By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains
Tech News

North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains

By Viral Trending Content 6 Min Read
Share
SHARE

Jan 15, 2025Ravie LakshmananBlockchain / Cryptocurrency

North Korean IT Fraud Network

Cybersecurity researchers have identified infrastructure links between the North Korean threat actors behind the fraudulent IT worker schemes and a 2016 crowdfunding scam.

The new evidence suggests that Pyongyang-based threamoret groups may have pulled off illicit money-making scams that predate the use of IT workers, SecureWorks Counter Threat Unit (CTU) said in a report shared with The Hacker News.

The IT worker fraud scheme, which came to light in late 2023, involves North Korean actors infiltrating companies in the West and other parts of the world by surreptitiously seeking employment under fake identities to generate revenue for the sanctions-hit nation. It’s also tracked under the names Famous Chollima, Nickel Tapestry, UNC5267, and Wagemole.

The IT personnel, per South Korea’s Ministry of Foreign Affairs (MoFA), have been assessed to be part of the 313th General Bureau, an organization under the Munitions Industry Department of the Workers’ Party of Korea.

Another notable aspect of these operations is that the IT workers are routinely dispatched to China and Russia to work for front companies such as Yanbian Silverstar and Volasys Silver Star, both of which were previously subjected to sanctioned by the Treasury Department’s Office of Foreign Assets Control (OFAC) in September 2018.

Cybersecurity

Both entities have been accused of engaging in and facilitating the exportation of workers from North Korea with the goal of generating revenue for the Hermit Kingdom or the Workers’ Party of Korea and obfuscating the workers’ true nationality from clients.

Sanctions were also imposed against Yanbian Silverstar’s North Korean CEO Jong Song Hwa for his role in controlling the “flow of earnings for several teams of developers in China and Russia.”

In October 2023, the U.S. government announced the seizure of 17 internet domains that impersonated U.S.-based IT services companies so as to defraud businesses in the country and abroad by allowing North Korean IT workers to conceal their true identities and locations when applying online to do freelance work.

Among the domains that were confiscated included a website named “silverstarchina[.]com.” Secureworks’s analysis of historical WHOIS records has revealed that the registrant’s street address matches the reported location of Yanbian Silverstar offices located in the Yanbian prefecture and that the same registrant email and street address were used to register other domain names.

One of those domains in question is kratosmemory[.]com, which has been previously used in connection with a 2016 IndieGoGo crowdfunding campaign that was later found to be a scam after the backers neither received a product nor a refund from the seller. The campaign had 193 backers and raised funds to the tune of $21,877.

“The people who donated to this campaign have not gotten anything that was promised to them,” one of the comments on the crowdfunding page claims. “They have not received any updates as well. This was a complete scam.”

The cybersecurity company also noted that the WHOIS registrant information for kratosmemory[.]com was updated around mid-2016 to reflect a different persona named Dan Moulding, which matches the IndieGoGo user profile for the Kratos scam.

“This 2016 campaign was a low-effort, small monetary-return endeavor compared to the more elaborate North Korean IT worker schemes active as of this publication,” Secureworks said. “However, it showcases an earlier example of North Korean threat actors experimenting with various money-making schemes.”

The development comes as Japan, South Korea, and the U.S. issued a joint warning to the blockchain technology industry regarding the persistent targeting of various entities in the sector by Democratic People’s Republic of Korea (DPRK) cyber actors to conduct cryptocurrency heists.

Cybersecurity

“The advanced persistent threat groups affiliated with the DPRK, including the Lazarus Group, […] continue to demonstrate a pattern of malicious behavior in cyberspace by conducting numerous cybercrime campaigns to steal cryptocurrency and targeting exchanges, digital asset custodians, and individual users,” the governments said.

Some of the companies targeted in 2024 included DMM Bitcoin, Upbit, Rain Management, WazirX, and Radiant Capital, leading to the theft of more than $659 million in cryptocurrency. The announcement marks the first official confirmation that North Korea was behind the hack of WazirX, India’s largest cryptocurrency exchange.

“This is a critical moment. We urge swift international action and support to recover the stolen assets,” WazirX founder Nischal Shetty posted on X. “Rest assured, we will leave no stone unturned in our pursuit of justice.”

Last month, blockchain intelligence firm Chainalysis also revealed that threat actors affiliated with North Korea have stolen $1.34 billion across 47 cryptocurrency hacks in 2024, up from $660.50 million across 20 incidents in 2023.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Trump Takes Aim at State AI Laws in Draft Executive Order

Changing Ends Season 3 Review: Forget Alan Carr’s The Traitors Success

1,139 HP: The New Porsche Cayenne Electric is a Monster

Former Revolut executives raise €30M to bring blockchain-based banking app Deblock to Ireland

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

TAGGED: Blockchain, cryptocurrency, Cyber Security, Cybersecurity, Internet, IT Fraud, Lazarus Group, North Korea
Share This Article
Facebook Twitter Copy Link
Previous Article More than 12,000 houses in ruins after fires devastate California
Next Article Where Is Sheinelle Jones From ‘Today’? Her Absence
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

S.T.A.L.K.E.R. 2: Heart of Chornobyl PS5 Graphics Analysis – How Does It Compare Against Xbox Series X and PC?
Gaming News
Trump Takes Aim at State AI Laws in Draft Executive Order
Tech News
2 UK shares I’d prefer to own over Lloyds stock right now
Business
Mevolaxy files for registration with the SEC
Crypto
Underdog Fantasy Promo Code FOXSPORTS: Bet $5, Get $100 on Wednesday's NBA Slate
Sports
RiNo apartment building asks judge to evict rooftop cocktail lounge
Business
Changing Ends Season 3 Review: Forget Alan Carr’s The Traitors Success
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

S.T.A.L.K.E.R. 2: Heart of Chornobyl PS5 Graphics Analysis – How Does It Compare Against Xbox Series X and PC?

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
S.T.A.L.K.E.R. 2: Heart of Chornobyl PS5 Graphics Analysis – How Does It Compare Against Xbox Series X and PC?
November 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?