Researchers say North Korean hackers are likely laundering stolen crypto by renting cloud compute to mine fresh coins, avoiding more scrutinized crypto mixers
A spy group working for the Kim regime has been feeding stolen coins into crypto mining services in an effort to throw tracers off their trail.
WiredAndy Greenberg
Context & Ripple Effects
This reported laundering route extends a documented pattern: North Korea-linked operators had previously used compromised machines for Monero mining and later used automated Bitcoin “peel” transactions to fragment stolen funds.
The significance is the shift from manipulating stolen coins directly to converting them through rented computing capacity, potentially moving activity away from the more visible mixer ecosystem.
First-order effects
The reported operators can seek newly mined cryptocurrency rather than sending stolen holdings through mixers, complicating transaction-tracing efforts.
Cloud-compute providers become a relevant control point: rented capacity may be used as an intermediate layer in a laundering workflow, not only for conventional computing workloads.
Second-order effects
Blockchain-analysis and compliance teams may need to connect theft proceeds, cloud-service payments, and mining outputs rather than focus principally on mixer-linked flows.
The approach can increase pressure on cloud providers and mining services to detect suspicious rental and mining patterns without treating ordinary compute customers as illicit.
Third-order effects
If this method is adopted more broadly, crypto laundering detection will increasingly depend on cross-market visibility between blockchain transactions and off-chain infrastructure services.
The pattern reinforces a wider legitimacy challenge for crypto markets: enforcement pressure can displace illicit activity into adjacent services rather than eliminate it.
The trend: Crypto-related financial crime is shifting from conspicuous on-chain obfuscation toward workflows that convert illicit assets through ordinary infrastructure services.
Who is APT43? Mandiant shining a light on some very interesting threat actors operating in North Korea. Happy graduation day! https://www.mandiant.com/...
Mandiant Intelligence is pleased to bring you 🇰🇵APT43, a prolific cyber operator that supports the interests of the North Korean regime. We believe APT43 funds itself through cybercrime to support its primary mission of collecting foreign intelligence. https://www.mandiant.com/..…
Many Korea watchers face relentless phishing attempts they've faced from hackers impersonating researchers, government officials, journalists. Such efforts are linked with this prolific cyberespionage operation known for its aggressive social engineering. https://www.washingtonpo…
.@Mandiant has elevated the threat status of a North Korean cyber group, APT43 (a.k.a., Kimsuky/Thallium). It's known for its “long con” targeting experts and laundering crypto stolen from individual users. From me & @timstarks: https://www.washingtonpost.com/ ...
The continuing symbiosis between the DPRK's nuclear ambitions and its cyber capabilities should serve as a warning concerning future nation-state activity in the domain. If North Korea can get this sophisticated, virtually any country with the proper motivation can also. https://…
This bit jumped out at me from Mandiant's new report on APT43, a North Korean espionage group with a sideline in cybercrime: It's paying stolen crypto to rent hashing power to mine crypto, dead-ending the money's blockchain trail and obtaining clean coins. https://www.wired.com/.…