{"id":25636,"date":"2025-07-10T22:49:56","date_gmt":"2025-07-10T19:49:56","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=25636"},"modified":"2025-07-10T22:49:59","modified_gmt":"2025-07-10T19:49:59","slug":"us-treasury-sanctions-north-korea-for-it-worker-malware-plot","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/25636\/us-treasury-sanctions-north-korea-for-it-worker-malware-plot\/","title":{"rendered":"US Treasury Sanctions North Korea for IT Worker Malware Plot"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; The U.S. Treasury sanctioned North Korean cyber operative Song Kum Hyok for using fake identities to infiltrate U.S. companies and fund Pyongyang\u2019s weapons programs.<br>&#8211; Song facilitated overseas IT workers with falsified documents to secure remote jobs, funneling earnings back to North Korea for military development.<br>&#8211; Stolen personal data, including Social Security numbers, was used to create fake aliases for operatives between 2022 and 2023.<br>&#8211; Five additional entities tied to the operation were blacklisted, freezing U.S. assets and banning American businesses from engaging with them.<br>&#8211; The crackdown aims to disrupt North Korea\u2019s cybercrime revenue streams financing weapons programs, following recent raids on IT worker networks.<\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>he <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/u-s-treasury\/\" class=\"acp-entity-link\" data-entity-id=\"54442\" data-entity-category=\"Organization\" title=\"Learn more about U.S. Treasury\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. Treasury<\/a><\/strong> has sanctioned a <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/north-korean\/\" class=\"acp-entity-link\" data-entity-id=\"46933\" data-entity-category=\"Location\" title=\"Learn more about North Korean\" target=\"_blank\" rel=\"noopener noreferrer\">North Korean<\/a> cyber operative<\/strong> at the center of a covert scheme that used <strong>fake identities<\/strong> to sneak operatives into American companies and quietly funnel wages back to <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/pyongyang\/\" class=\"acp-entity-link\" data-entity-id=\"54446\" data-entity-category=\"Location\" title=\"Learn more about Pyongyang\" target=\"_blank\" rel=\"noopener noreferrer\">Pyongyang<\/a>\u2019s weapons programs<\/strong>. The target, <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/song-kum-hyok\/\" class=\"acp-entity-link\" data-entity-id=\"54444\" data-entity-category=\"Person\" title=\"Learn more about Song Kum Hyok\" target=\"_blank\" rel=\"noopener noreferrer\">Song Kum Hyok<\/a><\/strong>, is identified as a key figure in <strong>Andariel<\/strong>, a hacking group notorious for <strong><a href=\"https:\/\/digitrendz.blog\/z\/topic\/ransomware-attacks\/\" class=\"acp-topic-link\" data-topic-id=\"16975\" title=\"Explore: ransomware attacks\" target=\"_blank\" rel=\"noopener noreferrer\">ransomware attacks<\/a><\/strong> and <strong>crypto thefts<\/strong> that help bankroll North Korea\u2019s military ambitions.<\/p>\n\n<p class=\"wp-block-paragraph\">According to investigators, <strong>Song supplied falsified U.S. documents<\/strong> to overseas IT workers, mainly based in <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/china\/\" class=\"acp-entity-link\" data-entity-id=\"1912\" data-entity-category=\"Location\" title=\"Learn more about China\" target=\"_blank\" rel=\"noopener noreferrer\">China<\/a> and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/russia\/\" class=\"acp-entity-link\" data-entity-id=\"253\" data-entity-category=\"Place\" title=\"Learn more about Russia\" target=\"_blank\" rel=\"noopener noreferrer\">Russia<\/a><\/strong>, letting them land <strong>remote jobs with unsuspecting U.S. employers<\/strong>. A slice of each paycheck reportedly flowed back to fund <strong>weapons of mass destruction<\/strong> and <strong><a href=\"https:\/\/digitrendz.blog\/z\/topic\/ballistic-missile-development\/\" class=\"acp-topic-link\" data-topic-id=\"42939\" title=\"Explore: ballistic missile development\" target=\"_blank\" rel=\"noopener noreferrer\">ballistic missile development<\/a><\/strong>. Some workers did more than collect salaries, they quietly planted <strong>malware<\/strong> on corporate networks, opening doors for future hacks.