Norway Seizes Millions in North Korean Crypto

Feds target North Korean money launderers linked to $250M crypto hack
Norwegian authorities have traced and halted 60 million kroner (£5.9 million) in cryptocurrency stolen last year by North Korean actors, marking the largest heist of its kind ever documented.

The economic and environmental crime agency of the Scandinavian country (Økokrim) asserted that North Korean threat actors have been engaged in an extensive money laundering operation since the March 2022 attack on the Ronin Network.

"Økokrim is adept at tracking money. This case demonstrates our ability to follow cryptocurrency transactions on the blockchain, even when criminals employ sophisticated methods," stated Marianne Bender, a state attorney at Økokrim.

"We collaborate with cryptocurrency tracking specialists from the FBI. Such international cooperation strengthens our society's resilience against digital, profit-driven crime."

The Ronin Network was established by Vietnamese blockchain game developer Sky Mavis to operate as an Ethereum sidechain for its Axie Infinity game. Nevertheless, the Pyongyang-backed APT group Lazarus managed to breach the company's network when an employee opened a malicious phishing email attachment. The hackers made off with an estimated $618 million in cryptocurrency and physical cash in the world's largest cyber heist to date.

Økokrim's recent achievement follows their earlier recovery of $30 million in funds stolen from Ronin.

Chainalysis, a blockchain analysis firm involved in the operation, also revealed that North Korean hackers are using the crypto mixer Tornado Cash to facilitate the laundering of the funds stolen in the attack.

These efforts take on added significance as North Korea is likely to utilise any pilfered cryptocurrency to support its rapidly expanding missile programme.

"This is money that can assist North Korea and its nuclear weapons programme. It has, therefore, been imperative to trace the cryptocurrency and attempt to block the funds when they are converted into physical assets," explained Bender.

The recently seized funds will be returned to Sky Mavis, enabling the company to reimburse some of its affected customers.

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.