Jul 21, 2026

From Payroll to Pyongyang: The DPRK IT Worker Money Trail

9

A year ago, DTEX detailed how DPRK IT workers and cyber operators function as a coordinated arm of the regime. A year of open-source and multilateral reporting has since reinforced the model mapped, one built on infiltrating global hiring pipelines and blending of full spectrum cyber operations. New DTEX i³ research, expanded on by reporting through April 2026, picks up where the employment story ends. It follows the money through how payments are reported, who controls the process, and how funds move through internal DPRK channels tied to state activity. At the center of the research is a new interactive map that traces the money through the DPRK system, providing context to where it ultimately leads.

Initial exposure

On April 8, 2026, ZachXBT published an 11-post thread based on data exfiltrated from an internal DPRK payment server. The extracted material included 390 accounts, chat logs, cryptocurrency transaction data, and self-identifications. The thread states that the data had not previously been released publicly, but DTEX holdings partially corroborate many aspects of the findings. It also identifies luckyguys[.]site as an internal payment remittance platform described as a Discord-style messenger used by DPRK IT workers to report payments back to handlers.

Details within the dataset further highlight the operational environment tied to this platform. The site was observed using a default password of “123456,” which remained unchanged across multiple user accounts, indicating minimal internal access controls. The associated records also exposed numerous organizational ties, with several entities identified in the data already under OFAC sanctions for supporting DPRK’s weapons development and sanctions evasion, including Sobaeksu, Saenal, and Songkwang.

Payment workflow

The social media thread gives the clearest public view of how this stream worked and provided a baseline that DTEX and others expanded upon. The information shows that all payments were processed and confirmed through the server administrator account PC-1234. In one example, direct messages between the user Rascal and PC-1234 covered payment transfers and the use of fraudulent identities from December 2025 through April 2026.

Payment reporting followed a repeatable pattern observed across the chat logs. Operators would acknowledge completed transfers, often referencing either direct crypto movement or conversion to fiat through Chinese financial channels and third-party payment services. Once submitted, those payments were verified by PC-1234, who responded with follow-on instructions tied to platform access and account usage, with variations depending on the operator and payment method.

RB wallet and assessed linkage

Based on a review of the chats, prior investigative context, and repeated self-identification language, DTEX, with input from partners in the community, assess that references to the “RB wallet” are likely references to the OFAC sanctioned Ryongbong General Corporation. That language should remain as an assessment supported by other communications and naming conventions tied to this direct activity (i.e., self-identification from some of the entities, operational control by Ryonbong, entities referring to Ryonbong only by RB, bases mentioned in the chats align with past Ryonbong efforts). The same chat stream repeatedly frames payment confirmation around PC-1234 and the RB wallet, which is the point where the money is acknowledged and moved forward. Chat reviews also show why payment totals should not be read as individual earnings. This movement and consolidation of funds follow a system where money is pooled, mixed, and moved at the lower and middle levels upward to centrally held accounts by the leadership chain to ultimately be used to fulfill specific mandates such as weapons funding.

High-value entries are most likely team collectors or managers remitting on behalf of multiple workers. Lower entries in the roughly $1,000 to $8,000 range fit individual-led contributions more closely. In chat examples, peak_sin_yong reported about $129,000, mighty about $63,000, and jgs313 about $821. This spread and understanding of DPRK’s organizational breakdowns support the assessment that some entities are not a single person earning money directly but are aggregating money from multiple workers and passing it upward.

Units and hierarchy

Chats show the money moving most often toward Unit 1020 and the overarching Command 710, with a smaller financial role tied to Unit 53 with seeming physical building identifiers of “128” at times. The money in this stream is moving upward and not moving back down in any way the chats make visible. The special value here is not only that names and handles were exposed but that operators identified who they belonged to, who they answered to, and what team or base they sat under. That turns the often generic “IT worker” story into a view of backend institutions, bases, units, colleges, and front companies sending revenue upward into a shared system. See below for a few observations and assessments either made or directly called out in the data:

