Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

ZachXBT Publishes Leaked DPRK Payment Data Showing $1M Monthly Crypto-to-Fiat Pipeline

CN
bitcoin.com
Follow
4 hours ago
AI summarizes in 5 seconds.
  • ZachXBT’s April 8 investigation exposed a DPRK IT worker payment server that processed over $3.5 million since late November 2025.
  • Three OFAC-sanctioned entities, Sobaeksu, Saenal, and Songkwang, appeared in the breached user list from luckyguys.site.
  • The internal DPRK site went offline on April 9, 2026, but ZachXBT archived all data before publishing the 11-part thread.

The leaked data came from a DPRK IT worker’s device compromised by infostealer malware. An unnamed source shared the files with ZachXBT, who confirmed the material had never been publicly released. The extracted records included approximately 390 accounts, IPMsg chat logs, fabricated identities, browser history, and cryptocurrency transaction records.

The internal platform at the center of the investigation was luckyguys.site, also referred to internally as WebMsg. It functioned as a Discord-style messenger, allowing DPRK IT workers to report payments to their handlers. At least ten users had never changed the default password, which was set to “123456.”

The user list contained roles, Korean names, cities, and coded group names consistent with known DPRK IT worker operations. Three companies appearing in the list, Sobaeksu, Saenal, and Songkwang, are currently sanctioned by the U.S. Treasury’s Office of Foreign Assets Control.

Payments were confirmed through a central admin account identified as PC-1234. ZachXBT shared direct message examples from a user nicknamed “Rascal,” which detailed transfers tied to fraudulent identities spanning December 2025 through April 2026. Some messages referenced Hong Kong addresses for bills and goods, though their authenticity was not verified.

The associated payment wallet addresses received more than $3.5 million during that period, equating to roughly $1 million per month. Workers used forged legal documents and fake identities to obtain employment. Crypto was either transferred directly from exchanges or converted to fiat through Chinese bank accounts using platforms like Payoneer. The admin account PC-1234 then confirmed receipt and distributed credentials for various crypto and fintech platforms.

Onchain analysis tied the internal payment addresses to known clusters of DPRK IT workers. Two specific addresses were identified: an Ethereum address and a Tron address that Tether froze in December 2025.

ZachXBT used the full dataset to map the complete organizational structure of the network, including payment totals per user and per group. He published an interactive org chart covering December 2025 through February 2026 at investigation.io/dprk-itw-breach, accessible with the password “123456.”

The compromised device and chat logs produced additional details. Workers used Astrill VPN and fake personas to apply for jobs. Internal Slack discussions included a post from a user named “Nami” sharing a blog about a DPRK worker deepfake applicant. The admin also sent 43 Hex-Rays and IDA Pro training modules to workers between November 2025 and February 2026, covering disassembly, decompilation, and debugging. One shared link specifically addressed unpacking hostile PE executables.

Thirty-three DPRK IT workers were found communicating through the same IPMsg network. Separate log entries referenced plans to steal from Arcano, a GalaChain game, using a Nigerian proxy, though the outcome of that effort was not clear from the data.

ZachXBT characterized this cluster as less operationally sophisticated than higher-tier DPRK groups such as Applejeus or Tradertraitor. He previously estimated that DPRK IT workers collectively generate multiple seven figures per month. He noted that low-tier groups like this one attract threat actors because the risk is low and competition is minimal.

The luckyguys.site domain went offline on Thursday, the day after ZachXBT published his findings. He confirmed the full dataset was archived before the site was taken down.

The investigation offers a direct view into how DPRK IT worker cells collect payments, maintain fake identities, and move money through crypto and fiat systems, with documentation that shows both the scale and the operational gaps these groups rely on to stay active.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

注册即分47万U奖池
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by bitcoin.com

18 minutes ago
Galaxy Digital Files First Nasdaq Annual Report, Targets $15 Billion AI Data Center Expansion
1 hour ago
Iran Limits Strait of Hormuz to 15 Ships Per Day Under US Ceasefire Deal
1 hour ago
Bitcoin Price Prediction Markets Show $100K Odds at 12% for 2026, Data Reveals
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarbitcoin.com
18 minutes ago
Galaxy Digital Files First Nasdaq Annual Report, Targets $15 Billion AI Data Center Expansion
avatar
avatarbitcoin.com
1 hour ago
Iran Limits Strait of Hormuz to 15 Ships Per Day Under US Ceasefire Deal
avatar
avatarbitcoin.com
1 hour ago
Bitcoin Price Prediction Markets Show $100K Odds at 12% for 2026, Data Reveals
avatar
avatarbitcoin.com
2 hours ago
Treasury Launches Cybersecurity Initiative Expanding Threat Intelligence Access for Digital Asset Firms
avatar
avatarbitcoin.com
2 hours ago
Treasury Secretary Pushes Clarity Act to Secure US Crypto Market Leadership
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink