DOJ Dismantles North Korea-Linked Crypto Theft Scheme, Defendants Stole Nearly $1M

2025/07/01 16:34

The US Department of Justice (DOJ) has charged four North Koreans for impersonating as remote IT workers and exploiting companies to steal crypto. The federal prosecutors noted that the operation could be a part of the DPRK strategy to fund its weapons program.

In a “cyber-enabled revenue generation network”, perpetrators landed in remote IT jobs using fake and stolen identities. The group exploited their company’s trust to steal and launder over $900,000 in crypto, the DOJ announcement read.

The federal prosecutors from the Northern District of Georgia have charged the defendants with a five-count wire fraud and money laundering indictment linked to the scheme.

“This indictment highlights the unique threat North Korea poses to companies that hire remote IT workers and underscores our resolve to prosecute any actor, in the United States or abroad, who steals from Georgia businesses,” said U.S. Attorney Theodore S. Hertzberg on Monday.

Fraudsters Target Georgia-Based Blockchain Firm, Serbian Crypto Company

The case is being handled by the Federal Bureau of Investigation (FBI) and is part of the DOJ’s ‘DPRK RevGen’ plan that targets high-impact North Korea-linked illicit revenue generation rings.

According to the investigation, the defendants initially operated as a team in the UAE in 2019. Between December 2020 and May 2021, these perpetrators joined a Georgia-based blockchain firm and a Siberian crypto company as developers.

“Both defendants concealed their North Korean identities from their employers by providing false identification documents containing a mix of stolen and fraudulent identity information,” the DOJ revealed.

In February 2022, two of the impersonated employers were assigned projects that provided them access to crypto. The defendants used that access to steal digital assets in two separate operations worth $175,000 and $740,000 at the time. They reportedly modified the source code of two employers’ smart contracts.

DPRK Crypto Attacks Magnify

North Korea has been developing novel and more sophisticated attacks on crypto firms in the recent past. In April, spies from the DPRK infiltrated the US corporate system to feed in a malware campaign targeting crypto developers.

They used fake US firms and domains to post job interviews to trick developers into downloading malware.

Another sophisticated method to steal crypto is via Zoom meetings, and hiding malware in GitHub. According to Nick Bax of the Security Alliance, a threat group is working to steal data and funds through fake business calls on Zoom.

The DPRK-linked players send messages in the chat saying they can’t hear audio, suggesting listeners click on a fake link.

Last week, reports revealed that North Korea is targeting Indian crypto job applicants with malware to steal their data.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Altcoin Season Breakout: SUI, ARB, GALA Jump 65-85% to Lead Q4 2025 Rally

Altcoin Season Breakout: SUI, ARB, GALA Jump 65-85% to Lead Q4 2025 Rally

Bitcoin and Ethereum may dominate crypto discourse, but the second half of 2025 is shaping up to reward a different class of assets that build quietly with utility as Altcoin season intensifies. As capital begins to rotate into tokens that combine infrastructure, governance, and usability, three underappreciated names are emerging: SUI, ARB, and GALA. These tokens are often ignored in mainstream narratives, yet their ecosystems, user metrics, and upcoming milestones position them for a potential breakout in Q3 and Q4. SUI: The Underestimated L1 Gaining Users Sui has developed a distinct approach among Layer 1 blockchains. Its object-based structure and parallel execution support faster, more scalable applications. Despite offering features such as zkLogin and sponsored gas to improve user experience, SUI remains less discussed compared to networks like Ethereum or Solana. Most infra today assumes you’re building alone. The Sui Stack assumes you’re building together – collaborating with users, data, other apps, and agents. It’s not just new plumbing. It’s a rethink of how software is supposed to work. Here’s how 👇 pic.twitter.com/vLk16yCmVe — Sui (@SuiNetwork) July 17, 2025 That may be changing. By mid-2025, total value locked (TVL) on Sui exceeded $580 million, based on DeFiLlama data. Activity in native DeFi platforms and early traction in GameFi are helping to build momentum. Applications like DeepBook and Navi Protocol are active on the network, while its Move-based development environment is attracting focused interest. With a market cap of over $13 billion and growing engagement levels, including 2.4 million interactions tracked by LunarCrush, Sui is seeing increased traction despite limited media focus. Sui is currently trading at $3.96 , 66% up from 30 days ago. ARB: A Governance Token Gaining Strategic Control Arbitrum remains the leading Ethereum Layer 2 network by TVL, yet the ARB token has not reflected that strength in its valuation. As of July 2025, ARB has a $2.5 billion market cap, even though Arbitrum secures over $14 billion in assets and handles large volumes across its applications. The difference now is the role of governance. Token holders are actively directing ecosystem decisions through the Arbitrum DAO, including a recent $200 million allocation to support gaming development. The rollout of Stylus, an upgrade allowing the use of programming languages like Rust and C++, may encourage broader participation from developers. As protocol use continues to expand and the DAO’s treasury oversight grows more visible, ARB may start reflecting its broader network influence. Arbitrum (ARB) has seen an 85% increase in the past month, driven by Altcoin season, and is trading at $0.48 now. GALA: From Speculative Token to Platform Asset GALA, once widely traded during the 2021 cycle, has shifted focus to building a structured Web3 ecosystem. The token now supports multiple functions across Gala Games, including in-game payments , NFT activity, and node infrastructure. While media attention has faded since its early surge, development within the platform continues. Mirandus is FREE to play until July 28th! No Exemplar? No problem. Enter the realm as a Hollow and explore a world of magic, monsters, and fortune. Your adventure begins now → https://t.co/iqj9B7dV9q #Mirandus #GalaGames pic.twitter.com/gKsvssV0Zh — Gala Games (@GoGalaGames) July 18, 2025 In 2025, games such as Mirandus and Legends Reborn are nearing release, while Gala Film and Gala Music are gaining support from creators. GalaChain is being steadily decentralized, and node activity is expanding. GALA now has a market cap of around $900 million. Still, community interaction is climbing. July saw 265,000 engagements and nearly 4,000 social mentions. If the broader GameFi sector sees renewed interest, Gala’s multi-application approach may gain new relevance. The price of GALA has surged by 65% over the past 30 days and is currently trading at $0.02. The Case for Asymmetric Upside SUI, ARB, and GALA offer practical utility with limited exposure. While the market continues to focus on major tokens, these projects are seeing measurable progress in development and user participation. If capital continues shifting toward use-case-driven assets during Altcoin season , these under-recognized names could benefit from renewed interest in the months ahead.
Share
CryptoNews2025/07/23 01:21