Threat Intelligence

Hacker faux pas uncloaks North Korean IT worker scheme

North Korea digital technology flag cyber background. North Korean banner cyberattack and espionage concept illustration.

North Korea had one of its IT worker scams' secrets unravel after a hacker inadvertently executed information-stealing malware on their own computer, according to Cybernews.

Infostealer compromise of the hacker's computer enabled the exfiltration of data from an internal North Korean payment server with 390 accounts, chat logs, and cryptocurrency transactions that shed light on the scheme that raked in $1 million in monthly earnings for Pyongyang, noted independent blockchain investigator ZachXBT, who was given access to the stolen data, in a post on X. North Korean threat actors were also discovered to have been coordinating payments on a website that could be accessed with the "123456" password, which is shared among 10 users.

Additional findings revealed that the scam, which is operated by a state-backed cluster less sophisticated than AppleJeus and TraderTraitor, was associated with the Songkwang, Sobaeksu, and Saenal firms previously sanctioned by the U.S. Treasury Department's Office of Foreign Assets Control. North Korean state-backed attackers were noted by vx-underground to have divulged their infrastructure and operations via accidental infostealer execution once before.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds