OFAC and South Korea’s Ministry of Foreign Affairs Sanction Entities Associated with North Korean Hacking and IT Workers’ Crypto Payment Systems

[ad_1]

On May 23, 2023, the U.S. Treasury’s Office of Foreign Assets Control (OFAC) and the South Korean Ministry of Foreign Affairs (MOFA) announced sanctions against several entities and individuals associated with illicit revenue-generating programs in Korea. North.

Three North Korean organizations have been sanctioned for their role in North Korean hacking activities, including the 110th Research Center and its parent agency, the Technical Reconnaissance Bureau. Together, these two organizations oversee and support the hacking activity of units like Lazarus Group, which are responsible for much of the cryptocurrency hacking activity we have tracked over the past few years. Notably, OFAC states in its press release that the 110th Research Center was behind the 2013 DarkSeoul malware attack on South Korean government agencies, confirming the longstanding suspicions of many members of the cybersecurity community.

OFAC and MOFA also sanctioned Chinyong Information Technology Cooperation Company, also known as Jinyong IT Cooperation Company, and its employee, Sang Man Kim, for their role in helping North Korean IT professionals find contracts abroad, part of which is sent back to the North. Korea to support its weapons development programs. OFAC and MOFA have included cryptocurrency addresses in their designations related to this activity, and do explore their activity in more detail below.

Chinyong IT and Sang Man Kims crypto activity tracking

OFAC has previously discussed the role of North Korean computer scientists in generating revenue for the country’s weapons program. Generally speaking, IT companies controlled by the North Korean government help workers find jobs in foreign companies, usually in the tech industry, but sometimes even in crypto companies that use fake documents to conceal their true citizenship. . In many cases, workers receive their wages directly in cryptocurrency, which is then funneled back to North Korea.

Chinyong IT is one such government-controlled IT company, and OFAC describes Sang Man Kim as an employee of its office in Vladivostok, Russia. According to OFAC, Chinyong has helped North Korean IT workers find jobs in Russia and Laos in particular, with Kim helping funnel funds to North Korea. Analysis of the addresses controlled by Kim and Chinyong IT gives us insight into this process.

In total, OFAC lists six cryptocurrency addresses associated with Kim, all of which are deposit addresses at a major mainstream exchange. Some of these addresses are Ethereum addresses that have also transacted using Tether and USDC ERC-20 tokens, which is why eight deposit addresses are shown below. MOFA also identified an additional address as belonging to the Chinyong IT organization. We can see some of the activity associated with these addresses below.

Kims’ exchange deposit addresses received over $28 million worth of cryptocurrency between 2021 and 2022, but are currently not active. As we see above, these funds come from a variety of sources, including mainstream exchanges, mixers, and DeFi protocols. Funds typically travel from these services to Kim via intermediary personal wallets, including the personal wallet that MOFA today identified as belonging to Chinyong IT.

From the information we have, it is unclear how all of these transactions fit together. For example, it’s possible that individual IT workers were paid in fiat currency, exchanged for cryptocurrency in services like those seen on the left side of our Reactor chart, and then funneled the funds to Kim. It is also possible that IT workers were paid directly in cryptocurrency. In this case, payments sent by crypto firms on the left side of the chart to personal wallets may represent payments made to North Korean IT people they were duped into hiring. It is also possible that the graph contains instances of both transaction streams. Either way, it’s clear that all the funds eventually moved to Kim’s exchange deposit addresses, where he presumably converted them to fiat.

Sanctions key to stopping North Korea’s abuse of cryptocurrency ecosystem

Sanctions like these are crucial to combating North Korea’s cryptocurrency mining. And while most analysis of North Korea’s cryptocurrency activity focuses on hacking, these sanctions have also shed light on North Korea’s cryptocurrency hacking schemes, which have also proven to be lucrative. . Finally, this series of sanctions, the result of collaboration between American and South Korean agencies, also shows the importance of international cooperation in the fight against this activity.

We commend OFAC and MOFA for their work here, and will label any addresses they have identified as being associated with sanctioned entities in our products.

This material is provided for informational purposes only and is not intended to provide legal, tax, financial or investment advice. Beneficiaries should consult their own advisors before making such decisions. Chainalysis has no responsibility for any decision made or any other act or omission in connection with the use of this material by Recipients.

Chainalysis does not warrant or guarantee the accuracy, completeness, timeliness, adequacy or validity of the information contained in this report and shall not be liable for any claims attributable to errors, omissions or other inaccuracies of any part of this material.

Sources

1/ https://Google.com/

2/ https://blog.chainalysis.com/reports/ofac-north-korea-sanctions-may-2023/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts