North Korean Hackers Evade UN Sanctions Through Cyber Operations and Crypto Schemes
The Multilateral Sanctions Monitoring Team (MSMT) has released a comprehensive report documenting systematic violations of UN sanctions by North Korea.
Between 2024 and 2025, North Korean cyber operations have achieved unprecedented scale in cryptocurrency theft.
In 2024 alone, DPRK-linked actors stole approximately USD 1.19 billion a 50 percent year-on-year increase.
Revealing how the Democratic People’s Republic of Korea (DPRK) employs sophisticated cyber operations, deployed IT workers, and cryptocurrency theft to circumvent international restrictions while funding weapons development and ballistic missile programs.
The trajectory continued accelerating through 2025, with USD 1.65 billion stolen in just the first nine months, bringing the combined total to USD 2.8 billion across the reporting period.
These proceeds now account for roughly one-third of the DPRK’s total foreign exchange revenue, underscoring cryptocurrency’s critical role in sanctions evasion.
The most significant incident involved the February 2025 TraderTraitor breach of Bybit, a Dubai-based cryptocurrency exchange, resulting in the theft of nearly USD 1.5 billion the largest cryptocurrency heist in history.
Additional high-profile targets included Japan’s DMM Bitcoin and India’s WazirX, with attacks leveraging supply chain vulnerabilities and third-party service compromises to bypass multi-factor authentication and transaction limits.
The MSMT report identifies multiple sophisticated DPRK APT groups operating in coordinated fashion.
TraderTraitor (also known as Jade Sleet and UNC4899) emerged as the most formidable, stealing approximately USD 2.58 billion between January 2024 and September 2025 through social engineering and supply chain intrusions.
CryptoCore (Sapphire Sleet) stole at least USD 33.5 million using spear-phishing tactics and malicious npm packages during fake skill assessments.
Attack methodologies have evolved significantly, incorporating generative AI to create synthetic identities and conduct realistic phishing campaigns.
The “Contagious Interview” campaign, discovered by Palo Alto Networks in 2023, evolved into the “ClickFake Interview” operation by 2025, expanding targeting beyond developers to non-technical roles.
Attackers now leverage ChatGPT and DeepSeek to automate social engineering, develop malware, and enhance operational efficiency.
The DPRK has dispatched between 1,500 and 3,200 IT workers globally, generating an estimated USD 350–800 million annually.
These workers infiltrate legitimate companies across artificial intelligence, blockchain, web development, and defense sectors by creating synthetic identities using AI-generated faces and forged credentials.
They obtain positions through platforms including Upwork, Freelancer, Fiverr, LinkedIn, and Discord, using VPN services to conceal locations and cryptocurrency payments to avoid detection.
Critically, the MSMT report documents increasingly blurred boundaries between IT workers and APT groups.
Some workers assist cyber units in vulnerability identification, database management, and even malware deployment, while others intentionally infiltrate defense and AI companies to gather technical intelligence for future operations.
DPRK cyber actors employ complex multi-stage laundering processes involving blockchain bridges, decentralized exchanges, cryptocurrency mixers, and peer-to-peer traders.
Between 2023 and 2024, Temp.Hermit exploited vulnerabilities in widely used South Korean authentication software to spread malicious code.
The MSMT findings underscore that DPRK operations now constitute integrated campaigns combining IT infiltration, supply chain compromise, on-chain theft, and cross-border money laundering.
Stolen assets move through a deliberate sequence: swapping into ETH and BTC, mixing through services like Tornado Cash and Wasabi Wallet, bridging across blockchains, and ultimately converting to fiat currency through OTC brokers in jurisdictions including Cambodia.
The DPRK’s First Credit Bank has utilized U.S. financial services companies to convert USD into renminbi while maintaining reserves across dozens of cryptocurrency wallets.
Organizations across exchanges, wallets, custodial services, and development teams must implement zero-trust architectures, enhanced background verification, supply chain security audits, and continuous threat intelligence monitoring to counter this persistent and evolving threat landscape.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…