  • Unit 1020 – Finance management unit under 710 Command. Absent the possible ‘128’ prefix seen on elements 128-710 and 128-53, suggesting it may operate from a distinct and separate location.
  • Command 710 – JiHuiBu (지휘부) = Command Bureau. Does not match any publicly documented DPRK bureau number. Location of command structure itself is unknown.
  • 128-53 – Primary evidence node for ‘128’ = Base 4 link. rji0124 verbatim: “financial manager of Base4 128-53.” Appears to be smaller financial or revenue generation consolidation apparatus.
  • Sobaeksu, Saenal, and Songkwang trading entities – Identified in the dataset and previously designated under sanctions related to 313 Munitions Industry Department (MID) front companies, these entities appear as part of the same reporting structure. Their presence highlights IT worker activity directly to the MID which controls DPRK’s research and development and productions of weapons, to include nuclear weapons and ballistic missiles among other military equipment.
  • Ryonbong-associated references (“RB”) – Entries tied to “RB” map closely with known references to Korea Ryonbong General Corporation, a sanctioned defense conglomerate involved in procurement for DPRK military programs.
  • Regional group labels (Chongjin, Hamhung, Pyongsong, Rason/Wonsan) – These groupings reflect geographic organization within the dataset, showing that reporting structures are not only functional but also can be regionally aligned.
  • Sector and institutional groups (University of Transport, Health IT, Forest IT, Print Teams) – These demonstrate that participation in this system extends beyond traditional cyber or financial units and includes educational, industrial, and technical institutions, an item talked about but rarely seen in open-source information. This reinforces the assessment that any organization with network access may be expected to generate and remit revenue upward.

For extra context and visibility, we mapped all the places mentioned in the chat to points in North Korea to show a geographic lens. After dealing with DPRK cyber efforts for many years, rarely have we seen where some of these efforts tie back, and although this is limited, we did our best in terms of showing where some of these entities physically lay. Markers at province centers represent assessed provincial affiliation, not a specific building or facility. Locations without coordinates were omitted all together.

Infrastructure and follow-on pivots

After information regarding luckyguys[.]site was exposed, other cyber companies examined 30 days of network activity tied to the server. Their analysis states the domain resolved to 163.245.219[.]19. VPN-related traffic to that IP was concentrated around Astrill VPN at 37.5%, Mullvad at 32.25%, and Proton VPN at 6.25%. They also observed American and Latvian residential IPs communicating with the infrastructure and noted connectivity to Gmail, ChatGPT, and Workana. They identified a second IP, 216.158.225[.]144, through X.509 certificate analysis and observed a sharp drop in traffic after public exposure. Others then pivoted from that reporting and identified luckyguys[.]cloud, registered on January 6, 2026, with the same registrar as luckyguys[.]site. That analysis also identified rbluckyguys[.]com and a login panel referencing “RB Luckyguys Management.”

Subcontractors, facilitators, and the Nigerian proxy

The public thread highlights a growing trend in proxy usage. One compromised device showed a “Jerry” discussing theft from Arcano, a GalaChain game, through a Nigerian proxy. ZachXBT states it was not clear whether the attack later materialized, but it sits alongside broader multilateral reporting on the facilitator layer. The Multilateral Sanctions Monitoring Team (MSMT) report states that Pakistan-based forgers provided fraudulent passports and identity material to DPRK IT workers, that those credentials were paid for with Ethereum, USDC, and Payoneer, and that Ukrainian brokers sold verified accounts, laptops, residential IP access, and identity packages tailored to DPRK IT worker needs. The same file also states DPRK workers relied on facilitators in Japan, Ukraine, the UAE, and the United States, and that a marked spike was observed in the use of Ukrainian identities on freelance platforms. DTEX and partnered investigations expand that even further to countries such as Nigeria, Pakistan, India, Iran, and parts of Latin America. That broader subcontracting point explains how DPRK operators increasingly want to move off camera, blend into criminal or labor ecosystems, and scale beyond direct DPRK attribution.

Unknown efforts and targeting

The public information also shows this cluster was not limited to payroll movement. At one point, intelligence shows administrators distributing 43 Hex-Rays and IDA Pro training modules between November 2025 and February 2026. These materials focused on reverse engineering, debugging, and software exploitation techniques. Concurrently, 33 DPRK IT workers were observed communicating on the same network via IPMsg. Separate information from internal holdings a year prior identified an actor impersonating PC-1234 and pushing malware-laced software to DPRK IT workers. This indicates other unknown actors were attempting to exploit this ecosystem in the past and that some of the workers recognized the attempt and warned one another. “Hackers pretend to be PC-1234 to deliver their viruses to other people… Just install the oconnect software only downloaded from RB site.”

