Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme

A major North Korea IT worker scheme has led to the sentencing of two U.S. nationals who helped facilitate fraudulent remote employment operations that generated millions of dollars for the Democratic People’s Republic of Korea (DPRK), a…

0
↗ Quelle (thecyberexpress.com)
Reagiere als Erste:r — dein Feedback zählt!

North Korea IT Worker Scheme

A major North Korea IT worker scheme has led to the sentencing of two U.S. nationals who helped facilitate fraudulent remote employment operations that generated millions of dollars for the Democratic People’s Republic of Korea (DPRK), according to the U.S. Department of Justice.

The case highlights how foreign actors exploited remote work systems, stolen identities, and U.S.-based infrastructure to infiltrate companies and access sensitive data.

Sentencing in North Korea IT Worker Scheme


Kejia Wang, 42, and Zhenxing Wang, 39, were sentenced for their roles in supporting the North Korea IT worker scheme, which placed overseas operatives into jobs at more than 100 U.S. companies.

Kejia Wang received a sentence of 108 months in prison, while Zhenxing Wang was sentenced to 92 months. Both had pleaded guilty to multiple charges, including conspiracy to commit wire fraud and money laundering. The court also ordered three years of supervised release and financial penalties, including forfeiture of $600,000.

Officials confirmed that the scheme generated more than $5 million in revenue for the DPRK, with at least $400,000 already recovered by authorities.

How the Laptop Farm Scheme Worked


At the center of the North Korea IT worker scheme were so-called “laptop farms” operated by the defendants in the United States. These setups were designed to make it appear that remote IT workers were physically located in the U.S.

Using stolen identities of more than 80 Americans, the group secured remote IT roles across multiple organizations, including several Fortune 500 companies. The defendants and their associates hosted company-issued laptops at U.S. locations, enabling overseas workers to access them remotely.

To facilitate this, they used hardware tools such as keyboard-video-mouse switches, allowing remote control of the devices from abroad. This setup helped bypass location checks and security controls commonly used by employers.

Use of Shell Companies and Financial Networks


The defendants also created shell companies, including Hopana Tech LLC and Independent Lab LLC, to support the North Korea IT worker scheme. These entities had no real operations but were used to present the overseas workers as legitimate U.S.-based employees.

Payments from victim companies were routed through financial accounts linked to these shell companies. Authorities said millions of dollars were funneled through these accounts, with a significant portion transferred to overseas co-conspirators.

In return, the facilitators in the U.S. received nearly $700,000 for their involvement.

Access to Sensitive Data and Security Risks


The North Korea IT worker scheme raised serious concerns about data security and national security. Investigators found that some of the fraudulently hired workers gained access to sensitive corporate information, including source code and restricted technical data.

In one instance, an overseas co-conspirator accessed data controlled under International Traffic in Arms Regulations from a U.S.-based defense contractor. The data included sensitive information related to advanced technologies.

Officials warned that such access could expose critical systems and intellectual property to foreign adversaries.

Ongoing Investigation and Wanted Suspects


Authorities continue to investigate the broader North Korea IT worker scheme, with several individuals still at large. The Federal Bureau of Investigation has identified multiple suspects believed to be involved in the operation.

The U.S. Department of State has announced a reward of up to $5 million for information that helps disrupt financial networks supporting such activities.

Law enforcement agencies have already taken action to dismantle parts of the operation. This includes the seizure of web domains and financial accounts linked to the scheme, along with the recovery of more than 70 laptops and remote access devices during coordinated searches.

The North Korea IT worker scheme is part of a broader effort by DPRK-linked actors to generate revenue through cyber-enabled operations. Authorities say these schemes often rely on stolen identities, fake online profiles, and third-party facilitators to gain access to company systems.

Public advisories from U.S. agencies have previously warned that such workers can earn significant sums, sometimes up to $300,000 annually, contributing to large-scale funding operations tied to North Korea’s strategic programs.

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme
id: 0b68caf1-a798-4642-8bd0-5362010629e1
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-27"
        description = "YARA Signature for "
    strings:
        $str = "Two U.S. Nationals Sentenced i" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Two US Nationals Sentenced in 5M North K")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Two US Nationals Sentenced in 5M North K*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Two US Nationals Sentenced in 5M North K"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme

Thematisch verwandte Begriffe: Nationals, Sentenced, North, Korea · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-100620 | Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an ove…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag