ZachXBT said a 390-account North Korean IT worker network has generated over $3.5 million in crypto flows since November 2025.
U.S Treasury sanctioned DPRK IT facilitators linked to crypto laundering networks that generated nearly $800 million for Pyongyang in 2024.
Disguised as a Zoom update, North Korean hackers use the new NimDoor malware to steal crypto and infiltrate crypto companies, researchers say.
North Korea was behind some of the largest crypto heists in history, including the $1.4 billion exploit on Bybit exchange earlier this year.
North Korea's Lazarus Group currently holds 13,518 BTC, worth around $1.13 billion, according to data from Arkham Intelligence.
The state-backed North Korean hacking group Kimsuky reportedly used a new malware variant to target at least two South Korean crypto firms.