The US Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned North Korean cyber actor Song Kum Hyok for his involvement in fraudulent employment schemes.
Song Kum Hyok and Fraudulent Employment Schemes
Song Kum Hyok is a North Korean cyber actor associated with the Andariel hacking group. He oversaw scams that recruited North Korean nationals in Russia and China, providing them with false identities to work for companies. The program exploited innocent businesses to generate revenue for the North Korean government. North Korean IT personnel sometimes infected business networks with malware for later exploitation. In 2022 and 2023, Song used information belonging to US persons, including names and social security numbers, to create aliases for hired foreign workers posing as US citizens seeking remote employment.
Connections with Russian Entities
Russian citizen Gayk Asatryan has contracted North Korean IT personnel through Russian-based businesses. He inked a 10-year agreement with the Korea Songkwang Trading General Corporation to send up to 30 North Korean workers to Russia. Asatryan also contracted with the Korea Saenal Trading Corporation for additional worker deployments. Both agreements help obscure the true nature of employment relationships and allow North Koreans to access international markets through Russian business entities.
Measures Against Weapons Financing
These sanctions are part of US government efforts to counter North Korea's strategic interests through cyber espionage. Deputy Secretary Michael Faulkender emphasized the importance of vigilance against DPRK financing of weapons programs. Previously, groups such as Lazarus, Bluenoroff, and Andariel were sanctioned by OFAC for cryptocurrency theft. The Treasury's actions also involve blocking all assets related to sanctioned individuals to prevent the use of digital assets to evade sanctions.
The sanctions against Song Kum Hyok and associated Russian companies highlight the US's decisive measures in countering North Korean financing of weapons development through cybercrime and fraud.