Leaked messages expose how Western companies end up supporting North Korea
New report comes with an interactive map tracing how US dollars end up in North Korea.

- A DTEX investigation says leaked payment records show North Korean IT workers sending foreign salaries to state-linked handlers.
- Researchers linked the system to sanctioned groups tied to North Korea’s weapons programs, including Sobaeksu, Saenal, and Songkwang.
- Chats describe cryptocurrency transfers, Chinese financial channels, and third-party services used to pool and move worker earnings.
- The findings suggest overseas IT revenue may support North Korea’s military programs and assistance to Russia’s war in Ukraine.
A leaked server has revealed how North Korean IT workers allegedly funneled foreign salaries into Pyongyang's weapons programs and Russian war effort.
State-backed hackers from Democratic People Republic of Korea (DPKR), continue to seek remote jobs in Western tech companies to secure a monthly paycheck.
North Korean IT workers have increasingly been linked to schemes in which they obtain remote employment at foreign companies using stolen identities or fabricated credentials. They may do the work, but their salaries are funding North Korea’s military. As widely reported before.
A newly published investigation by threat intelligence firm DTEX sheds light on what happens after North Korean IT workers receive paychecks from unsuspecting foreign employers.
Researchers traced the money through an internal payment reporting and messaging system used by North Korean IT workers.
This system is likely linked to organizations sanctioned by the US Treasury for supporting the country's military and nuclear programs.
The findings reinforce growing evidence that revenue generated by overseas IT workers supports a much broader state apparatus than previously understood.
Data exfiltrated from the North Korean system leaves a trail
The latest findings are largely based on data exfiltrated from an internal payment platform that North Korean IT workers used to report earnings to their handlers. The platform uses domains identified as luckyguys[.]site and rbluckyguys[.]com.
Back in April, blockchain sleuth ZachXBT shared that “an unnamed source shared data exfiltrated” from an internal North Korean payment server.
Multiple North Korean accounts on the platform were using a default password "123456," suggesting minimal internal access controls.
DTEX researchers analyzed transactions to link them to North Korea’s government.
“The associated records also exposed numerous organizational ties, with several entities identified in the data already under OFAC sanctions for supporting DPRK’s weapons development and sanctions evasion, including Sobaeksu, Saenal, and Songkwang,” researchers wrote.
The salaries are flowing into North Korea’s infrastructure
The leaked chats provide what researchers describe as one of the clearest public views yet into North Korea's internal payment workflow.
According to DTEX, workers reported that when they completed cryptocurrency transfers to an administrator account with a nickname PC-1234. The administrator verified payments before issuing further instructions.
In one example, direct messages between the user Rascal and PC-1234 covered payment transfers and the use of fraudulent identities from December 2025 through April 2026.
Messages reviewed by researchers show operators discussing cryptocurrency transfers, fiat conversions via Chinese financial channels, and third-party payment services.
Some accounts reported transfers exceeding $129,000, while others showed much smaller payments more consistent with individual earnings. Researchers believe many of the larger payments were consolidated contributions collected from multiple workers.
“This movement and consolidation of funds follow a system where money is pooled, mixed, and moved at the lower and middle levels upward to centrally held accounts by the leadership chain to ultimately be used to fulfill specific mandates such as weapons funding,” researchers said.
Chat records reference universities, healthcare organizations, industrial, and technical institutions, suggesting revenue collection spans numerous sectors within North Korea.
Researchers also observed infrastructure communicating with services including Gmail, ChatGPT, Workana, and several commercial VPN providers.While facilitators in countries including Pakistan, Ukraine, Japan, the United Arab Emirates, Nigeria, the United States, India, Iran, and parts of Latin America are alleged to have supplied fraudulent identities, residential IP addresses, laptops, and verified freelance accounts to North Korean operators.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Researchers link payments to sanctioned organizations
DTEX assesses that repeated references to an "RB wallet" across the database are likely referring to Ryonbong General Corporation, a defense conglomerate sanctioned for supporting North Korea's military procurement efforts.
The leaked records also mention organizations named Sobaeks, Saenal, and Songkwang. All 3 have previously been sanctioned for supporting North Korea's weapons development programs.
Researchers also observed repeated references to Unit 1020, Command 710, and Unit 53, suggesting a structured hierarchy overseeing financial reporting.
Links to Russia
Findings also point to increasing military cooperation between North Korea and Russia.
Revenue generated by the North Korean workers dispatched overseas may ultimately help finance organizations supplying military equipment and other support tied to Russia's war in Ukraine, as North Korea has been supporting Russia’s military.
“Revenue from the IT worker stream does not stop at a resume scam or a payroll abuse story,” DTEX researchers wrote.
“It can feed a larger DPRK system that supports sanctioned entities, domestic state needs, and a Russian war effort that is actively consuming all facets of North Korean weapons and military support,” they added.