For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.
But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them.
According to a report by Daily NK, which specialises in reporting on the internal affairs of North Korea, the country's National Intelligence Agency arrested a hacking ring on 12 July after uncovering a sophisticated scheme to steal from the Chosun Central Bank and the Foreign Trade Bank - the two institutions sitting at the very heart of North Korea's financial system.
The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau. That is the same shadowy military intelligence agency that runs the Lazarus Group, the hackers responsible for stealing billions from foreign banks and cryptocurrency exchanges over the past decade.
Those arrested are not Lazarus members themselves, but - if reports are correct - were trained in the same system, by the same institution, and had the same skills.
After leaving military service, the veterans allegedly recruited young IT prodigies from Kim Chaek University of Technology and Pyongyang University of Science and quietly built an operation to enrich themselves personally rather than fill the North Korean state's coffers.
Using Chinese-made specialist wireless equipment and encrypted messaging apps, the group is said to have broken into the well-guarded internal networks and foreign payment systems of both banks. Once inside, they allegedly took split portions of state trade funds into tiny increments - in an attempt to avoid detection - and moved the funds into cryptocurrency wallets.
Brokers in China are reported to have converted the cryptocurrency back into cash, while contacts in border areas exchanged the laundered funds for US dollars and Chinese yuan.
In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea deploys internationally, and turned it inwards.
Unfortunately for the hackers, officials in Pyongyang began noticing small discrepancies in foreign currency payment approvals and flagged suspicious access to overseas IP addresses. Investigators for the National Intelligence Agency traced encrypted cryptocurrency traffic to a location in Pyongyang, and raided it on the night of 12 July - seemingly catching the hackers while they were laundering funds via their computers.
Computer equipment and burner phones have been confiscated by the authorities, as part of the investigation.
Lets not forget - this is all happening in the dictatorship of North Korea. Any punishment dealt out by the authorities against the hackers is likely to not just be harsh, but also extend beyond the individuals involved to include their families as well.
NK Daily quotes a source as reporting that an official had said in response to the case:
"They used the skills the state trained them with to defend the country, and instead robbed the country’s coffers. This goes beyond ordinary guilt-by-association penalties. It will be hard for the entire family line to survive."
tags
Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s.
View all posts
Facts Only
* A hacking ring was arrested on July 12 following the uncovering of a scheme to steal from the Chosun Central Bank and the Foreign Trade Bank.
* The ringleaders are said to be discharged veterans from the cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.
* The ringleaders allegedly recruited IT prodigies from Kim Chaek University of Technology and Pyongyang University of Science after leaving military service.
* The group reportedly used Chinese-made specialist wireless equipment and encrypted messaging apps to access internal networks and foreign payment systems.
* Funds were allegedly moved into cryptocurrency wallets before being converted back to cash, which was then exchanged for US dollars and Chinese yuan by brokers and border contacts.
* Investigators traced encrypted cryptocurrency traffic to a location in Pyongyang and conducted a raid on July 12th.
* Computer equipment and burner phones were confiscated during the investigation.
Executive Summary
State-trained hackers, previously known for stealing from foreign financial institutions and cryptocurrency exchanges for North Korea's weapons program, reportedly executed a scheme to steal funds from the Chosun Central Bank and the Foreign Trade Bank. The hacking ringleaders are said to be discharged veterans from the cyber operations unit under the Reconnaissance and Intelligence General Bureau. These individuals allegedly recruited IT prodigies and established an operation to enrich themselves rather than support the state.
The group reportedly used Chinese-made equipment to infiltrate internal networks and foreign payment systems, moving portions of state trade funds into cryptocurrency wallets. Brokers in China allegedly converted these assets back into cash, which was then exchanged for US dollars and Chinese yuan through contacts in border areas. Authorities initiated an investigation after noticing discrepancies in foreign currency payments and suspicious access to overseas IP addresses, leading to a raid on July 12th where equipment was confiscated.
Full Take
The narrative illustrates a critical convergence between state-sponsored cyber capabilities, illicit financial crime, and internal institutional vulnerability within an authoritarian structure. The pattern suggests that skills cultivated for national defense are co-opted for personal enrichment through sophisticated transnational criminal activity, effectively weaponizing state-developed knowledge against the state itself. This process demonstrates how insider access and specialized training can be leveraged to create parallel economies outside of official control, bypassing conventional state mechanisms.
The implication is that systemic vulnerabilities in state institutions—specifically financial oversight—become exploited when those same specialized actors are capable of operating within the security apparatus. The response by North Korean authorities, focusing on internal tracking (tracing traffic to Pyongyang) rather than external disruption, suggests an attempt to manage a crisis rooted in internal resource mismanagement rather than pure external threat mitigation. This dynamic raises questions about cognitive sovereignty: if state-sanctioned knowledge is utilized for private gain, what remains of the concept of national security integrity? The threat extends beyond individual punishment; it touches upon the structural integrity of the system that trains and controls these operatives, suggesting that accountability must address the entanglement of specialized skills within the state’s operational framework.
Bridge questions: How does the existence of such sophisticated internal networks challenge conventional models of state control? What are the long-term effects on the social cohesion and perceived legitimacy of the regime when high-level expertise is used for personal profit rather than state objectives? What mechanisms exist to ensure that specialized skills trained under a government remain aligned with the collective welfare rather than being channeled into extractive operations?
Sentinel — Human
The text functions as an investigative narrative synthesizing reports about North Korean cyber activity and subsequent internal arrests, demonstrating features consistent with journalistic aggregation rather than pure synthetic generation.
