On-Chain Tracking | US Further Cracks Down on North Korean IT Worker Fraud Network Using Cryptocurrency to Fund Weapons of Mass Destruction, Sanctions 6 Individuals and 2 Entities

Odaily星球日报Publicado em 2026-03-14Última atualização em 2026-03-14

Resumo

On March 12, the U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned six individuals and two entities involved in a Democratic People’s Republic of Korea (DPRK)-led IT worker fraud network. The scheme defrauded U.S. companies to fund DPRK’s weapons of mass destruction programs, with nearly $800 million involved in 2024 alone. The sanctioned individuals facilitated cryptocurrency exchange, money laundering, and IT operations for DPRK IT workers who used fake identities to infiltrate companies. Two entities, Amnokgang and Quangvietdnbg, were key operators. OFAC identified 21 cryptocurrency addresses linked to the network. One individual exchanged approximately $2.5 million in crypto for DPRK operatives. Chain analysis revealed significant outflows to various exchanges, including over 200,000 USDT and substantial amounts of Ethereum, Tether, and TRX. This action underscores ongoing efforts to combat DPRK’s use of crypto to evade sanctions and highlights the importance of robust anti-money laundering screening for virtual asset service providers.

On March 12, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) announced sanctions against 6 individuals and 2 entities involved in a North Korea-led IT worker fraud network. The announcement stated that these participants systematically defrauded U.S. companies to provide funding for weapons of mass destruction programs, with the amount involved in 2024 alone approaching $800 million.

https://home.treasury.gov/news/press-releases/sb0416

Sanctions Details

According to the U.S. OFAC disclosure, North Korea-controlled IT teams used forged documents, stolen identities, and fabricated personas to conceal their true identities and gain employment at legitimate companies in the U.S. and other countries. The North Korean government seizes the vast majority of these overseas IT workers' salaries, obtaining hundreds of millions of dollars in funding to support its weapons of mass destruction and ballistic missile programs. In some cases, North Korean-linked personnel also secretly implanted malicious software into corporate networks to steal proprietary and sensitive information.

This round of sanctions targets a total of 6 individuals (Nguyen Quang Viet, Do Pyong Kyong, Hoang Van Nguyen, Yun Song Guk, Hoang Minh Quang, York Louis Celestino Herrera), identified as providing substantial assistance to North Korean IT workers through cryptocurrency exchange, money laundering, bank account opening, IT business对接 (liaison), etc.; and 2 corporate entities (Amnokgang, Quangvietdnbg), identified as key operators and facilitators of the IT worker fraud network.

Sanctioned Address Analysis

This sanctions action locked a total of 21 cryptocurrency addresses. According to the OFAC notification, from mid-2023 to mid-2025, Quangvietdnbg's CEO Nguyen Quang Viet exchanged approximately $2.5 million worth of cryptocurrency for the North Korean side, identifying cryptocurrency as a key channel for North Korean IT workers to transfer funds and evade sanctions.

Analysis was conducted on these 21 addresses using the on-chain anti-money laundering analysis platform Beosin KYT and the tracking investigation tool Beosin Trace, with results as follows:

YUN, Song Guk (North Korean national, head of IT workers in Boten, Laos)

ETH:

0xb637f84b66876ebf609c2a4208905f9ddac9d075

0x95584C303FCd48AF5c6B9873015f2AD0ca84EaE3

According to Beosin Trace statistics, approximately 200,851 USDT previously flowed out to various centralized exchanges.

HOANG, Minh Quang (Collaborated to complete IT service transactions exceeding $70,000)

BTC: bc1qyy5pt5cx3zth8xlj92lq5y87dh8xv3nwgs4ncq

Previously, 0.57462 BTC flowed into a Coinbase account.

SIM, Hyon Sop (Representative of North Korea's Kwangsong Bank in China, 11 new addresses added)

Originally frozen address (ETH network):

0x4f47bc496083c727c5fbe3ce9cdf2b0f6496270c

This address had a liquid flow volume of 21,937,732.52 USDT and 2,071,126.59 USDC. Currently, 58,148.62 USDT remains dormant at this address.

Newly sanctioned addresses (ETH network):

0xd04E33461FEA8302c5E1e13895b60cEe8AEfda7F

0x76EA76CA4Eb727f18956aB93445a94c5280412B9

0xFb3eFf152ea55D1BfA04Dbdd509A80fD7b72cdEB

0xFda1Ec4A6178d4916b001a065422D31EBE5F62FF

0x747AFB5c7A7fc34B547cD0FDEbf9b91759C5a52b

Fund flow diagram as follows:

Approximately 98,139.11 USDT, 21,300 USDC, and 0.51268 ETH flowed out.

New TRX addresses:

TPDLpXxPcaSsupEZ3yrVksmNkYP5SLeKxu

TGXE9dGWawjfd3xqFSho1h1bRbRv9wUGrF

TNTFhgFoKH4srBMiWbfrVFqP2AThSmdwf1

TXhf9nU9bjo1j9z5qEesHdr6gtdndfnA4T

TK17wfSPp32RWrnzZPrGpv7TxdNFvvvE2s

TYeQD2VddTZ9NkFkAnT9DD8cUGetGUQZB2

Approximately 6,236.74 TRX and 999,014.46 USDT flowed out.

Same address cross-chain:

ARB: 0x4f47bc496083c727c5fbe3ce9cdf2b0f6496270c

BSC: 0x4f47bc496083c727c5fbe3ce9cdf2b0f6496270c

1,133,025.26 USDT, 935,943.84 BUSD, and 17,811.05 USDC flowed out to various centralized exchanges.

