/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
Technology

North Korean

Filtered to Regulatory & Policy ×
119 articles decelerating

$2.02B in crypto was attributed to North Korean hackers in 2025 coverage, as reporting broadened from major thefts to IT-worker infiltration and blockchain-based malware.

Who they are

Coverage uses North Korean primarily to track a state-linked cybercrime and espionage ecosystem: hacking groups including Lazarus and Andariel, alongside workers alleged to obtain remote IT jobs under false identities. The entity appears in stories about exchange thefts, malware campaigns, sanctions, criminal indictments, and U.S., South Korean, Japanese, and UN responses rather than as a conventional technology company or product.

The recent arc

Coverage reached its recent high in 2025Q3, shifting emphasis from individual attributed intrusions toward the operational machinery around them. Reuters reported in September that North Korean hackers were flooding crypto-sector targets with credible job offers, while the U.S. case against an Arizona “laptop farm” operator described workers securing jobs at 309 U.S. companies. Google’s October warning on “EtherHiding” added a technical escalation: malware embedded on blockchains, which it described as a first for a nation-state threat actor.

The tension

The central tension is between increasingly visible financial and labor-fraud operations and efforts to disrupt them through attribution, prosecutions, sanctions, and employer detection. Lazarus remains the recurring adversary in alleged crypto thefts, including South Korean suspicions around the Upbit hack, while U.S. agencies target laundering and IT-worker networks; Amazon’s report that keystroke-latency anomalies exposed a worker shows defenders are also trying to identify deception inside legitimate hiring processes.

Why it matters

If this trajectory holds, the risk extends beyond episodic exchange hacks: crypto platforms, remote-work employers, and software supply chains may face interconnected social-engineering, identity, and malware threats. The reported rise in crypto thefts and the spread of worker schemes across more than 40 countries make international coordination consequential, but attribution and enforcement may remain difficult where operators can use intermediaries, false identities, and new technical channels.

North Korean has appeared in 119 articles since 2014-12. Coverage peaked in 2025Q3 with 10 articles. Frequently mentioned alongside North Korea, U.S., Lazarus, Microsoft.

Articles
119
mentions
Velocity
-83.3%
growth rate
Acceleration
-0.433
velocity change
Sources
34
publications

Coverage Timeline

2026-01-14
The Record 2 related

The US urged UN members to take a tougher stance against North Korea IT worker scams and crypto thefts; an October 2025 report found 40+ countries were affected

The U.S. on Monday urged United Nation member states to take a tougher stance against North Korean efforts to skirt sanctions through …

2025-07-25
The Record 9 related

The US Treasury sanctions three senior North Korean officials accused of tricking companies into hiring North Koreans using stolen identities as IT workers

Three senior North Korean officials involved in IT schemes have been sanctioned by the U.S. Treasury Department.

2025-05-03
New York Times 16 related

The US designates Cambodia's Huione Group as a money-laundering operation, saying it laundered $4B+ since August 2021 for criminals such as North Korean hackers

Selam Gebrekidan / New York Times :

2025-05-02
New York Times 11 related

The US designates Cambodia's Huione Group as a money-laundering operation, saying it laundered $4B+ since August 2021 for criminals such as North Korean hackers

The Treasury Department said Huione Group and its affiliates had laundered more than $4 billion.

2025-02-28
Bloomberg 13 related

Experts say stopping North Korean thefts will require higher security spending by crypto exchanges, more stringent rules, and better government cooperation

- Hackers drained Ether, other tokens from “cold” crypto wallet  — Exchanges must step up spending on security, experts say

2023-11-30
BleepingComputer 10 related

The US sanctions Sinbad, a crypto mixer allegedly used by the North Korean Lazarus hacking group, and the US, the Netherlands, and Poland seize the service

The U.S. Department of the Treasury has sanctioned the Sinbad cryptocurrency mixing service for its use as a money-laundering tool by the North Korean Lazarus hacking group.

2023-04-08
CoinDesk 33 related

The US Treasury warns that DeFi services that aren't compliant with AML and terrorist financing rules pose “the most significant current illicit finance risk”

US Treasury Damilola Lawrence / Cryptopolitan : U.S Treasury report reveals how North Korea and criminals use DeFi services to facilitate money laundering Florence Muchai / Cryptopolitan : US Treasury...

2022-07-08
Wall Street Journal 22 related

The FBI and MI5 issue a rare joint statement warning tech companies of China's large-scale state-sponsored hacking and a global network of agents to steal IP

Hello, sorry I'm late. Christopher Wray / F.B.I. : Director's Remarks to Business Leaders in London Gordon Corera / BBC : China: MI5 and FBI heads warn of ‘immense’ threat MI5 : Joint address by MI5 a...

2020-07-31
Associated Press 6 related

EU imposes its first ever cyber sanctions, hitting six people and three organizations including GRU, for involvement in WannaCry, NotPetya, and other attacks

Place of birth: Shandong Province, China Federal Computer Week : FCW Insider: July 31 Francesco Guarascio / Reuters : EU sanctions Russian intelligence, North Korean, Chinese firms over alleged cybera...

2019-09-15
ZDNet 10 related

US Treasury sanctions three North Korean state-sponsored hacking groups, Lazarus, Bluenoroff, and Andarial; Lazarus was responsible for WannaCry ransomware

the same hackers who allegedly launched WannaCry and behind the Sony hacks. https://home.treasury.gov/... https://twitter.com/... Catalin Cimpanu / @campuscodi : US Treasury sanctions three North Kore...

Loading articles...

Quarterly Coverage

Top Sources

Narrative

TEXXR tracks 93 tech news articles mentioning North Korean, dating back to December 2014. The biggest stories include DOJ announces hacking charges against a North Korean government spy, linked to the... and US-based security vendor KnowBe4 says it unwittingly hired a North Korean hacker who then.... Frequently covered alongside Microsoft, DOJ, Sony, FBI, and Lazarus.

Key Moments

2024Q4safety +40pts; research -100pts; regulation +40pts
2025Q1safety -15pts; developer +25pts; competition +25pts
2025Q3safety -25pts; developer -25pts; research +22pts

Relationships

Loading graph...