By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains
Tech News

North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains

By Viral Trending Content 6 Min Read
Share
SHARE

Jan 15, 2025Ravie LakshmananBlockchain / Cryptocurrency

North Korean IT Fraud Network

Cybersecurity researchers have identified infrastructure links between the North Korean threat actors behind the fraudulent IT worker schemes and a 2016 crowdfunding scam.

The new evidence suggests that Pyongyang-based threamoret groups may have pulled off illicit money-making scams that predate the use of IT workers, SecureWorks Counter Threat Unit (CTU) said in a report shared with The Hacker News.

The IT worker fraud scheme, which came to light in late 2023, involves North Korean actors infiltrating companies in the West and other parts of the world by surreptitiously seeking employment under fake identities to generate revenue for the sanctions-hit nation. It’s also tracked under the names Famous Chollima, Nickel Tapestry, UNC5267, and Wagemole.

The IT personnel, per South Korea’s Ministry of Foreign Affairs (MoFA), have been assessed to be part of the 313th General Bureau, an organization under the Munitions Industry Department of the Workers’ Party of Korea.

Another notable aspect of these operations is that the IT workers are routinely dispatched to China and Russia to work for front companies such as Yanbian Silverstar and Volasys Silver Star, both of which were previously subjected to sanctioned by the Treasury Department’s Office of Foreign Assets Control (OFAC) in September 2018.

Cybersecurity

Both entities have been accused of engaging in and facilitating the exportation of workers from North Korea with the goal of generating revenue for the Hermit Kingdom or the Workers’ Party of Korea and obfuscating the workers’ true nationality from clients.

Sanctions were also imposed against Yanbian Silverstar’s North Korean CEO Jong Song Hwa for his role in controlling the “flow of earnings for several teams of developers in China and Russia.”

In October 2023, the U.S. government announced the seizure of 17 internet domains that impersonated U.S.-based IT services companies so as to defraud businesses in the country and abroad by allowing North Korean IT workers to conceal their true identities and locations when applying online to do freelance work.

Among the domains that were confiscated included a website named “silverstarchina[.]com.” Secureworks’s analysis of historical WHOIS records has revealed that the registrant’s street address matches the reported location of Yanbian Silverstar offices located in the Yanbian prefecture and that the same registrant email and street address were used to register other domain names.

One of those domains in question is kratosmemory[.]com, which has been previously used in connection with a 2016 IndieGoGo crowdfunding campaign that was later found to be a scam after the backers neither received a product nor a refund from the seller. The campaign had 193 backers and raised funds to the tune of $21,877.

“The people who donated to this campaign have not gotten anything that was promised to them,” one of the comments on the crowdfunding page claims. “They have not received any updates as well. This was a complete scam.”

The cybersecurity company also noted that the WHOIS registrant information for kratosmemory[.]com was updated around mid-2016 to reflect a different persona named Dan Moulding, which matches the IndieGoGo user profile for the Kratos scam.

“This 2016 campaign was a low-effort, small monetary-return endeavor compared to the more elaborate North Korean IT worker schemes active as of this publication,” Secureworks said. “However, it showcases an earlier example of North Korean threat actors experimenting with various money-making schemes.”

The development comes as Japan, South Korea, and the U.S. issued a joint warning to the blockchain technology industry regarding the persistent targeting of various entities in the sector by Democratic People’s Republic of Korea (DPRK) cyber actors to conduct cryptocurrency heists.

Cybersecurity

“The advanced persistent threat groups affiliated with the DPRK, including the Lazarus Group, […] continue to demonstrate a pattern of malicious behavior in cyberspace by conducting numerous cybercrime campaigns to steal cryptocurrency and targeting exchanges, digital asset custodians, and individual users,” the governments said.

Some of the companies targeted in 2024 included DMM Bitcoin, Upbit, Rain Management, WazirX, and Radiant Capital, leading to the theft of more than $659 million in cryptocurrency. The announcement marks the first official confirmation that North Korea was behind the hack of WazirX, India’s largest cryptocurrency exchange.

“This is a critical moment. We urge swift international action and support to recover the stolen assets,” WazirX founder Nischal Shetty posted on X. “Rest assured, we will leave no stone unturned in our pursuit of justice.”

Last month, blockchain intelligence firm Chainalysis also revealed that threat actors affiliated with North Korea have stolen $1.34 billion across 47 cryptocurrency hacks in 2024, up from $660.50 million across 20 incidents in 2023.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Enterprise Ireland leads Irish Tech Delegation Targets Nordic Growth and VC Funding at Slush 2025

Gemini 3 Is Here—and Google Says It Will Make Search Smarter

Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale

Cloudflare outage disrupts X, OpenAI and more

xAI Grok 4.1, Better EQ, Fewer Hallucinations, Faster Logic

TAGGED: Blockchain, cryptocurrency, Cyber Security, Cybersecurity, Internet, IT Fraud, Lazarus Group, North Korea
Share This Article
Facebook Twitter Copy Link
Previous Article More than 12,000 houses in ruins after fires devastate California
Next Article Where Is Sheinelle Jones From ‘Today’? Her Absence
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

US Banks Authorized To Hold Crypto For Blockchain Transaction Fees, OCC Reveals
Crypto
Half the Internet just broke: Cloudflare crash sparks global chaos
World News
Meta prevails in historic FTC antitrust case, won’t have to break off WhatsApp, Instagram
Business
Enterprise Ireland leads Irish Tech Delegation Targets Nordic Growth and VC Funding at Slush 2025
Tech News
France’s TotalEnergies accused of complicity in ‘civilian massacre’ in Mozambique
Business
Central Asia and South Caucasus forge stronger ties at Tashkent summit
World News
Here’s why the Nvidia stock price matters even if you don’t own it!
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

US Banks Authorized To Hold Crypto For Blockchain Transaction Fees, OCC Reveals

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
US Banks Authorized To Hold Crypto For Blockchain Transaction Fees, OCC Reveals
November 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?