North Korean Hackers Hacked: ZachXBT Leaks Internal Payment Server with Password '123456'

North Korean Hackers Hacked: ZachXBT Leaks Internal Payment Server with Password '123456'

N
News Editor 01
2026-07-23 11:10:15
On-chain sleuth ZachXBT exposed a DPRK fake IT worker network making $1M monthly, after a leaked internal payment server with default password '123456'.
ZachXBTNorth Korea hackersinternal server leak123456money laundering

Blockchain investigator ZachXBT dropped a bombshell on X: leaked data from a North Korean internal payment server has laid bare a sprawling fraud network of fake IT workers. The operation rakes in around $1 million per month, but its security is astonishingly weak — the management panel's default password was “123456”, and ten users never changed it.

Insider Server Hacked Back, Password Laughably Simple

The leak started with a twist of irony. ZachXBT revealed that a DPRK IT worker's device was infected with an information-stealing malware, exposing IPMsg chat logs, fake identity documents, and browsing history. The gang used an internal platform at luckyguys[.]site to report payments to their handlers. This system, which processes millions of dollars monthly, had a default password of “123456”. The user list even included three entities sanctioned by the U.S. Treasury's OFAC: Sobaeksu, Saenal, and Songkwang.

$1M Monthly Haul and a Clean Money Trail

By analyzing chat records between the admin “PC-1234” and workers, ZachXBT mapped out the operation. Since late November 2025, payment wallets have received over $3.5 million, averaging about $1 million per month. The laundering method is consistent: move crypto out of exchanges, convert to fiat via Chinese bank accounts or fintech platforms like Payoneer, then settle internally after PC-1234's approval. On-chain data showed one Tron network payment address was frozen by Tether in December 2025.

Deepfake Interviews, Game Hacking Plans Exposed

The leaked group chats also revealed daily activities. An employee codenamed “Jerry” used Astrill VPN and multiple fake identities to mass-apply for jobs. In Slack, someone shared a security article about “DPRK IT workers using Deepfake for job applications” and a colleague joked: “Is that you?” Records also showed Jerry discussing using a Nigerian proxy to steal from the blockchain game “Arcano” on GalaChain. Admins frequently distributed training materials for Hex-Rays, IDA Pro reverse engineering, decompilation, and malware unpacking — clearly sharpening technical skills.

Still, ZachXBT noted this group's maturity is far below that of elite Lazarus units like AppleJeus or TraderTraitor. He offered a provocative take: for other cyber threats, these low-tier DPRK hacker groups — weak defenses, flush with cash, and “deserving it” — might be the easiest, lowest-risk targets available.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.