ZachXBT
ZachXBT
@zachxbt
Apr 8 1 month ago 11 tweets Read on X

1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.

I spent long hours going through all of it, none of which has ever been publicly released.

It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion.

Enjoy the findings!

Tweet image 1

2/ A DPRK IT worker had their device compromised via infostealer. Extracted data included IPMsg chat logs, fake identities, and browser history.

Digging through the IPMsg logs revealed this site being discussed:
luckyguys[.]site

An internal payment remittance platform, essentially a Discord-style messenger used by DPRK IT workers to report payments back to their handlers.

Tweet image 1
Tweet image 2

3/ The site's default password was 123456, which remained unchanged for ten users.

The user list included roles, Korean names, cities, and coded group names consistent with DPRK IT worker operations.

Three companies which appeared are currently OFAC sanctioned: Sobaeksu, Saenal, & Songkwang.

Tweet image 1
Tweet image 2
Tweet image 3

4/ Here is one of the WebMsg users 'Rascal' and their DMs with PC-1234 detailing payment transfers and the use of fraudulent identities from December 2025 through April 2026.

All payments are processed and confirmed through the server admin account: PC-1234.

Addresses in Hong Kong were used for bills and goods, though the authenticity of it requires further verification.

5/ Since late November 2025 $3.5M+ was received across the payment wallet addresses.

The remittance pattern was consistent across users:

Users transfer crypto originating from an exchange or service, or convert to fiat via Chinese bank accounts through platforms like Payoneer.

PC-1234 then confirms receipt and provides account credentials, varying between crypto exchanges and fintech payment platforms depending on the user.

Tweet image 1
Tweet image 2
Tweet image 3

6/ Using the full dataset I mapped out the complete organizational structure of the network, including payment totals per user and group.

The interactive org chart can be accessed here:

Password: 123456

Note: Data range is Dec 2025 through Feb 2026. Payment totals are derived from scraped transaction data and may vary slightly.

Tweet image 1

7/ Tracing the internal payment addresses revealed links onchain to several attributed DPRK IT worker's from known clusters.

The Tron payment address was frozen by Tether in December 2025.

Payment addresses:
0xb51DA55047Fd899aD08Ab5CE349823664d311998
TSxYS91qoXrJUoMhWaQfMz9p2b7FTw57L3

Tweet image 1
Tweet image 2

8/ Jerry's compromised device shows usage of Astrill VPN and various fake personas applying for jobs.

An internal Slack showed 'Nami' sharing a blog post about a DPRK IT worker deepfake job applicant. A second user asked if it was them, while a third noted they aren't allowed to share external links.

Another screenshot shows 33 DPRK IT workers communicating on the same network via IPMsg.

Tweet image 1
Tweet image 2
Tweet image 3
Tweet image 4

9/ Jerry actively discussed stealing from a project with another DPRK IT worker via Nigerian proxy targeting Arcano, a GalaChain game.

However, it remains unclear if the attack later materialized.

Tweet image 1
Tweet image 2
Tweet image 3

10/ The admin sent 43 examples of Hex-Rays/IDA Pro training modules to the group from Nov 2025 to Feb 2026.

The trainings covered disassembly, decompilation, local and remote debugging, and various cybersecurity topics.

A link sent on November 20 explicitly stated: 'using-ida-debugger-to-unpack-an-hostile-pe-executable'

Tweet image 1
Tweet image 2
Tweet image 3
Tweet image 4

11/ This cluster of DPRK IT worker activity is less sophisticated compared to groups like AppleJeus and TraderTraitor, which operate far more efficiently and present the greatest risks to the industry.

I previously estimated DPRK IT workers generate multiple seven figures per month in revenue, and the data here supports that.

Unpopular opinion: threat actors are leaving an opportunity on the table by not targeting low-tier DPRK groups. The risk of repercussions is low, competition is minimal, and the targets are arguably deserving.

I plan to continue building out with future findings.

Special thanks to for helping me purchase two premium domains.

Tweet image 1

Missing some Tweet in this thread? You can try to Update

More Threads by @zachxbt

4 tweets • 4 days ago
Read Thread
7 tweets • 18 days ago
Read Thread
13 tweets • 24 days ago
Read Thread
9 tweets • 1 month ago
Read Thread
11 tweets • 1 month ago
Read Thread

Unroll Another Thread

Convert any Twitter threads to an easy-to-read article instantly

Have you tried our Twitter bot?

You can now unroll any thread without leaving Twitter/X. Here's how to use our Twitter bot to do it.

  • Give us a follow on Twitter. follow us
  • Drop a comment, mentioning us @unrollnow on the thread you want to Unroll.
  • Wait For Some Time, We will reply to your comment with Unroll Link.
UnrollNow Twitter Bot
Modal Image
0:00 / 0:00