/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers say North Korean hackers are likely laundering stolen crypto by renting cloud compute to mine fresh coins, avoiding more scrutinized crypto mixers

A spy group working for the Kim regime has been feeding stolen coins into crypto mining services in an effort to throw tracers off their trail.

Wired Andy Greenberg

Context & Ripple Effects

This reported laundering route extends a documented pattern: North Korea-linked operators had previously used compromised machines for Monero mining and later used automated Bitcoin “peel” transactions to fragment stolen funds.

The significance is the shift from manipulating stolen coins directly to converting them through rented computing capacity, potentially moving activity away from the more visible mixer ecosystem.

First-order effects

  • The reported operators can seek newly mined cryptocurrency rather than sending stolen holdings through mixers, complicating transaction-tracing efforts.
  • Cloud-compute providers become a relevant control point: rented capacity may be used as an intermediate layer in a laundering workflow, not only for conventional computing workloads.

Second-order effects

  • Blockchain-analysis and compliance teams may need to connect theft proceeds, cloud-service payments, and mining outputs rather than focus principally on mixer-linked flows.
  • The approach can increase pressure on cloud providers and mining services to detect suspicious rental and mining patterns without treating ordinary compute customers as illicit.

Third-order effects

  • If this method is adopted more broadly, crypto laundering detection will increasingly depend on cross-market visibility between blockchain transactions and off-chain infrastructure services.
  • The pattern reinforces a wider legitimacy challenge for crypto markets: enforcement pressure can displace illicit activity into adjacent services rather than eliminate it.

The trend: Crypto-related financial crime is shifting from conspicuous on-chain obfuscation toward workflows that convert illicit assets through ordinary infrastructure services.

Discussion

  • @argvee Heather Adkins on x
    Who is APT43? Mandiant shining a light on some very interesting threat actors operating in North Korea. Happy graduation day! https://www.mandiant.com/...
  • @imposecost Andrew Thompson on x
    Mandiant Intelligence is pleased to bring you 🇰🇵APT43, a prolific cyber operator that supports the interests of the North Korean regime. We believe APT43 funds itself through cybercrime to support its primary mission of collecting foreign intelligence. https://www.mandiant.com/..…
  • @myhlee Michelle Ye Hee Lee on x
    Many Korea watchers face relentless phishing attempts they've faced from hackers impersonating researchers, government officials, journalists. Such efforts are linked with this prolific cyberespionage operation known for its aggressive social engineering. https://www.washingtonpo…
  • @myhlee Michelle Ye Hee Lee on x
    .@Mandiant has elevated the threat status of a North Korean cyber group, APT43 (a.k.a., Kimsuky/Thallium). It's known for its “long con” targeting experts and laundering crypto stolen from individual users. From me & @timstarks: https://www.washingtonpost.com/ ...
  • @jasonatwell14 Jason Atwell on x
    The continuing symbiosis between the DPRK's nuclear ambitions and its cyber capabilities should serve as a warning concerning future nation-state activity in the domain. If North Korea can get this sophisticated, virtually any country with the proper motivation can also. https://…
  • @ericgeller Eric Geller on x
    Interesting details here on a newly revealed North Korean hacking team. Full report here: https://mandiant.widen.net/... https://twitter.com/...
  • @a_greenberg Andy Greenberg on x
    This bit jumped out at me from Mandiant's new report on APT43, a North Korean espionage group with a sideline in cybercrime: It's paying stolen crypto to rent hashing power to mine crypto, dead-ending the money's blockchain trail and obtaining clean coins. https://www.wired.com/.…