AMNOKGANG TECHNOLOGY DEVELOPMENT COMPANY

ETH:

0xcB74874f1e06Fcf80A306e06e5379A44B488bA2D

0x0330070FD38Ec3bB94F58FA55D40368271E9e54A

0x9Be599d7867f5E1a2D7Ec6dB9710dF2b98A15573

A total of approximately 205.02 ETH, 274,531.15 USDT, and 228,496.97 USDC were involved. Among these, 96.05 ETH remains dormant in address 0x9be599d7867f5e1a2d7ec6db9710df2b98a15573.

Tron network

TNrX2FwrHKoo4XACGkmSzqeK4pdnKYn6Z7

TEEYCuGDyeNkuDj4u6GQRXxXo3Nh29r2vP

TZB4NrX7k9ZsV6PRc1GigAztLL8WHpLvwP

TDe2UNAvuUnTbbDo7518eMe3TXN5qJW8Ft

2,744.75 TRX and 4,941,817.62 USDT flowed out to various centralized exchanges.

Beosin Anti-Money Laundering Recommendations

This action is another measure by the U.S. Treasury Department to continuously combat North Korea's use of cryptocurrency to evade sanctions. For the virtual asset industry, how to conduct anti-money laundering compliance screening and identify addresses involved in high-risk funds has become a key capability for Virtual Asset Service Providers (VASPs).

Perguntas relacionadas

QWhat action did the U.S. Treasury's OFAC take on March 12 regarding North Korean IT workers?

AThe U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned 6 individuals and 2 entities involved in a North Korean-led IT worker fraud network.

QHow much money was involved in the fraudulent activities in 2024, according to the OFAC announcement?

AThe amount involved in the fraudulent activities in 2024 was nearly $800 million.

QWhat was the primary purpose of the funds obtained by the North Korean government through these IT workers?

AThe North Korean government seized the vast majority of the overseas IT workers' salaries to obtain hundreds of millions of dollars in funding for its weapons of mass destruction and ballistic missile programs.

QHow many cryptocurrency addresses were sanctioned in this action, and which platform was used to analyze them?

AA total of 21 cryptocurrency addresses were sanctioned. They were analyzed using the Beosin KYT on-chain anti-money laundering analysis platform and the Beosin Trace investigation tool.

QWhat key capability is mentioned as crucial for Virtual Asset Service Providers (VASPs) in light of these actions?

AFor Virtual Asset Service Providers (VASPs), the key capability mentioned is conducting anti-money laundering compliance screenings to identify addresses involved with high-risk funds.

Leituras Relacionadas

a16z: From Companies to DAOs, DUNA May Become the Next Generation Organizational Form

This article, "From Companies to DAOs: How DUNA Could Become the Next Organizational Form," traces the 500-year evolution of business collaboration. It begins with medieval structures like the *commenda* and Florentine *compagnia*, which exposed partners to personal risk. The modern corporation, exemplified by the Dutch East India Company (VOC), was a revolutionary leap, enabling large-scale, capital-intensive ventures by offering limited liability and reducing coordination costs. However, corporations introduced new challenges like principal-agent problems and bureaucratic overhead. The piece argues that software and internet-native protocols are now reducing these traditional overheads. Decentralized Autonomous Organizations (DAOs) emerged as a new model for coordination without centralized management. Yet, DAOs face a significant legal vacuum: they lack legal recognition, leaving members exposed to unlimited personal liability, and their tokens are vulnerable to being classified as securities under unclear regulations (e.g., the Howey Test). This has forced projects into suboptimal workarounds like offshore foundations. The article identifies the Decentralized Unincorporated Nonprofit Association (DUNA) as a potential solution. Recently legalized in states like Wyoming, the DUNA provides a legal wrapper for decentralized networks. It grants key protections—legal personality, limited liability, and perpetual existence—to a group without imposing a traditional hierarchical management structure. This allows token-holder communities to govern, hold assets, and contract as a single legal entity, aligning with their decentralized nature. While DUNA doesn't solve all governance challenges or magically resolve securities law questions, it represents a crucial step. It fills the legal recognition gap, offering a native legal form for internet-scale, decentralized collaboration and extending the separation of personal risk from organizational venture into a new domain.

marsbitHá 1m

a16z: From Companies to DAOs, DUNA May Become the Next Generation Organizational Form

marsbitHá 1m

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

The 2026 Mid-Year Report on On-Chain RWA highlights a significant growth in tokenized stock market capitalization, which nearly doubled from $951 million in March to $1.89 billion by July. However, the report reveals a fundamental contradiction in this "layer 2.5" ecosystem: products with the strongest legal foundation (like regulated U.S. infrastructure) lack liquidity and distribution, while freely tradable offshored wrapper products often lack substantive ownership rights. The increase is driven largely by a few products (SECZ, FGRS, STRCx) and platforms (Ondo, xStocks, Securitize collectively hold over 85% share). While distributed value across networks like Ethereum, Solana, and BNB Chain has grown, the market remains fragmented. Products referencing the same underlying asset (e.g., Apple stock) are distinct legal liabilities with different intermediaries and jurisdictional rules, offering varying degrees of legal claim. The report cautions that headline numbers are misleading, as they reflect changes in distributed token value—driven by issuance, conversions, and price movements—not pure investor inflows. True "canonical shares" with legal ownership, wide wallet distribution, institutional liquidity, and independent on-chain price discovery do not yet exist at scale. Tokenized treasuries show stronger product-market fit, and ETFs may be easier to scale than single stocks. The core takeaway is a trade-off: legal certainty versus liquidity and composability.

marsbitHá 50m

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

marsbitHá 50m

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ruHá 3h

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ruHá 3h

Trading

Spot
活动图片