<\/p>\n\n<p class=\"wp-block-paragraph\">Between <strong>2022 and 2023<\/strong>, Song\u2019s network used <strong>stolen Social Security numbers and addresses<\/strong> to craft credible aliases. The Treasury\u2019s <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/office-of-foreign-assets-control\/\" class=\"acp-entity-link\" data-entity-id=\"47771\" data-entity-category=\"Organization\" title=\"Learn more about Office of Foreign Assets Control\" target=\"_blank\" rel=\"noopener noreferrer\">Office of Foreign Assets Control<\/a> (OFAC)<\/strong> also blacklisted <strong>five additional entities<\/strong>, including <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/gayk-asatryan\/\" class=\"acp-entity-link\" data-entity-id=\"54450\" data-entity-category=\"Person\" title=\"Learn more about Gayk Asatryan\" target=\"_blank\" rel=\"noopener noreferrer\">Gayk Asatryan<\/a><\/strong>, a <strong>Russian national<\/strong> who hired North Korean IT staff through his companies.<\/p>\n\n<p class=\"wp-block-paragraph\">Under the sanctions, all <strong>U.S.-based assets<\/strong> belonging to these parties are frozen, and <strong>American businesses<\/strong> are barred from any dealings. <strong>Foreign banks<\/strong> that continue to do business with the blacklisted network could face penalties too.<\/p>\n\n<p class=\"wp-block-paragraph\">This crackdown ties into a wider <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/justice-department\/\" class=\"acp-entity-link\" data-entity-id=\"11064\" data-entity-category=\"Organization\" title=\"Learn more about Justice Department\" target=\"_blank\" rel=\"noopener noreferrer\">Justice Department<\/a> push<\/strong> to dismantle <strong>North Korea\u2019s IT worker schemes<\/strong>. Earlier this month, federal agents raided <strong>29 so-called \u201c<a href=\"https:\/\/digitrendz.blog\/z\/topic\/laptop-farms\/\" class=\"acp-topic-link\" data-topic-id=\"42946\" title=\"Explore: laptop farms\" target=\"_blank\" rel=\"noopener noreferrer\">laptop farms<\/a>\u201d<\/strong>, makeshift offices where these operatives worked undercover. Those raids led to <strong>arrests<\/strong>, <strong>indictments<\/strong>, and the seizure of <strong>websites<\/strong> and <strong>financial channels<\/strong> used to hide the money trail.<\/p>\n\n<p class=\"wp-block-paragraph\">By blocking these <strong>cybercrime cash streams<\/strong>, Washington aims to squeeze Pyongyang\u2019s ability to keep building its banned weapons. The sanctions highlight how <strong>state-backed hacking groups<\/strong> increasingly exploit <strong>global hiring systems<\/strong> to launder money and fuel prohibited military projects<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/legal\/treasury-sanctions-north-korean-over-it-worker-malware-scheme\/\" target=\"_blank\">BLEEPINGCOMPUTER<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Treasury has imposed sanctions on a North Korean cyber operative involved in a sophisticated scheme using fake identities to infiltrate American companies and fund Pyongyang\u2019s weapons programs.** The move targets **Song Kum Hyok**, a key member of the **Andariel hacking group**, known for orchest&#8230;<\/p>\n","protected":false},"author":1,"featured_media":25635,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[3327],"tags":[37294,37295,37297,37298,37296],"entities":[37358,1322,37360,6449,32883,33433,37359,2371,37357,37356],"class_list":["post-25636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-newswire","tag-korea-for","tag-north-korea","tag-sanctions-north","tag-treasury-sanctions","tag-worker-malware","entity-andariel-hacking-group","entity-china","entity-gayk-asatryan","entity-justice-department","entity-north-korean","entity-office-of-foreign-assets-control","entity-pyongyang","entity-russia","entity-song-kum-hyok","entity-u-s-treasury"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/25636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=25636"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/25636\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/25635"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=25636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=25636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=25636"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=25636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}