On a humid July morning in Pyongyang, North Korea’s state intelligence agents burst into a nondescript safe house, catching a group of former military cyber operatives red-handed. The men, once part of the country’s elite cyber units, now stood accused of an audacious crime: hacking their own government’s central and state-run banks, siphoning off foreign currency, and laundering the loot through a sophisticated web of digital assets. According to Daily NK, the July 12 raid, which was later reported by outlets including CoinDesk and Cointelegraph, marked an unprecedented twist in North Korea’s cyber saga—one where the regime found itself both perpetrator and victim.
For years, North Korea’s state-backed cyber units have been infamous for orchestrating high-profile cyberattacks and cryptocurrency heists across the globe, targeting foreign exchanges and digital asset projects to bypass crushing international sanctions. This time, however, the tables had turned. The culprits were insiders, veterans of the Reconnaissance General Bureau’s cyber division, who allegedly banded together after their military service. They recruited fresh IT talent from top institutions like Kim Chaek University of Technology and Pyongyang University of Science and Technology, forming a clandestine organization that would soon exploit the very institutions they once served.
As Daily NK detailed, the group infiltrated internal networks of the Central Bank of North Korea and the Foreign Trade Bank. Their digital break-in allowed them to divert foreign currency accounts and state trade company funds, funneling the money into overseas digital asset wallets. The operation’s motive? Not ideology or loyalty to the regime, but personal gain—a rare admission in a country where state and individual interests are usually inseparable.
The laundering process was as intricate as it was familiar. The stolen funds were broken into numerous small transfers, each sent to overseas digital asset wallets. From there, Chinese over-the-counter (OTC) brokers helped convert the assets into U.S. dollars and Chinese yuan. Cash deliveries were arranged in real time through intermediaries stationed in border cities like Sinuiju and Hyesan, utilizing encrypted messaging apps, unregistered mobile phones, and Chinese wireless devices to evade detection. These tactics mirrored the standard playbook of North Korean cybercriminals operating abroad, a point underscored by CoinDesk and Cointelegraph.
North Korean authorities first caught wind of the scheme after spotting irregularities in foreign currency payment approvals. Anomalous overseas IP access records led investigators to the group’s existence. When the state intelligence agents moved in, they seized disposable phones and communication equipment. The Foreign Trade Bank’s headquarters and the Central Bank’s IT facilities were quickly locked down, and vehicles equipped to trace mobile signals patrolled Pyongyang’s streets. The authorities’ rapid, forceful response highlighted the gravity of the breach—after all, it’s not every day that North Korea’s own financial institutions fall prey to homegrown hackers.
International observers were quick to note the case’s singularity. As CoinDesk put it, "If confirmed, this would be a rare case in which North Korea is both a perpetrator and a victim of digital asset crime." The incident threw a spotlight on the regime’s vulnerability, even as its cyber operatives continue to wreak havoc internationally.
The laundering method itself was nothing new. According to TRM Labs, North Korean hackers have long relied on Chinese OTC brokers and certain financial institutions to turn stolen digital assets into hard currency. This time, the same playbook was used, but with the regime’s own money. Multinational sanctions monitoring bodies have repeatedly flagged the central role played by these Chinese intermediaries, and Chainalysis has documented similar laundering routes in past North Korean cyber operations.
North Korea’s cybercrime footprint is staggering. TRM Labs estimates that, as of April 2026, North Korean-linked hacking groups were responsible for 76% of global digital asset hacking losses, including major incidents like the $285 million hack on April 1 and the KelpDAO attack on April 18. Since 2017, these groups are believed to have stolen over $6 billion in digital assets. Last year alone, Chainalysis reported that North Korean hackers made off with an eye-watering $2 billion—a record for a single year. These figures underscore the regime’s reliance on cybercrime as a lifeline for its sanctioned economy.
Amid the fallout from the Pyongyang arrests, another North Korean-linked group, BlueNoroff, was busy targeting the global cryptocurrency industry with a different kind of deception. Between May 31 and July 14, 2026, BlueNoroff unleashed a wave of phishing attacks, impersonating Zoom and Microsoft Teams video conferences to dupe crypto professionals. The scheme, uncovered by UK security firm Jumpsec and reported by DailySecu, began with the hijacking of Telegram accounts belonging to victims’ trusted contacts. Attackers then sent out meeting invitations via Calendly links, which redirected targets to convincing fake video conference sites.
Once inside the faux meeting, victims were prompted to enter their names and enable their webcams, unwittingly streaming video to the attackers. The interface mimicked a real call, displaying messages like "waiting for other participants." Next came the ruse: victims were told their microphone wasn’t working or that a Zoom SDK update was needed, and instructed to run commands that installed malware on their systems. The malware was designed to disable Microsoft Defender, steal Telegram data, system information, and browser-stored encryption keys, and exfiltrate everything to a Telegram channel controlled by the attackers.
What set this campaign apart was its use of AI-generated faces and synthesized body movements, making the fake meetings seem eerily authentic. The attackers even checked for the presence of browser wallet extensions like MetaMask before deciding whom to target—no random phishing here, only those with potential crypto assets were pursued. The fake Microsoft Teams page was especially sophisticated, offering emoji reactions and blocking mobile access, all in a bid to bolster credibility.
BlueNoroff’s attacks were a stark reminder that the weakest link in cybersecurity is often human trust. As Jumpsec warned, "Even video conference links sent by someone you know should be double-checked, and any request to run commands or update software during a meeting should be treated with extreme caution." The campaign’s rapid evolution—five different phishing kits identified in just six weeks—showed the group’s relentless drive to outpace defenders.
Back in Pyongyang, the fate of the arrested hackers remains unclear. North Korean authorities have yet to issue any official statement about the case, and independent confirmation of the details remains elusive. Both CoinDesk and Cointelegraph noted that their reporting relied on anonymous sources inside North Korea, with no external verification possible. The precise amount stolen and the full background of the operation are still unknown, leaving plenty of unanswered questions.
Yet, the message is unmistakable: North Korea’s cyber operations are a double-edged sword, capable of turning inward as much as outward. In a country famed for its tight control and secrecy, even the guardians of the digital realm are not immune to temptation—or to the long arm of the state when things go awry.