Wu reported that on-chain detective ZachXBT disclosed a leak of internal North Korea payment server data showing that its IT workers' network achieved approximately $1 million/month in revenue through methods such as impersonation and cryptocurrency-to-fiat conversions. Since November 2025, the related wallets have received over $3.5 million in total; the data involves 390 accounts and chat records, indicating that they used an internal platform for unified accounting, with funds confirmed and distributed by an administrator account PC-1234, and some entities have been sanctioned by OFAC. On-chain analysis shows that the related addresses are associated with known North Korean IT clusters, including a TRON address that was frozen by Tether in December 2025. The implementation details of some attack activities remain unclear.

TRX0.94%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments