Australia, in coordination with the United States, has imposed sanctions on North Korean cybercriminals and entities accused of generating illicit revenue to support Pyongyang's weapons of mass destruction (WMD) programs. The sanctions target one individual and four entities linked to activities such as espionage, cryptocurrency theft, and fraudulent IT worker schemes, with the aim of disrupting North Korea's ability to fund its weapons development. The measures include financial restrictions and travel bans, and are part of a broader international effort to counter North Korea's destabilizing cyber operations.
Australian officials highlighted that North Korean hacking groups have stolen over $2 billion in digital assets in the first three quarters of 2025, with proceeds laundered through networks in Russia, China, and other countries. The joint action underscores ongoing collaboration between Australia, the US, and other partners to push back against hostile cyber campaigns and promote responsible conduct in cyberspace. The sanctions follow similar US actions against North Korean nationals and institutions involved in laundering cybercrime proceeds.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Australia imposed sanctions on North Korean-linked cybercriminals and related entities involved in cyber operations that generate revenue for Pyongyang's weapons of mass destruction programs. The move was reported as aligning with existing or parallel U.S. sanctions as part of a broader effort to disrupt North Korea's illicit cyber and financial networks.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.