BTC $64,839.35 +0.76%
ETH $1,923.86 +0.96%
BNB $585.49 +2.91%
XRP $1.07 +0.56%
SOL $74.23 +0.94%
TRX $0.3280 +0.46%
DOGE $0.0699 -0.83%
ADA $0.1666 +1.16%
BCH $212.07 +0.39%
LINK $8.44 +1.28%
HYPE $53.13 -3.69%
AAVE $98.75 +0.14%
SUI $0.6906 +0.27%
XLM $0.1723 -1.12%
ZEC $475.04 +1.99%
BTC $64,839.35 +0.76%
ETH $1,923.86 +0.96%
BNB $585.49 +2.91%
XRP $1.07 +0.56%
SOL $74.23 +0.94%
TRX $0.3280 +0.46%
DOGE $0.0699 -0.83%
ADA $0.1666 +1.16%
BCH $212.07 +0.39%
LINK $8.44 +1.28%
HYPE $53.13 -3.69%
AAVE $98.75 +0.14%
SUI $0.6906 +0.27%
XLM $0.1723 -1.12%
ZEC $475.04 +1.99%

nvo

All
Article
Flash

North Korea dismantles an elite hacking group involved in infiltrating central banks and foreign trade banks to steal funds and launder money through cryptocurrency

According to South Korean media Daily NK, North Korean authorities arrested an elite hacker group on July 12, which is suspected of infiltrating the internal networks of the North Korean central bank and foreign trade bank, stealing national trade funds and laundering money through cryptocurrency. Sources say the group's leader is a veteran from the cyber warfare unit under the North Korean Reconnaissance General Bureau, who recruited talented IT graduates from Kim Chaek University of Technology and Pyongyang University of Science and Technology, using encrypted communications and wireless devices to commit crimes.They split the stolen funds into small amounts and transferred them to overseas cryptocurrency wallets, exchanged them for cash through intermediaries, and then converted them into dollars and other currencies in border areas. Pyongyang officials launched an investigation after discovering anomalies in foreign currency payment approvals and records of overseas IP access, ultimately raiding a safe house and arresting suspects who were laundering money, seizing equipment worth hundreds of thousands of dollars. This case has caused a stir among the elite and military circles in Pyongyang, with senior officials in the Reconnaissance General Bureau and the science and education sector worried about being implicated. North Korea has long been accused of stealing billions of dollars in cryptocurrency assets through hacker organizations like the Lazarus Group, but this incident rarely shows that its own financial system has also become a target of internal attacks.

The U.S. Department of Justice seized over $25 million in cryptocurrency, involving a transnational investment fraud network

The U.S. Attorney's Office for the District of Columbia, in conjunction with the U.S. Secret Service Washington Field Office, announced that an investigation into multiple international cyber fraud cases has led to the seizure of over $25 million in cryptocurrency, with the funds suspected to be linked to cryptocurrency investment scams targeting residents of the United States and Canada. This operation is part of the U.S. "Scam Center Strike Force," initiated in 2025 by D.C. Attorney Jeanine Ferris Pirro, which has so far recovered assets totaling over $800 million.U.S. prosecutors stated that on July 21, 2026, the D.C. Attorney's Office submitted five civil forfeiture complaints to the U.S. District Court, seeking to confiscate over $25 million in crypto assets recovered from various fraud investigations. Investigators indicated that these cases involve multiple money laundering networks, with victims spread across the globe. Criminal groups lure victims into investing through fake cryptocurrency investment platforms, online romance scams, and other methods, and conceal the source of funds through multi-layered wallet addresses and coin mixing operations.The seized funds are related to five major investigations: in one case, Canadian law enforcement provided the U.S. Secret Service with wallet addresses suspected of transferring illegal proceeds. Investigators froze the relevant addresses and tracked over 270 suspected victim transactions, involving approximately $10.4 million; the second case involves an online romance scam where over 200 victims were defrauded, with illegal funds transferred through hundreds of intermediary wallet addresses, mixing with other victims' funds, totaling about $12.08 million; the third case involves a victim in the Washington D.C. area who participated in a fake cryptocurrency investment project and lost contact with the scammers after a failed withdrawal, with related funds amounting to about $1.23 million; in the fourth case, a victim transferred millions of dollars in cryptocurrency to a fake investment account, and investigators traced part of the funds to six wallet addresses, freezing approximately $2.39 million; in the fifth case, scammers impersonated a "fund recovery" agency, tricking victims into paying fees, with the amount involved being about $285,000. The U.S. Secret Service stated that these cases are still under ongoing investigation, and law enforcement is tracking the suspects behind the fraud networks and will collaborate with international law enforcement agencies to hold them accountable.

The EU sanctions "the most active ransomware operator in history" Stern, involved in over 300 million dollars in ransom inflow

The United States, the European Union, and the United Kingdom jointly announced sanctions against a group involving state-level hacker organizations, cybercrime gangs, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global businesses, critical infrastructure, and government agencies. Among the most notable is the EU's sanction against the Russian cybercriminal Vitaly Nikolayevich Kovalev (alias "Stern").The EU has identified Stern as one of the core managers of the notorious Trickbot Group ransomware organization, which includes several high-risk ransomware variants such as Conti ransomware and Ryuk. On-chain analysis shows that wallet addresses associated with Stern have received over $300 million in ransom payments, potentially making him the "largest confirmed ransomware operator" to date. According to analysis, the $300 million only represents the profits obtained by Stern personally, and the overall illegal income of the Trickbot group may be much higher.On-chain fund flows indicate that Stern has had transactional connections with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum. Investigations show that Stern plays a role similar to "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning.
app_icon
ChainCatcher Building the Web3 world with innovations.