ZachXBT Exposes Leaked DPRK Payment Server: Default Password '123456', $1M Monthly Crypto-to-Fiat Pipeline

ZachXBT Exposes Leaked DPRK Payment Server: Default Password '123456', $1M Monthly Crypto-to-Fiat Pipeline

N
News Editor 01
2026-07-09 01:04:13
Blockchain investigator ZachXBT published a leak from a North Korean IT worker payment server, revealing over $3.5 million processed since November 2025, with a monthly average of $1 million. Default password was '123456', and three OFAC-sanctioned entities were identified.
North Koreacryptocurrencyblockchain investigationsecurity breachZachXBT

Blockchain investigator ZachXBT released an 11-part thread on April 8, 2026, exposing data exfiltrated from an internal North Korean payment server used by DPRK IT workers. The leak revealed that the server processed over $3.5 million in payments since late November 2025, equating to roughly $1 million per month.

Key Findings: Default Password '123456' and Sanctioned Entities

The leaked data originated from a DPRK IT worker's device compromised by infostealer malware. An anonymous source shared the files with ZachXBT, who confirmed the material had never been publicly released. The extracted records included approximately 390 accounts, IPMsg chat logs, fabricated identities, browser history, and cryptocurrency transaction records.

The core internal platform was luckyguys.site, also known internally as WebMsg. It functioned as a Discord-style messenger, allowing DPRK IT workers to report payments to their handlers. At least ten users had never changed the default password, which was set to '123456'. The user list contained roles, Korean names, cities, and coded group names consistent with known DPRK IT worker operations. Three companies appearing in the list—Sobaeksu, Saenal, and Songkwang—are currently sanctioned by the U.S. Treasury's Office of Foreign Assets Control (OFAC).

Payment Flow and Fund Transfers

Payments were confirmed through a central admin account identified as PC-1234. ZachXBT shared direct message examples from a user nicknamed 'Rascal,' which detailed transfers tied to fraudulent identities spanning December 2025 through April 2026. Some messages referenced Hong Kong addresses for bills and goods, though their authenticity was not verified.

The associated payment wallet addresses received over $3.5 million during that period, equating to roughly $1 million per month. Workers used forged legal documents and fake identities to obtain employment. Crypto was either transferred directly from exchanges or converted to fiat through Chinese bank accounts using platforms like Payoneer. The admin account PC-1234 then confirmed receipt and distributed credentials for various crypto and fintech platforms.

Onchain analysis tied the internal payment addresses to known clusters of DPRK IT workers. Two specific addresses were identified: an Ethereum address and a Tron address that Tether froze in December 2025.

Operational Scale and Security Vulnerabilities

ZachXBT used the full dataset to map the complete organizational structure of the network, including payment totals per user and per group. He published an interactive org chart covering December 2025 through February 2026 at investigation.io/dprk-itw-breach, accessible with the password '123456'.

The compromised device and chat logs produced additional details. Workers used Astrill VPN and fake personas to apply for jobs. Internal Slack discussions included a post from a user named 'Nami' sharing a blog about a DPRK worker deepfake applicant. The admin also sent 43 Hex-Rays and IDA Pro training modules to workers between November 2025 and February 2026, covering disassembly, decompilation, and debugging. One shared link specifically addressed unpacking hostile PE executables.

Thirty-three DPRK IT workers were found communicating through the same IPMsg network. Separate log entries referenced plans to steal from Arcano, a GalaChain game, using a Nigerian proxy, though the outcome of that effort was not clear from the data.

ZachXBT characterized this cluster as less operationally sophisticated than higher-tier DPRK groups such as Applejeus or Tradertraitor. He previously estimated that DPRK IT workers collectively generate multiple seven figures per month. He noted that low-tier groups like this one attract threat actors because the risk is low and competition is minimal.

Aftermath

The luckyguys.site domain went offline on April 9, 2026, the day after ZachXBT published his findings. He confirmed the full dataset was archived before the site was taken down. The investigation offers a direct view into how DPRK IT worker cells collect payments, maintain fake identities, and move money through crypto and fiat systems, with documentation that shows both the scale and the operational gaps these groups rely on to stay active.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.