# Chinese and North Korean Cyber Groups Intensify Asia-Pacific Campaign on Record 2025 Haul


Threat actors linked to China and North Korea have consolidated their dominance over the Asia-Pacific financial sector, with North Korea's state-backed cybercriminals achieving unprecedented financial gains in 2025 while evolving their tactics to evade increasingly coordinated international enforcement efforts. A comprehensive analysis of the regional threat landscape reveals a sophisticated, well-resourced operation that has become central to funding state activities, accounting for a significant share of national GDP.


## The Threat


The scope of the threat has reached critical proportions. According to CrowdStrike's 2026 Financial Services Threat Landscape Report, six of the nine major threat groups actively targeting financial services in Q1 2026 are directly linked to China or North Korea. More broadly, cybercriminal operations conducted at least 78 documented data-leak-and-ransom campaigns against organizations across the Asia-Pacific and Oceania regions, though security researchers acknowledge this figure represents only a portion of actual activity.


The financial toll has been staggering. In 2025 alone, threat actors operating under North Korean direction stole approximately $2.02 billion in cryptocurrency, representing between 6% and 7% of the Democratic People's Republic of Korea's estimated $29 billion gross domestic product. This concentration of illicit revenue in a single sector underscores how cybercrime has become a cornerstone of state funding for the isolated regime.


Key threat indicators:

  • Primary targets: Financial institutions, cryptocurrency exchanges, fintech platforms, and digital asset custodians
  • Attack methods: Data-leak-and-ransom operations, credential theft, supply chain compromise, advanced persistent threats (APTs)
  • Geographic focus: Southeast Asia, Oceania, and increasingly, Australia
  • Motivation: Currency generation for state coffers and operational funding for military and intelligence programs

  • ## Background and Context


    The emergence of cybercrime as a revenue stream for North Korea reflects both economic desperation and strategic capability development. Faced with international sanctions that have crippled conventional economic activity, the DPRK has systematically invested in building world-class hacking operations capable of targeting high-value cryptocurrency assets and financial networks across Asia-Pacific.


    China's involvement in the threat landscape takes a different form. While North Korean groups operate primarily for financial gain, Chinese threat actors frequently blend financial theft with espionage objectives, targeting financial institutions alongside government agencies and critical infrastructure operators.


    ### The Cryptocurrency Factor


    Cryptocurrency theft has become the preferred attack vector for state-sponsored groups because it offers several advantages over traditional financial fraud:


    | Advantage | Impact |

    |-----------|--------|

    | Pseudonymity | Transaction trails are harder to trace than wire transfers |

    | Speed | Stolen assets can move across exchanges within minutes |

    | Irreversibility | Unlike bank transfers, crypto transactions cannot be reversed or frozen as easily |

    | Volume | Single exchanges hold billions in digital assets, concentrating targets |

    | Cross-border | No single nation's banking system can easily intercept funds |


    ### Regional Vulnerability


    The Asia-Pacific region has become a particular focus because of:

  • High cryptocurrency adoption in countries like Singapore, South Korea, and Australia
  • Regulatory gaps in emerging markets like Cambodia, Laos, and Myanmar, which have become havens for scam operations
  • Cryptocurrency scam compounds operating openly in Southeast Asia, processing tens of billions in illicit funds annually without meaningful law enforcement interference
  • Geographic proximity for North Korean and Chinese threat actors
  • Skilled technical workforce in developed Asia-Pacific nations that can be co-opted or compromised

  • ## Technical Details and Evolution


    Blockchain analysis firm Chainalysis, which this week announced a collaboration with South Korea's National Police Agency to strengthen investigations into illicit cryptocurrency flows, emphasized that threat group tactics continue to evolve at an accelerating pace.


    According to Eric Jardine, head of research at Chainalysis: "Our figures should be viewed as lower-bound estimates based on activity we've been able to attribute. North Korea's record-breaking 2025 performance, achieved with significantly fewer known attacks, suggests we may only be seeing the most visible portion of its activity."


