Recently, a significant data leak was detected. ZachXBT just announced information about an internal payment server of a North Korean IT team being compromised, with over 390 accounts exposed along with all chat histories and crypto transaction data.



What caught my attention the most is the scale of the money transfers. From late November last year to now, the related wallet addresses have moved more than $3.5 million. Notably, the USDT wallet addresses on the Tron network were transferred through exchanges or converted into fiat via platforms like Payoneer, then deposited into Chinese bank accounts.

Looking at on-chain data, there is an interesting detail. One of the USDT addresses on Tron was blacklisted by Tether in December. This indicates that Tether is also monitoring this situation. Additionally, three companies in the user list have been sanctioned by OFAC, including Sobaeksu.

ZachXBT compiled the entire organizational chart and data scope from December last year to February this year. This is a typical example of how IT groups associated with sanctioned regimes still attempt to launder money through crypto channels. Security analysts should pay attention to these patterns to detect similar activities early in the future.
TRX-0,26%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin