The DPRK’s Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities

2025-11-25 Slowmist

https://slowmist.medium.com/explanation-msmt-the-dprks-violation-and-evasion-of-un-sanctions-via-cyber-and-it-worker-e2a674d3a2c5

Thumbnail for The DPRK’s Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities

MSMT’s findings, summarized by SlowMist, state that the DPRK used cyber operations, cryptocurrency theft, overseas IT workers, front companies, and intermediaries to evade UN sanctions and raise funds for weapons programs. The excerpt says DPRK-linked cryptocurrency theft reached at least USD 1.19 billion in 2024 and USD 1.645 billion from January to September 2025, including TraderTraitor activity against Bybit, DMM Bitcoin, and WazirX. It describes multiple DPRK-linked clusters and workers using social engineering, fake recruitment, malicious NPM packages, cryptocurrency software, supply chain intrusions, and malware such as BeaverTail and InvisibleFerret to target cryptocurrency firms and workers. The report matters for defenders because it connects revenue generation, espionage, IT-worker fraud, and laundering infrastructure into a state-level sanctions-evasion ecosystem.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN thispersondoesntexist.com 2025-11-25 2025-11-25

Related Actors

Related Reports

« Back