- What: North Korea's IT worker scheme funds Russia's war effort.
- Impact: Highlights state-sponsored cyber activities and financial support for conflict.
Threat Intelligence North Korea’s IT worker scheme funds Russia’s war effort, report finds July 21, 2026 Share By SC Staff North Korea's scheme to deploy IT workers globally is funneling money through a complex network of front companies and sanctioned entities, which in turn partially funds Russia's war in Ukraine, according to a new report. This operation has expanded beyond solely supporting the country's weapons programs to encompass a broader range of the regime's objectives, as reported by CyberScoop. Security firm DTEX's research reveals that the illicit IT worker scheme is a significant revenue stream for North Korea, with funds being channeled through organizations like Sobaeksu, Saenal, and Songkwang. Notably, $1.97 million in payments between December 2025 and February 2026 flowed directly through Korea Ryonbong General Corp, a sanctioned defense entity. This revenue supports not only weapons manufacturing and supply to Russia's military but also various domestic programs. Previously leaked data, including chat logs and transaction data from a North Korean payment server, corroborates these findings. The scheme operates on a bottom-up model, where individuals at the lower levels generate revenue, with a portion being siphoned upwards to fund a wider array of state activities and sanctioned entities, including Russia's ongoing military operations. Source: CyberScoop SC Staff Related Threat Intelligence Ostium trading platform loses $23.75 million in off-chain exploit SC Staff July 21, 2026 The attacker manipulated illegitimate price reports to disguise them as valid ones, then rapidly opened and closed large positions to generate artificial profits. Threat Intelligence Sophisticated crypter service Cruciferra evades detection with advanced techniques SC Staff July 21, 2026 Cruciferra, first offered for sale in autumn 2025, underpins dozens of campaigns delivering malware such as AsyncRAT, Agent Tesla, and Remcos. Threat Intelligence HollowGraph malware uses Microsoft 365 calendar for command and control SC Staff July 20, 2026 HollowGraph, believed to be part of the Cavern command-and-control framework, targets organizations in Israel for espionage purposes. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting DNS Spoofing Deauthentication Attack Dictionary Attack Distributed Scans DumpSec Google Hacking Hybrid Attack Password Cracking Reconnaissance You can skip this ad in 5 seconds