OTHER

US Government Shuts Down Major North Korean ‘Remote IT Workers’ Operation

On Monday, the U.S. Department of Justice announced the launch of various enforcement initiatives targeting North Korea’s revenue-generating schemes, which involve covert remote IT workers embedded in American tech companies to finance the regime’s nuclear weapons program and pilfer sensitive data and cryptocurrency.

As part of this nationwide effort by the DOJ, authorities revealed the arrest and indictment of U.S. citizen Zhenxing “Danny” Wang, who is accused of managing a long-standing fraud operation from New Jersey that enabled the infiltration of remote North Korean IT workers into U.S. tech firms. The indictment claims this scheme generated over $5 million for the North Korean regime.

Wang faces multiple charges, including conspiracy to commit wire fraud, money laundering, and identity theft.

In addition, eight other individuals have been indicted for their roles in the scheme: six Chinese nationals and two Taiwanese citizens, all charged with conspiracy for wire fraud, money laundering, identity theft, hacking, and violating sanctions.

“Thousands of North Korean cyber operatives have been trained and deployed by the regime to integrate into the global digital workforce and systematically target U.S. companies,” remarked Leah B. Foley, U.S. Attorney for the District of Massachusetts.

Between 2021 and 2024, the co-conspirators allegedly impersonated over 80 U.S. individuals to gain remote positions at more than 100 American firms, resulting in $3 million in damages from legal fees, data breach remediation, and other expenses.

The group reportedly established laptop farms within the U.S., allowing North Korean IT workers to effectively conceal their identities. According to the DOJ, they used keyboard-video-mouse (KVM) switches, enabling a single individual to operate multiple computers from one keyboard and mouse. Furthermore, they allegedly set up shell companies in the U.S. to create the facade that the North Korean IT workers were associated with legitimate businesses, facilitating the transfer of funds abroad, as per the DOJ’s statement.

The fraudulent operation reportedly involved North Korean workers stealing sensitive information, including source code, from the companies that employed them, particularly from a California defense contractor “developing artificial intelligence-powered equipment and technologies.”

The DOJ disclosed that the FBI executed searches in June at 21 locations across 14 states, believed to be housing the laptop farms connected to the North Korean operation. The raids led to the seizure of 137 laptops.

In addition, authorities seized at least 21 web domains, 29 financial accounts used in laundering tens of thousands of dollars, and over 70 laptops and remote access devices, including KVMs.

Five North Korean nationals were indicted on charges of wire fraud and money laundering for allegedly stealing over $900,000 in cryptocurrency from two unnamed companies through the use of fake or stolen identities, according to the DOJ.