Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

US Storms 29 Laptop Farms in Crackdown on North Korean IT Worker Schemes

Posted on July 1, 2025July 1, 2025 By CWS

The US Division of Justice on Monday introduced a nation-wide motion in opposition to pretend IT employee schemes funding the North Korean authorities.

Involving North Korean nationals fraudulently acquiring distant IT employment inside US corporations through the use of pretend or stolen identities, these schemes are estimated to have netted greater than $88 million over six years.

A whole bunch of US corporations are believed to have been duped into hiring North Korean IT staff, with People aiding these people to pose as US individuals by working laptop computer farms within the nation to disguise their location.

On Monday, the DOJ introduced a coordinated motion throughout 16 states that included searchers of 29 recognized and suspected laptop computer farms.

The motion resulted within the seizure of 29 monetary accounts laundering illicit proceeds from these schemes, the seizure of 21 web sites, one arrest, and two indictments.

As a part of one scheme, folks within the US, China, UAE, and Taiwan assisted North Koreans in acquiring employment at greater than 100 US corporations, by entrance corporations, fraudulent web sites and the internet hosting of laptop computer farms, court docket paperwork present.

Along with receiving common wage funds, the North Korean IT staff gained entry to and even stole delicate data, together with export-controlled US navy expertise and cryptocurrency.

In a single scheme, North Korean IT staff obtained employed by an Atlanta, Georgia-based blockchain analysis and growth agency and stole over $900,000 in digital foreign money.Commercial. Scroll to proceed studying.

On Monday, the DOJ introduced the arrest and indictment of US nationwide Zhenxing ‘Danny’ Wang of New Jersey, for his involvement in a multi-year fraud scheme producing over $5 million in income by distant IT work obtained utilizing greater than 80 compromised identities. Over 100 US corporations have been affected, together with many Fortune 500 corporations.

The fraudulent IT staff additionally gained entry to Worldwide Visitors in Arms Laws (ITAR) knowledge from a California-based protection contractor, and an abroad co-conspirator stole data marked as being managed beneath the ITAR.

Chinese language nationals Jing Bin Huang, Baoyu Zhou, Tong Yuze, Yongzhe Xu, Ziyou Yuan, and Zhenbang Zhou, and Taiwanese nationals Mengting Liu and Enchia Liu have been additionally indicted alongside Wang for his or her roles within the scheme. Legislation enforcement additionally seized 17 internet domains and 29 monetary accounts holding tens of hundreds of {dollars}.

One other indictment costs 4 North Korean nationals, particularly Kim Kwang Jin, Kang Tae Bok, Jong Pong Ju, and Chang Nam Il for his or her roles in a scheme to steal over $900,000 in cryptocurrency from two corporations, the Atlanta-based blockchain agency, and a digital token firm in Serbia.

After acquiring employment, Kim Kwang Jin and Jong Pong Ju have been assigned jobs that offered them with entry to the employers’ digital foreign money property. In February and March 2022, they stole $175,000 and $740,000 from these corporations, then used the digital foreign money mixer Twister Money to launder the funds.

In mid-June, the FBI performed 21 searchers at premises throughout 14 states in a crackdown on recognized and suspected laptop computer farms supporting North Korean distant IT employee schemes, and seized roughly 137 laptops.

On Monday, Microsoft stated it suspended 3,000 recognized Microsoft shopper accounts created by North Korean IT staff, mentioning that these people depend on AI and witting facilitators to cover their identities and land jobs. Microsoft is monitoring this exercise as Jasper Sleet. 

“There are only a few main corporations within the US that haven’t been touched by this rip-off at this level. It’s an epidemic,” John Hultquist, Chief Analyst, Google Risk Intelligence Group, stated in an emailed assertion.

“It’s nice to see extra strain from legislation enforcement, particularly in opposition to the facilitators who act as middlemen for the North Koreans. With out their assist will probably be a lot more durable to tug this off. Nonetheless, it’s necessary for everybody to take a very good have a look at their hiring practices. This exercise is incessantly found by cautious organizations,” Hultquist added.

Associated: US Seeks Forfeiture of $7.74M in Cryptocurrency Tied to North Korean IT Employees

Associated: SentinelOne Focused by North Korean IT Employees, Ransomware Teams, Chinese language Hackers

Associated: North Korean Pretend IT Employees Pose as Blockchain Builders on GitHub

Associated: US Costs 5 Folks Over North Korean IT Employee Scheme

Security Week News Tags:Crackdown, Farms, Korean, Laptop, North, Schemes, Storms, Worker

Post navigation

Previous Post: U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes $7.74 Million
Next Post: CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks

Related Posts

Malicious NPM Packages Disguised as Express Utilities Allow Attackers to Wipe Systems Security Week News
Hackers Stole 300,000 Crash Reports From Texas Department of Transportation Security Week News
Ahold Delhaize Data Breach Impacts 2.2 Million People Security Week News
Linux Security: New Flaws Allow Root Access, CISA Warns of Old Bug Exploitation Security Week News
Sensitive Information Stolen in Sensata Ransomware Attack Security Week News
Zscaler to Acquire MDR Specialist Red Canary Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • In Other News: Hacker Helps Kill Informants, Crylock Developer Sentenced, Ransomware Negotiator Probed
  • Critical HIKVISION ApplyCT Vulnerability Exposes Devices to Code Execution Attacks
  • Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users
  • Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It
  • Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • In Other News: Hacker Helps Kill Informants, Crylock Developer Sentenced, Ransomware Negotiator Probed
  • Critical HIKVISION ApplyCT Vulnerability Exposes Devices to Code Execution Attacks
  • Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users
  • Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It
  • Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News