Russia linkage

Observing at a strategic overview reveals the broader consequences. Reporting on March 2, 2026 stated that South Korean intelligence assessed North Korea had shipped around 33,000 containers to Russia, including ammunition equating to more than 15 million 152mm shells and 220 artillery pieces, and that more than 16,000 North Korean troops had been deployed near the Russia-Ukraine border in various roles. Council on Foreign Relations said that North Korea first shipped weapons to Russia in August 2023, later sent between 14,000 and 15,000 soldiers, and in June 2025 agreed to send about 5,000 construction workers and 1,000 combat engineers to Kursk. The same article described Russia retrofitting first-person-view drones with North Korean-made cluster munitions. This is a consequence that is often overlooked. Revenue from the IT worker stream does not stop at a resume scam or a payroll abuse story. It can feed a larger DPRK system that supports sanctioned entities, domestic state needs, and a Russia war effort that is actively consuming all facets of North Korean weapons and military support. For anyone still asking, “so what?” or “is it really that bad?”, follow the money. Western salaries paid to DPRK IT workers are funneled through front companies into weapons manufacturing and procurement and can then supply efforts we weren’t really factoring in, such as Russia’s war effort. Through this expanded lens, that money trail reframes the problem entirely.

Why the money matters

International reporting is often read as if DPRK IT workers only fund the weapons program, but that idea is too narrow. The above mentioned MSMT report states nearly all DPRK malicious cyber activity, laundering, and IT work is carried out under the supervision, direction, and for the benefit of entities sanctioned for their role in DPRK WMD and ballistic missile programs. It names the Reconnaissance General Bureau, Ministry of National Defense, Ministry of Atomic Energy Industry, Munitions Industry Department, Office 39, and the Second Academy of Natural Sciences. It also states DPRK front companies support those entities and conduct IT work, procurement, and money laundering on their behalf.

Investigations and partnerships dedicated to this space or topic add to the point the public rarely sees. Smaller elements, as we have seen with the DPRK based hacking units, can be funding themselves and paying upward into that system as a cost of business, a mechanism of access, or both.

To learn more about DPRK IT worker activity, request a DTEX i³ threat briefing.

Sources

Multilateral Sanctions Monitoring Team. (2025, October 22). The DPRK’s Violation and Evasion of UN Sanctions through Cyber and IT Worker Activities. The DPRK’s Violation and Evasion of UN Sanctions through Cyber and IT Worker Activities.

ZachXBT. (2026, April 8). Thread mirror: internal DPRK payment server containing 390 accounts, chat logs, and crypto transactions. Rattibha thread mirror.

Redman, J. (2026, April 9). ZachXBT Publishes Leaked DPRK Payment Data Showing $1M Monthly Crypto-to-Fiat Pipeline. Bitcoin.com News article.

Woodward, E. (2026, April 22). Unmasking DPRK Cyber Threat Actors: Fake IT Worker Infrastructure. Team Cymru post.

Plausible Deniability. (2026, April 30). Pulling the Thread: Pivoting on DPRK IT Worker Infrastructure. Plausible Deniability post.

Casimiro, C. (2026, March 2). N. Korea Increased Military Supply Shipments to Russia: Intelligence. The Defense Post article.

Carlough, M., & Kennedy, J. (2025, November 25). How North Korea Has Bolstered Russia’s War in Ukraine. Council on Foreign Relations article.

DTEX. (2025, May 14). Exposing DPRK’s Cyber Syndicate and Hidden IT Workforce. DTEX report.

FAQ

Internal payment and communication hub used by a network of North Korean (DPRK) state-backed fake IT workers. The platform allowed operatives to coordinate remote tech jobs, report salary remittances, and manage crypto-to-fiat conversion pipelines. Investigators also found later related infrastructure including luckyguys[.]cloud, and rbluckyguys[.]com.

Operators reported completed transfers into luckyguys[.]site, either as direct crypto movement or fiat conversion through Chinese financial channels and third-party payment services. Administrator PC-1234 verifies each payment. Funds are pooled at lower levels and consolidated upward through back into DPRK-controlled channels to centrally held leadership accounts.

Chats show funds moving to the “RB wallet” which is assessed as tied to the OFAC-sanctioned Korea Ryonbong General Corporation with moderate confidence. All money flows to the wallet would’ve then been under the purview of representatives within the Munitions Industry Department. The smaller accounts lead to assessments that other smaller organizations would’ve kept their earnings and the smaller sums were possible access fees in order to do business.

DPRK IT worker revenue funds funneled upward can feed a broader DPRK system tied to sanctioned entities, weapons manufacturing, procurement and state-directed activity. That matters because North Korea is also supplying Russia’s war effort: South Korean intelligence has reported around 33,000 containers shipped to Russia, including ammunition equivalent to more than 15 million 152mm shells, and more than 16,000 North Korean troops deployed near the Russia-Ukraine border. The point is not that a single salary payment can be traced to a specific weapon shipment, but that Western payroll can ultimately support the same state system behind DPRK military activity.

Subscribe today to stay informed and get regular updates from DTEX