North Korean Hackers Infiltrated Companies as Fake IT Workers, Stole Millions from Crypto Projects
Cybersecurity researchers have uncovered a sophisticated operation in which North Korean hackers assumed false identities to infiltrate technology companies as legitimate IT employees. Their primary targets were cryptocurrency projects, and they managed to siphon off substantial sums on a monthly basis. A newly released investigation reveals that this group was generating approximately one million dollars each month—equivalent to roughly 93 lakh Indian rupees—through a well-coordinated scheme. In total, the hackers accumulated over 3.5 million dollars, which translates to more than 3.25 crore rupees.
How the Scheme Was Exposed
The entire network came to light after a North Korean operative known by the alias “Jerry” fell victim to an info-stealing malware attack on his personal device. An unidentified source managed to extract sensitive data from that device, including private chat logs, forged identification documents, and detailed browser history. This digital footprint revealed the extent of the fraud, showing that the group had been manipulating legal paperwork and fabricating identities to secure employment in various firms.
A Weak Password for a Major Operation
The hackers coordinated their efforts through a secret website called luckyguys.site. This platform served as a hub for communication, planning, and task allocation among group members. Despite the scale of their criminal enterprise—which involved stealing millions of dollars—the site’s shared password was astonishingly weak: simply “123456.” Investigators also discovered that several individuals within this group were linked to organizations already sanctioned by the United States government, including Sobaeksu, Saenal, and Songkwang.
Money Laundering via Multiple Channels
To hide their tracks and convert stolen assets into usable currency, the hackers followed a carefully designed process. They first exchanged the pilfered cryptocurrency into fiat money. From there, they funneled these funds through online payment platforms such as Payoneer, eventually transferring the money into Chinese bank accounts. The group used messaging applications like Discord to submit real-time reports on their activities and maintain contact with their handlers, ensuring seamless coordination across different time zones.
An Internal Leaderboard and Fake Job Applications
Remarkably, the hackers maintained an internal leaderboard on their website. This system tracked the earnings generated by each member after December 8, 2025, complete with blockchain transaction links as proof of their illicit gains. The lengths these fraudsters went to conceal their identities is illustrated by two specific cases. “Jerry” submitted a fraudulent job application to a T-shirt company based in Texas, claiming expertise in WordPress and SEO. Meanwhile, another operative named “Rascal” shared fake billing documents with a Hong Kong address along with a photograph of an Irish passport. These examples demonstrate how the group attempted to infiltrate businesses across the globe using fabricated personas.
A Long History of Crypto Theft
This operation is not an isolated incident. Security agencies have been tracking North Korean IT workers for years. According to data compiled by security researcher Taylor Monnahan, these hackers have been systematically breaching decentralized finance platforms for the past seven years. Since 2017, they have stolen more than 7 billion dollars—roughly 65 thousand crore rupees—in cryptocurrency. Their capabilities are further underscored by their involvement in the high-profile Drift Protocol hack, which resulted in losses of 285 million dollars, or about 2,600 crore rupees. This latest report serves as a stark reminder of the persistent and evolving threat posed by state-sponsored cybercriminals operating under false identities.