    This statement carries profound implications. North Korean threat groups achieved their highest financial haul while actually conducting fewer operations than in previous years, indicating:


    1. Increased sophistication — Operations are more targeted and efficient

    2. Larger payloads — Attacks are hitting higher-value targets or extracting more per compromise

    3. Better operational security — More attacks are going undetected by security vendors and researchers

    4. Advanced tooling — Custom malware and exploitation frameworks are improving in stealth and effectiveness


    Typical attack chain observed:

  • Initial access via phishing or supply chain compromise
  • Lateral movement within target networks using living-off-the-land techniques
  • Credential harvesting and privilege escalation
  • Cryptocurrency exchange access through stolen or created accounts
  • Rapid asset movement through multiple intermediary wallets before conversion
  • Final cash-out through peer-to-peer or informal value transfer networks

  • ## Implications for Organizations and Governments


    The intersection of cybercriminal success and state sponsorship creates a strategic challenge that transcends traditional cybersecurity. This is not merely a technical security problem—it is a geopolitical and economic warfare tactic that directly funds state capabilities in military, missile, and nuclear programs.


    For financial institutions:

  • Cryptocurrency exchange platforms and custodians represent the highest-value targets and face the most sophisticated adversaries
  • Legacy banks handling APAC cross-border transactions are increasingly targeted for access to corporate cryptocurrency holdings
  • Fintech platforms and payment processors face both direct attacks and supply chain compromise

  • For government policymakers:

  • The scale of state-sponsored cybercrime funding represents a failure of existing sanctions regimes
  • International cooperation is becoming essential—no single nation can effectively counter transnational cybercrime
  • Cryptocurrency regulation and exchange compliance frameworks must improve to prevent illicit asset movement

  • For the broader region:

  • The existence of openly operating cybercrime scam compounds in Cambodia, Burma, and Laos creates permissive sanctuaries for criminal operations that feed intelligence and resources back to state actors
  • Southeast Asian nations must prioritize law enforcement coordination to dismantle these physical infrastructure nodes

  • ## Recommendations for Defense


    Organizations operating in the Asia-Pacific region should implement heightened controls:


  • Cryptocurrency security: If holding digital assets, use hardware wallets, air-gapped systems, and multi-signature approval for any fund movements
  • Enhanced detection: Implement advanced endpoint detection and response (EDR) tools capable of identifying living-off-the-land attack techniques
  • Credential management: Deploy passwordless authentication, hardware security keys, and Zero Trust architecture
  • International reporting: Engage with law enforcement and threat intelligence partners to attribute attacks and contribute to collective defense
  • Supply chain hardening: Scrutinize third-party software and services for signs of compromise, particularly software originating from or transiting through high-risk regions

  • The South Korea-Chainalysis collaboration represents a model for enhanced international investigation and attribution. More nations should adopt similar partnerships to increase the friction and cost of conducting state-sponsored cybercrime operations.


    ---


    ## HackWire Analysis


    The conventional narrative around North Korean cybercrime treats it as a desperate regime compensating for economic isolation. That framing misses what's actually happening: North Korea has engineered a repeatable, scalable criminal production line that generates state revenue at volumes comparable to legitimate exports, all while directly contributing to military capability development. The 2025 figures should alarm policymakers more than typical cybersecurity incidents because they represent proof of concept that sanctions enforcement has fundamentally broken down in the digital domain.


    What distinguishes this moment is the evolution toward *efficiency*—fewer attacks, higher yields. This suggests the DPRK has either (1) identified a concentrated set of ultra-high-value targets, (2) developed technical sophistication that dramatically improves success rates, or (3) established more stable operational relationships with accomplices inside target organizations. All three scenarios are worse than the prior pattern of spray-and-pray attacks. A nation that can generate $2 billion in annual revenue while reducing operational tempo has moved from opportunistic cybercrime into a deliberate economic warfare capability.


    The Cambodia-Laos-Burma scam compound ecosystem is the blind spot in regional responses. These aren't rogue operations—they're partially tolerated infrastructure that funnels funds and launders stolen assets. Until governments treat physical scam compounds as national security threats equivalent to weapons manufacturing, they will continue to serve as both profit centers and incubators for more sophisticated state actors. The next escalation will likely see these operations increasingly integrated with state cyber operations rather than remaining merely parasitic.


    For defenders, the message is clear: assume your organization is either a current or future target. The bar for entry-level attacks has never been lower, but the sophistication of *successful* attacks on high-value targets has never been higher. Regional financial institutions should treat this report as an actionable threat assessment requiring immediate board-level attention and budget reallocation toward adversary-hardened detection and response capabilities.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)