beyond IT into healthcare, sales, and ten allies warned that these marketing. In February 2026, three North Korean workers aim to bypass sanctions, a tactic highlighted by impersonating Chinese nationals were identified at an Australian healthcare company after investigators detected suspicious VPN usage and passport anomalies. The FBI investigation into is currently investigating a North Korean national who reportedly secured remote employment with a U.S. federal agency. Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, noted that operatives use stolen identities, fraudulent documents, and VPNs to mask their locations, sometimes utilizing US-based facilitators to receive hardware. Financial investigations have also revealed the massive scale of these operations. A report by the Royal United Services Institute (RUSI) estimated that estimate North Korea stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025 to fund its weapons programs. To manage these assets, Pyongyang is increasingly outsourcing outsources laundering to established Asian criminal networks. The regime reportedly networks, such as ‘pig butchering’ syndicates, or sells stolen coins at a discount to third parties or utilizes infrastructure used by organized crime, such as ‘pig butchering’ syndicates. parties. This process involves mixing stolen funds with other criminal proceeds and utilizing money mules in China, the Philippines, and Indonesia, as well as over-the-counter desks and alongside entities like Cambodia’s Huione Group to convert digital assets into fiat currency. Recent FBI disclosures have further detailed the methods used by these operatives. Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, noted that workers use stolen identities, fraudulent documents, and VPNs to mask their locations, sometimes aided by US-based facilitators who receive hardware to create the illusion of domestic presence.
Versions
- 2026-08-31 23:58 UTC North Korean crypto hacking and software supply-chain ops
- 2026-08-17 12:13 UTC North Korean crypto hacking and software supply-chain ops
- 2026-08-12 13:37 UTC North Korean crypto hacking and software supply-chain ops
- 2026-08-10 04:21 UTC North Korean crypto hacking and software supply-chain ops
- 2026-07-31 20:56 UTC North Korean crypto hacking and software supply‑chain ops
- 2026-07-31 05:20 UTC North Korean crypto hacking and software supply‑chain ops
- 2026-07-30 04:33 UTC North Korean cryptocurrency hacking and supply‑chain attacks
- 2026-07-26 03:17 UTC North Korean cryptocurrency hacking
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.