OFAC hit Russian national Vitaliy Sergeyevich Andreyev, a North Korean individual, and two entities, for enabling DPRK-linked fraud. Elliptic data show Andreyev’s sanctioned Bitcoin address received over $600K tied to the 2023 Atomic Wallet hack, with cross-chain layering used for obfuscation.

OFAC hit Russian national Vitaliy Sergeyevich Andreyev, a North Korean individual, and two entities, for enabling DPRK-linked fraud. Elliptic data show Andreyev’s sanctioned Bitcoin address received over $600K tied to the 2023 Atomic Wallet hack, with cross-chain layering used for obfuscation.
elliptic.co
Revision history

5 recorded changes

Want your article here?

Promote with Leviathan News

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned Russian national Vitaliy Sergeyevich Andreyev, North Korean national Kim Ung Sun, and two entities — Shenyang Geumpungri Network Technology Co., Ltd. in China and Korea Sinjin Trading Corporation in North Korea — for supporting a Democratic People’s Republic of Korea (DPRK) fraud and illicit IT‑worker network. According to OFAC, the network helped North Korean overseas IT workers impersonate non‑North Korean developers, obtain remote work with foreign companies (including U.S. firms), steal data, and in some cases conduct ransomware and other fraud schemes that generated revenue for the DPRK government. The entities are linked to Chinyong Information Technology Cooperation Company, a DPRK employer of IT workers operating in Russia and Laos, with OFAC assessing that a delegation of these workers has generated over $1 million in profits for Chinyong and Korea Sinjin since 2021. Blockchain analytics firm Elliptic reports that Andreyev is the only sanctioned party in this action publicly tied to a crypto address, a Bitcoin address that has received more than $600,000 and has traceable exposure to the June 2023 Atomic Wallet exploit, which has been attributed to North Korea’s Lazarus Group. Elliptic’s analysis shows that funds linked to this Atomic Wallet hack moved through a chain of addresses and used cross‑chain bridging and layering to obscure their origin, mirroring obfuscation techniques commonly associated with DPRK threat actors. The designations expand a broader U.S. campaign against North Korean revenue‑generation via cybercrime and illicit IT work, reinforce compliance expectations for financial institutions and crypto businesses around DPRK‑linked flows, and highlight the growing use of cross‑chain tools to launder proceeds from major hacks and fraud schemes.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Hacks

Comments