ZachXBT reveals North Korea's IT team using fake identities and cross-border accounts to launder over $3.5 million in crypto assets

robot
Abstract generation in progress

ME News Report, April 8th (UTC+8), according to on-chain investigator ZachXBT, a North Korean IT worker’s device was infected with malware, leading to the leak of internal payment server data involving approximately 390 accounts, chat logs, and encrypted transactions.
The leaked data shows that the North Korean IT team reported income through the internal platform luckyguys.site, using numerous forged identities and fake legal documents to transfer cryptocurrency from exchanges or other services into wallets controlled by an administrator account “PC-1234,” then converting to fiat currency via Bank of China accounts and platforms like Payoneer.
Since November 2025, the related addresses have received over $3.5 million, with one Tron address being frozen by Tether in December 2025.
ZachXBT also published the organizational structure, payment details, and some publicly accessible addresses of the network.
(Source: PANews)

TRX0.73%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin