North Korea’s IT Worker Scam: U.S. Treasury Sanctions Cyber Espionage Mastermind

The U.S. Treasury has sanctioned cyber actor Song Kum Hyok for hacking antics with North Korea’s Andariel group, a sub-cluster of the Lazarus group. Song’s side gig included providing fake identities to foreign IT workers, who split their U.S. earnings with him, fueling North Korea’s missile dreams.

Pro Dashboard

Hot Take:

It seems North Korea’s guiding career advice for hackers is: “Fake it till you make it… and fund our weapons program!” The U.S. Treasury apparently disagrees with this unconventional résumé-building strategy and has decided to give Mr. Song Kum Hyok an unforgettable ‘career setback’ with a side of sanctions.

Key Points:

  • Song Kum Hyok, a member of North Korea’s hacking group Andariel, was sanctioned by the U.S. Treasury for his role in IT worker schemes.
  • Andariel, linked to the Lazarus group, is known for financially-motivated cyber activities such as ransomware and cryptocurrency theft.
  • Song provided fake U.S. identities to foreign IT workers, sending their earnings back to North Korea to fund its weaponry programs.
  • The U.S. Treasury sanctioned several associated entities, freezing assets and banning transactions with them.
  • Recent U.S. actions included raids on 29 “laptop farms,” resulting in arrests, indictments, and multiple seizures.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?