Blockchain investigator ZachXBT dropped a bombshell on X: leaked data from a North Korean internal payment server has laid bare a sprawling fraud network of fake IT workers. The operation rakes in around $1 million per month, but its security is astonishingly weak — the management panel's default password was “123456”, and ten users never changed it.
Insider Server Hacked Back, Password Laughably Simple
The leak started with a twist of irony. ZachXBT revealed that a DPRK IT worker's device was infected with an information-stealing malware, exposing IPMsg chat logs, fake identity documents, and browsing history. The gang used an internal platform at luckyguys[.]site to report payments to their handlers. This system, which processes millions of dollars monthly, had a default password of “123456”. The user list even included three entities sanctioned by the U.S. Treasury's OFAC: Sobaeksu, Saenal, and Songkwang.
$1M Monthly Haul and a Clean Money Trail
By analyzing chat records between the admin “PC-1234” and workers, ZachXBT mapped out the operation. Since late November 2025, payment wallets have received over $3.5 million, averaging about $1 million per month. The laundering method is consistent: move crypto out of exchanges, convert to fiat via Chinese bank accounts or fintech platforms like Payoneer, then settle internally after PC-1234's approval. On-chain data showed one Tron network payment address was frozen by Tether in December 2025.
Deepfake Interviews, Game Hacking Plans Exposed
The leaked group chats also revealed daily activities. An employee codenamed “Jerry” used Astrill VPN and multiple fake identities to mass-apply for jobs. In Slack, someone shared a security article about “DPRK IT workers using Deepfake for job applications” and a colleague joked: “Is that you?” Records also showed Jerry discussing using a Nigerian proxy to steal from the blockchain game “Arcano” on GalaChain. Admins frequently distributed training materials for Hex-Rays, IDA Pro reverse engineering, decompilation, and malware unpacking — clearly sharpening technical skills.
Still, ZachXBT noted this group's maturity is far below that of elite Lazarus units like AppleJeus or TraderTraitor. He offered a provocative take: for other cyber threats, these low-tier DPRK hacker groups — weak defenses, flush with cash, and “deserving it” — might be the easiest, lowest-risk targets available.

