From Payroll to Pyongyang: The DPRK IT Worker Money Trail
Why DTEX?<br>Platform
Platform
Platform OverviewUniquely designed to collect the minimum amount of data for a near zero impact on the endpoint and network.<br>Platform IntegrationsGet more powerful and relevant insights from deeper integrations.<br>DTEX NextDiscover DTEX NEXT innovations: proactive security, risk-adaptive DLP, insider threat detection, and AI governance to stay ahead of threats.
Solutions
AI Risk ManagementNew<br>Insider Risk Management<br>Data Loss Prevention<br>Privacy & Trust<br>User Activity Monitoring<br>User & Entity Behavior Analytics
DTEX Agentic Defenders
Triage GuardianNew<br>Threat HunterNew<br>Risk Assistant
Use Cases
By Use Case
AI Agent OversightNew<br>Shadow AINew<br>Foreign Interference<br>Leavers and Joiners<br>Third-party / Contractor Risk
By Industry
Financial Services<br>Manufacturing<br>Pharma & Life Science<br>Healthcare<br>Government<br>Technology<br>Telecommunications
Services
DTEX i3 ServicesLeverage our team of elite insider investigators in support of your program<br>Leverage our team of elite insider investigators in support of your program.
DTEX i3 ResearchTake advantage of cutting edge, timely insider risk research<br>Take advantage of cutting edge, timely insider risk research.
Upcoming Workshops<br>See the latest workshops
Datasheet
Insider Investigations and Intelligence Services
See how insider investigations and intelligence services help security teams prioritize risk, run hunts, and contain insider threats faster with analysts.
Resources
Report
Exposing DPRK’s Cyber Syndicate and Hidden IT Workforce
This report is an urgent call to shift from attribution to full-spectrum threat awareness against DPRK’s evolving cyber tactics.
Resource Library
All Resources<br>Blogs<br>Case Studies<br>Datasheets<br>E-books<br>Guides<br>Infographics<br>Reports<br>Solution Briefs<br>Threat Advisories<br>Videos<br>Webinars
Research & Insights
i3 HubExplore DTEX’s cutting edge, timely insider risk research<br>Threat Advisories<br>Reports<br>MITRE Inside-R ProtectLearn more about our partnership and gain access to insider threat indicators
Self-Services Resources
IRM 101Learn the basics of Insider Risk Management<br>Value CalculatorEvaluate your insider threat savings potential
About
About DTEXEmpowering a trusted workforce through technology innovation and collaboration<br>CareersJoin our team and help shape the future of Cybersecurity<br>Events & Webinars<br>Newsroom<br>Contact Us
Search
REQUEST A DEMO
Jul 21, 2026
From Payroll to Pyongyang: The DPRK IT Worker Money Trail
Michael Barnhart
MIN
Follow the money: Explore the interactive map tracing the DPRK IT worker money trail.
A year ago, DTEX detailed how DPRK IT workers and cyber operators function as a coordinated arm of the regime. A year of open-source and multilateral reporting has since reinforced the model mapped, one built on infiltrating global hiring pipelines and blending of full spectrum cyber operations. New DTEX i³ research, expanded on by reporting through April 2026, picks up where the employment story ends. It follows the money through how payments are reported, who controls the process, and how funds move through internal DPRK channels tied to state activity. At the center of the research is a new interactive map that traces the money through the DPRK system, providing context to where it ultimately leads.
Initial exposure
On April 8, 2026, ZachXBT published an 11-post thread based on data exfiltrated from an internal DPRK payment server. The extracted material included 390 accounts, chat logs, cryptocurrency transaction data, and self-identifications. The thread states that the data had not previously been released publicly, but DTEX holdings partially corroborate many aspects of the findings. It also identifies luckyguys[.]site as an internal payment remittance platform described as a Discord-style messenger used by DPRK IT workers to report payments back to handlers.
Details within the dataset further highlight the operational environment tied to this platform. The site was observed using a default password of “123456,” which remained unchanged across multiple user accounts, indicating minimal internal access controls. The associated records also exposed numerous organizational ties, with several entities identified in the data already under OFAC sanctions for supporting DPRK’s weapons development and sanctions evasion, including Sobaeksu, Saenal, and Songkwang.
Full combined chats. Downloadable text file here .
Payment workflow
The social media thread gives the clearest public view of how this stream worked and provided a baseline that DTEX and others expanded upon. The information shows that all payments were processed and confirmed through the server administrator account PC-1234. In one example, direct messages between the user Rascal and PC-1234 covered payment transfers and the use of fraudulent identities from December 2025 through April 2026.
Payment reporting followed a repeatable pattern observed across the chat...