The post ZachXBT Exposes Internal Data of North Korean IT Workers, Reveals $3.5M Transactions appeared on BitcoinEthereumNews.com. ZachXBT exposed internal dataThe post ZachXBT Exposes Internal Data of North Korean IT Workers, Reveals $3.5M Transactions appeared on BitcoinEthereumNews.com. ZachXBT exposed internal data

ZachXBT Exposes Internal Data of North Korean IT Workers, Reveals $3.5M Transactions

2026/04/09 04:19
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

ZachXBT exposed internal data from North Korean IT workers today, detailing a $3.5 million crypto flow since late 2025. According to ZachXBT, the dataset came from a compromised device and includes 390 accounts, chat logs, and transaction records. The findings reveal how workers used fake identities, weak security, and coordinated systems to process roughly $1 million monthly.

ZachXBT Uncovers Internal Payment System

According to ZachXBT in a detailed X thread, an unnamed source provided data extracted from an internal payment server used by North Korean DPRK IT workers. The dataset includes chat logs from IPMsg, account lists, and browser histories tied to fraudulent operations. Users discussed a platform called luckyguys[.]site, described as a remittance hub.

The system functioned as both a messaging tool and a reporting channel. Workers submitted earnings and received instructions through this platform. However, weak security exposed the system, as several accounts used the default password “123456” without changes.

User records listed Korean names, cities, and coded group identifiers. Additionally, three entities; Sobaeksu, Saenal, and Songkwang, appeared in the data. These companies are currently under OFAC sanctions, linking the network to previously identified operations.

Transaction Patterns Reveal $3.5M Flow

Transaction logs show a consistent movement of funds across the network. According to ZachXBT, users transferred crypto from exchanges or services before converting it into fiat. In many cases, workers used Chinese bank accounts and platforms like Payoneer for off-ramping.

An administrative account identified as PC-1234 confirmed payments and distributed account credentials. These credentials varied between crypto exchanges and fintech platforms depending on user needs. Since November 2025, tracked wallet addresses have processed over $3.5 million.

Blockchain tracing linked several payment addresses to known DPRK. One Tron wallet was frozen by Tether in December 2025. This action indicates limited intervention by industry participants as per ZachXBT.

Fake Identities, Training, and Coordination

The dataset also outlines how workers secured remote jobs using fabricated identities. According to ZachXBT, compromised device data revealed fake personas, job applications, and browser activity. 

Workers relied on tools like Astrill VPN to mask locations during these operations. This new investigation comes after ZachXBT called out Circle over $285M Drift Protocol exploit delay. In the new report, internal chats showed coordination across multiple platforms. 

In one instance, 33 workers communicated through IPMsg on the same network. Additionally, Slack discussions referenced a blog about deepfake job applicants. Meanwhile, some conversations suggested planned theft attempts. 

One user discussed targeting a GalaChain project called Arcano through a Nigerian proxy. However, the data does not confirm whether the attack occurred. Training materials circulated widely within the group. 

The admin shared 43 modules covering reverse engineering topics, including Hex-Rays and IDA Pro. These sessions focused on disassembly, debugging, and malware analysis, indicating ongoing technical development within the network.

Source: https://coingape.com/zachxbt-exposes-internal-data-of-north-korean-it-workers-reveals-3-5m-transactions/

Piyasa Fırsatı
FLOW Logosu
FLOW Fiyatı(FLOW)
$0.03278
$0.03278$0.03278
+1.54%
USD
FLOW (FLOW) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!