Full Report
DTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs. The post North Korea’s IT worker scheme funds Russia’s war effort appeared first on CyberScoop.
Analysis Summary
# Threat Actor: DPRK IT Workers (facilitated by PC-1234)
## Attribution & Identity
- **Actor Identity:** North Korean (DPRK) IT Workers.
- **Controlled By:** A single administrator known as "**PC-1234**" who manages an internal payment server/wallet.
- **Known Associations:**
- **Korea Ryonbong General Corp** (Sanctioned defense entity involved in weapons procurement).
- **Sobaeksu**, **Saenal**, and **Songkwang** (Sanctioned entities receiving funds).
- Cooperation with Russian military efforts.
- **Western Facilitators:** The group utilizes "laptop farms" hosted by North American and international accomplices to masking their true location.
## Activity Summary
Recent research from DTEX (July 2026) identified a sophisticated "bottom-up" funding scheme where North Korean IT workers, masquerading as legitimate remote employees, funnel their salaries into a web of front companies. Between December 2025 and February 2026, researchers tracked approximately $2.84 million in transactions. Unlike previous operations focused solely on the DPRK nuclear program, these specific funds have been traced to entities supporting Russia’s war effort in Ukraine, including manufacturing and supplying weapons.
## Tactics, Techniques & Procedures
- **Employment Fraud:** Using stolen or fake identities to secure remote IT positions at Western companies.
- **Financial Laundering:** Funneling salaries through internal payment servers (e.g., the PC-1234 cluster) to move money from the "bottom" (individual workers) to "top" (state-sanctioned entities).
- **Identity Obfuscation:** Using "laptop farms" where accomplices in the U.S. and elsewhere host hardware that the workers access remotely via VPN or RDP to appear as if they are local.
- **Social Engineering:** Manipulating hiring managers and HR departments through resume scams and payroll abuse.
- **MITRE ATT&CK IDs (Inferred):**
- T1136 (Create Account - for fake personas)
- T1090 (Proxy - via laptop farms)
- T1566 (Phishing/Social Engineering for employment)
## Targeting
- **Sectors:** Technology, Defense, Finance, and general corporate sectors employing remote IT staff.
- **Geography:** Primarily targeting companies in the **United States** (~70 companies impacted) and other Western nations.
- **Victims:** Commercial enterprises ranging from small businesses to large corporations; specifically referenced are entities that inadvertently hired DPRK workers for software development or technical roles.
## Tools & Infrastructure
- **Payment Infrastructure:** Internal North Korean payment servers/wallets managed by admin **PC-1234**.
- **Hardware Facilitation:** Laptop farms located in residential homes (e.g., hosted by U.S. nationals).
- **Web/Chat Logs:** Use of internal payment servers to record transactions and chat logs between workers and managers.
- **Defanged Infrastructure:**
- `hxxps[://]www[.]dtex[.]ai/wp-content/uploads/2026/07/all_chats_combined[.]txt` (Referenced data source).
- `hxxps[://]www[.]dtex[.]ai/org_hierarchy[.]html` (Mapping of the organization).
## Implications
The IT worker scheme has evolved into a diversified revenue stream that extends beyond North Korea's domestic weapons programs. It now directly bolsters the Russian military-industrial complex and the war in Ukraine. This creates a "double threat" where Western companies unknowingly fund the very weaponry used against geopolitical allies while simultaneously exposing their internal networks to state-sponsored actors.
## Mitigations
- **Rigorous Identity Verification:** Implement mandatory video interviews with identity document checks (e.g., holding a passport/license) for remote hires.
- **Hardware Baseline:** Prohibit or strictly monitor the use of residential VPNs or non-corporate-issued hardware.
- **Background Checks:** Conduct deep-dive background checks that verify past employment through direct contact with previous HR departments, rather than provided references.
- **Network Monitoring:** Monitor for "impossible travel" or remote access originating from known laptop farm hubs or service provider IPs associated with residential proxies.