
U.S. Treasury Targets North Korean IT Revenue Network
Read Our Expert Analysis
Create an account or login for free to unlock our expert analysis and key takeaways for this development.
By continuing, you agree to receive marketing communications and our weekly newsletter. You can opt-out at any time.
Recommended for you

U.S. Treasury Targets Iran’s Use of Crypto, Sanctions Two UK-Registered Exchanges
The U.S. Treasury has imposed sanctions on two UK-registered cryptocurrency platforms and several Iranian officials, marking a step toward treating digital-asset venues as sanctionable nodes in Iran’s financial apparatus. The move highlights Washington’s effort to disrupt opaque crypto channels that analysts say have moved tens of billions of dollars and to deter state-linked money flows supporting the IRGC.

Operation Zero Sanctioned by U.S. Treasury Over Crypto-Funded Cyber Exploits
The U.S. Treasury, via OFAC, blacklisted Operation Zero and associated individuals for buying and reselling stolen offensive cyber tools using millions in cryptocurrency; court filings tied one insider sale to roughly $1.3 million and to a defense‑contractor leak. The move — taken under the Protecting American Intellectual Property Act — signals a wider enforcement posture that now layers criminal prosecutions, sanctions on brokers, and pressure on crypto platforms.

UK Targets 2Rivers Network and Transneft in Major Oil Sanctions
The UK imposed sanctions on the 2Rivers maritime network and designated PJSC Transneft in a bid to squeeze Russian energy revenues linked to the war in Ukraine. The measures hit 175 entities and target a pipeline operator that transports more than 80% of Russia’s exported crude.
North Korea-linked hackers deploy AI deepfakes and new malware against crypto and fintech firms
Security researchers attribute a recent surge of tailored intrusions against cryptocurrency, fintech and venture firms to a North Korea-linked cluster that combined AI-generated deepfakes with social engineering to deliver seven distinct malware families. The campaign introduced multiple novel data-harvesting tools, leveraged automated reconnaissance and trusted collaboration channels, and highlights parallel risks from exposed AI endpoints and unvetted plugin ecosystems that amplify attacker scale.

CJNG-linked Kovay Gardens hit with U.S. Treasury sanctions over timeshare fraud
The U.S. Treasury designated Kovay Gardens and affiliated entities, alleging the resort fed a cartel-run fraud network that targeted American tourists. Authorities say financial intelligence and law-enforcement filings point to hundreds of suspicious reports and hundreds of millions of dollars in suspected losses tied to the scheme.

Polyfill.io Compromise Linked to North Korean Operators, Impacting 100k+ Sites
Forensic artifacts (LummaC2 sample and harvested CDN/DNS credentials) tie the 2024 Polyfill.io library compromise to operators aligned with North Korea; investigators warn the incident exemplifies a broader trend of supply‑chain abuse that pairs credential theft, control‑plane takeover, and resilient off‑platform monetization to convert web traffic into crypto flows.
South Korea breaks a cross-border crypto laundering operation that moved roughly W149 billion
Customs investigators uncovered a multi-year scheme that allegedly routed about 148.9 billion won through cryptocurrency and local bank accounts; three suspects have been referred to prosecutors. The action is part of a broader enforcement push as authorities tighten oversight of foreign exchange flows and underground exchange activity.

Crypto payments accelerate human-trafficking networks across Southeast Asia
New blockchain-forensics research shows a steep 2025 uptick in cryptocurrency-funded human‑trafficking activity in Southeast Asia concentrated on messaging platforms; traffickers route payments mainly through dollar‑pegged stablecoins and use Telegram-based escrow and cash‑out markets. These trafficking flows sit inside a wider professionalized laundering ecosystem — brokers, mule networks and language‑specific trading venues — that increases resilience to takedowns and raises the need for cross‑platform, cross‑jurisdiction disruption.