-
DOJ seeks to forfeit $15.1 million in USDT stolen by North Korean hackers
-
Funds linked to APT38, the military hacking unit behind major crypto heists
-
Five individuals pleaded guilty to helping North Korean IT workers infiltrate U.S. companies
-
Scheme affected 136 firms and earned more than $2.2 million for North Korea
A Major Forfeiture Targeting APT38
The U.S. Department of Justice has moved to seize more than $15 million in USDT tied to North Korean hacking operations. The funds were linked to APT38, one of the regime’s main cyber units responsible for large crypto heists. The FBI captured the assets earlier in 2025, and the DOJ is now seeking approval to return the funds to victims.
The stolen tokens came from several 2023 hacks, including major incidents affecting exchanges and payment processors. North Korean hackers have been among the most active global actors, stealing more than two billion dollars worth of crypto so far this year.
A Network Of Fake IT Workers Inside U.S. Companies
The DOJ also secured guilty pleas from five people who helped North Korean workers pose as remote IT staff inside 136 American companies. The helpers provided stolen identities and even hosted corporate laptops at their homes to make it appear that the workers were based in the United States.
The scheme generated more than 2.2 million dollars for North Korea and compromised the identities of more than 18 U.S. citizens.
North Korea Uses Cybercrime To Fund Its Regime
Authorities say North Korea relies heavily on crypto theft and overseas IT schemes to bypass international sanctions. Advisory reports warn that these operations funnel hundreds of millions of dollars into programs linked to the Ministry of Defense.
The DOJ plans to continue tracking and seizing stolen crypto as APT38 attempts to move funds through mixers, bridges, and OTC brokers.